Job Description Summary:The
Director, AI & Data Governancepioneers our Data and AI Governance frameworks, ensuring that as our technology ecosystem evolves with emerging, allowlisted AI technologies, our data tracking, DLP/DSPM enforcement, and overall privacy posture remain uncompromised.
Your Role:- Implementation Oversight & Requirement Engineering - Translate written data classification policies into precise, testable technical requirements for InfoSec. Design and execute validation protocols to ensure the tuning of DSPM/DLP rules actively achieves mandated privacy outcomes.
- AI Governance & Allowlist Management - Serve as a core member of the enterprise AI Governance Committee. Own the enterprise AI Allowlist, ensuring it is accurate and highly accessible to employees to verify if AI usage is allowed, disallowed, or needs review.
- Data Visibility & Tooling Ecosystem - Manage the process for tracking, recording, and reporting data flows, including where restricted/confidential data intersects with AI. Utilize OneTrust to maintain RoPA, conduct DPIAs, and manage AI vendor risk assessments.
- Strategy & Policy Evolution - Monitor emerging AI capabilities and changing regulatory frameworks (e.g., EU AI Act, NIST AI RMF). Update internal policies and procedures to address new risks, using real-world telemetry from DSPM to refine corporate data protection rules.
- Cross-Functional Orchestration - Act as the strategic liaison between Legal, Security, and Engineering. Influence without direct authority to embed privacy-by-design into technical architectures and resolve complex false-positive escalations gracefully.
Skills & Requirements:- Bachelor's Degree, IT, Computer Science, Law, or Information Security
- 7+ years in Data Governance, Privacy Engineering, Information Security, or a related field
- Strong understanding of LLMs, OneTrust, and generating requirements for DSPM/DLP tools. Deep knowledge of GDPR, CCPA, and emerging frameworks (NIST, EU AI Act).
Preferred:- Master's Degree or JD, Privacy Engineering
- 10+ years acting as a functional lead in GRC or Privacy architecture
- CIPP/E, CIPT, CISSP, or equivalent certifications preferred.
ModMed Benefits Highlight: At ModMed, we believe it's important to offer a competitive benefits package designed to meet the diverse needs of our growing workforce. Eligible Modernizers can enroll in a wide range of benefits:
United States- Comprehensive medical, dental, and vision benefits, including a company Health Savings Account contribution,
- 401(k): ModMed provides a matching contribution each payday of 50% of your contribution deferred on up to 6% of your compensation. After one year of employment with ModMed, 100% of any matching contribution you receive is yours to keep.
- Generous Paid Time Off and Paid Parental Leave programs,
- Company paid Life and Disability benefits, Flexible Spending Account, and Employee Assistance Programs,
- Company-sponsored Business Resource & Special Interest Groups that provide engaged and supportive communities within ModMed,
- Professional development opportunities, including tuition reimbursement programs and unlimited access to LinkedIn Learning,
- Global presence and in-person collaboration opportunities; dog-friendly HQ (US), Hybrid office-based roles and remote availability for some roles,
- Weekly catered breakfast and lunch, treadmill workstations, Zen, and wellness rooms within our BRIC headquarters.