Privacy and RAI Engineer
Requisition ID
549593
Category
Legal
Location
United States - NY, New York
Location: This is a hybrid remote/in-office role based in NYC
Medidata follows a hybrid office policy in which employees who are hired for an in-person position are expected to work on site a certain number of days per week following Company policy.
About our Company:
Medidata is powering smarter treatments and healthier people through digital solutions to support clinical trials. Celebrating over 25 years of ground-breaking technological innovation across more than 38,000 trials and 12 million patients, Medidata offers industry-leading expertise, analytics-powered insights, and one of the largest clinical trial data sets in the industry. More than 1 million registered users across approximately 2,300 customers trust Medidata's seamless, end-to-end platform to improve patient experiences, accelerate clinical breakthroughs, and bring therapies to market faster. A Dassault Systèmes brand (Euronext Paris: FR0014003TT8, DSY.PA), Medidata is headquartered in New York City and has been recognized as a Leader by Everest Group and IDC. Discover more at www.medidata.com. Listen to our latest podcast, from Dreamers to Disruptors, and follow us at @Medidata.
About the Team:
This is an opportunity to be part of the Privacy & AI team tackling some of the most complex questions at the intersection of privacy & AI law, technology and life sciences as part of our tight-knit, dynamic legal department at our U.S. headquarters in New York City. We're seeking a Privacy & AI Engineer to further mature our Privacy & AI Program. This role reports directly to Medidata's VP, Associate General Counsel, Privacy & AI, working closely with our highly collaborative, cross-functional partners. As a member of the broader legal team, you will play a pivotal role in (i) translating legal and regulatory requirements into product-embedded technical controls that our cross-functional partners can act upon, (ii) maturing our privacy and responsible AI programs in collaboration with our cross-functional partners, and (iii) further developing operational efficiencies of the broader legal and regulatory teams leveraging existing third-party tools, including generative AI service providers.
Responsibilities:
Privacy Engineering & Technical Implementation:
-
Support the design and implementation of technical privacy controls across Medidata's software development lifecycle (SDLC) in collaboration with partners in R&D, engineering, data science and information security.
-
Lead Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for new and materially modified products, with particular attention to personal data processing and AI/ML components.
-
Collaborate with partners in information security to evaluate and advise on the architecture of data flows involving clinical trial subject data, real-world data inputs, and sponsor datasets for compliance with applicable data protection frameworks.
Responsible AI Governance:
-
Partner with the AI product and data science teams to document AI system risk assessments and algorithmic impact analyses for Medidata AI products, including classification of systems under the EU AI Act risk tiers, NIST AI RMF governance mapping, and ISO 42001 standard.
-
Support Medidata's obligations under laws like the EU AI Act — including documentation, human oversight design, incident reporting readiness, and Fundamental Rights Impact Assessment (FRIA) scoping for high-risk AI use cases in clinical contexts.
-
Track applicable regulatory obligations, and the status of ongoing compliance activities across product lines.
-
Collaborate with cross-functional partners to generate model cards, and AI system disclosures to support both internal governance and client-facing transparency commitments, including enterprise AI data sheet responses.
Privacy Operations & Technical Program Management Support:
-
Support the Privacy Program Manager in evolving technical components of Medidata's privacy program infrastructure, including data mapping tooling, consent management platforms, and privacy management software (e.g., TrustArc or equivalent).
-
Collaborate with our privacy counsels to track regulatory developments and prepare technical briefings for the VP, Associate General Counsel, Privacy & AI and Chief Legal Officer on emerging privacy engineering and AI governance obligations relevant to Medidata's business.
-
Support the Privacy & AI team in responding to Data Subject Access Requests (DSARs) and data rights exercises involving clinical trial participants — including technical scoping, data mapping, and workflow automation.
-
Serve as a technical privacy and AI subject matter expert in client security and privacy assessments, vendor due diligence reviews, and responses to enterprise RFPs and information security questionnaires.
-
Support the broader legal team with initiatives relating to further adoption of AI in daily operations.
Qualifications:
-
6+ years of experience in privacy engineering, data governance, or a related technical compliance role — preferably within a healthcare, life sciences, or enterprise SaaS organization.
-
Demonstrated understanding of data protection frameworks relevant to clinical research and/or healthcare contexts, including GDPR, HIPAA, UK GDPR, LGPD and US State Consumer Health Privacy Laws.
-
Working familiarity with AI governance frameworks, including NIST AI RMF 1.0, ISO 42001, and EU AI Act deployer, producer and provider obligations.
-
Hands-on experience with privacy engineering techniques such as data minimization, de-identification, pseudonymization, access control design, and audit logging.
-
Ability to translate complex legal and regulatory requirements into actionable technical specifications and product controls.
-
Experience contributing to or leading DPIAs/PIAs and cross-functional data protection reviews.
-
Strong oral and written communication skills with ability to produce clear policy documents, technical briefs, and executive-ready summaries for different audience types such as legal and/or R&D leadership personas.
-
Experience with privacy management platforms (e.g., OneTrust, Osano, Securiti) or data catalog/lineage tools.
-
Experience with implementing generative AI service provider tools like Claude, Gemini or ChatGPT.
-
Familiarity with open agentic AI standards including MCP, A2A, and emerging agent orchestration frameworks with particular attention to their data access, permissioning, and audit implications.
-
IAPP Certification(s): CIPT (Certified Information Privacy Technologist)
-
IAPP certification(s): AIGP, CIPP/E, CIPP/US, or CIPM.
-
Experience with clinical trial software (EDC, CTMS, eClinical platforms), RWD, and regulated healthcare IT environments.
-
Familiarity with HITRUST, HDS 2.0, NHS DSPT, FedRAMP, or similar security certification frameworks with privacy control intersections.
-
Prior experience with AI product governance, including model risk management, algorithmic bias assessment, or fairness/explainability tooling.
-
Proficiency in Python or equivalent scripting language for privacy automation, data analysis, or tooling development.
-
Bachelor's degree required, preferably in Computer Science, Information Systems, Data Science, or a related technical field.
-
Advanced degree in law, information privacy, or a relevant technical discipline is a plus. Equivalent professional experience and certification will be considered.
As with all roles, Medidata sets ranges based on a number of factors including function, level, candidate expertise and experience, and geographic location.
The salary range for positions that will be physically based in the NYC Metro Area is $114,750-153,000.
Base pay is one part of the Total Rewards that Medidata provides to compensate and recognize employees for their work. Most sales positions are eligible for a commission on the terms of applicable plan documents, and many of Medidata's non-sales positions are eligible for annual bonuses. Medidata believes that benefits should connect you to the support you need when it matters most and provides benefits, including medical, dental, life and disability insurance, 401(k) matching, family leave, flexible paid time off; and 10 paid holidays per year.
Note: Please be on the lookout for job scams. Medidata recruiters will never ask applicants for monetary compensation, credit card, or banking details.
Equal Employment Opportunity:In order to provide equal employment and advancement opportunities to all individuals, employment decisions at Medidata are based on merit, qualifications and abilities. Medidata is committed to a policy of non-discrimination and equal opportunity for all employees and qualified applicants without regard to race, color, religion, gender, sex (including pregnancy, childbirth or medical or common conditions related to pregnancy or childbirth), sexual orientation, gender identity, gender expression, marital status, familial status, national origin, ancestry, age, disability, veteran status, military service, application for military service, genetic information, receipt of free medical care, or any other characteristic protected under applicable law. Medidata will make reasonable accommodations for qualified individuals with known disabilities, in accordance with applicable law.
We will accept applications on an ongoing basis until we fill the position.
#LI-EM1
#LI-Hybrid