Dassault Systemes

Privacy and RAI Engineer

Dassault Systemes$114K — $153K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in privacy engineering, data governance, or technical compliance, preferably in healthcare or life sciences
  • Solid understanding of data protection frameworks like GDPR, HIPAA, and state privacy laws
  • Familiarity with AI governance frameworks including NIST AI RMF and EU AI Act requirements
  • Hands-on experience with privacy engineering techniques such as data minimization and de-identification
  • Proven ability to translate legal requirements into actionable technical specifications
  • Experience contributing to DPIAs/PIAs and cross-functional data protection reviews
  • Strong communication skills for effective documentation and presentation to varied audiences

Responsibilities

  • Design and implement technical privacy controls in Medidata's software development lifecycle
  • Lead Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for new or modified products
  • Collaborate to ensure compliance with data protection frameworks for clinical trial and sponsor datasets
  • Document AI system risk assessments and algorithmic impact analyses for AI products
  • Support legal obligations under laws such as the EU AI Act and prepare documentation for high-risk AI use cases
  • Track regulatory obligations and manage ongoing compliance activities
  • Serve as a subject matter expert for client security assessments and vendor due diligence

Benefits

  • Medical, dental, life and disability insurance
  • 401(k) matching
  • Flexible paid time off
  • 10 paid holidays per year
  • Family leave provisions
Full Job Description
Location: This is a hybrid remote/in-office role based in NYC

About the Team:

This is an opportunity to be part of the Privacy & AI team tackling some of the most complex questions at the intersection of privacy & AI law, technology and life sciences as part of our tight-knit, dynamic legal department at our U.S. headquarters in New York City. We're seeking a Privacy & AI Engineer to further mature our Privacy & AI Program. This role reports directly to Medidata's VP, Associate General Counsel, Privacy & AI, working closely with our highly collaborative, cross-functional partners. As a member of the broader legal team, you will play a pivotal role in (i) translating legal and regulatory requirements into product-embedded technical controls that our cross-functional partners can act upon, (ii) maturing our privacy and responsible AI programs in collaboration with our cross-functional partners, and (iii) further developing operational efficiencies of the broader legal and regulatory teams leveraging existing third-party tools, including generative AI service providers.

Responsibilities:

Privacy Engineering & Technical Implementation:
  • Support the design and implementation of technical privacy controls across Medidata's software development lifecycle (SDLC) in collaboration with partners in R&D, engineering, data science and information security.
  • Lead Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for new and materially modified products, with particular attention to personal data processing and AI/ML components.
  • Collaborate with partners in information security to evaluate and advise on the architecture of data flows involving clinical trial subject data, real-world data inputs, and sponsor datasets for compliance with applicable data protection frameworks.

Responsible AI Governance:
  • Partner with the AI product and data science teams to document AI system risk assessments and algorithmic impact analyses for Medidata AI products, including classification of systems under the EU AI Act risk tiers, NIST AI RMF governance mapping, and ISO 42001 standard.
  • Support Medidata's obligations under laws like the EU AI Act - including documentation, human oversight design, incident reporting readiness, and Fundamental Rights Impact Assessment (FRIA) scoping for high-risk AI use cases in clinical contexts.
  • Track applicable regulatory obligations, and the status of ongoing compliance activities across product lines.
  • Collaborate with cross-functional partners to generate model cards, and AI system disclosures to support both internal governance and client-facing transparency commitments, including enterprise AI data sheet responses.

Privacy Operations & Technical Program Management Support:
  • Support the Privacy Program Manager in evolving technical components of Medidata's privacy program infrastructure, including data mapping tooling, consent management platforms, and privacy management software (e.g., TrustArc or equivalent).
  • Collaborate with our privacy counsels to track regulatory developments and prepare technical briefings for the VP, Associate General Counsel, Privacy & AI and Chief Legal Officer on emerging privacy engineering and AI governance obligations relevant to Medidata's business.
  • Support the Privacy & AI team in responding to Data Subject Access Requests (DSARs) and data rights exercises involving clinical trial participants - including technical scoping, data mapping, and workflow automation.
  • Serve as a technical privacy and AI subject matter expert in client security and privacy assessments, vendor due diligence reviews, and responses to enterprise RFPs and information security questionnaires.
  • Support the broader legal team with initiatives relating to further adoption of AI in daily operations.

Qualifications:
  • 6+ years of experience in privacy engineering, data governance, or a related technical compliance role - preferably within a healthcare, life sciences, or enterprise SaaS organization.
  • Demonstrated understanding of data protection frameworks relevant to clinical research and/or healthcare contexts, including GDPR, HIPAA, UK GDPR, LGPD and US State Consumer Health Privacy Laws.
  • Working familiarity with AI governance frameworks, including NIST AI RMF 1.0, ISO 42001, and EU AI Act deployer, producer and provider obligations.
  • Hands-on experience with privacy engineering techniques such as data minimization, de-identification, pseudonymization, access control design, and audit logging.
  • Ability to translate complex legal and regulatory requirements into actionable technical specifications and product controls.
  • Experience contributing to or leading DPIAs/PIAs and cross-functional data protection reviews.
  • Strong oral and written communication skills with ability to produce clear policy documents, technical briefs, and executive-ready summaries for different audience types such as legal and/or R&D leadership personas.
  • Experience with privacy management platforms (e.g., OneTrust, Osano, Securiti) or data catalog/lineage tools.
  • Experience with implementing generative AI service provider tools like Claude, Gemini or ChatGPT.
  • Familiarity with open agentic AI standards including MCP, A2A, and emerging agent orchestration frameworks with particular attention to their data access, permissioning, and audit implications.
  • IAPP Certification(s): CIPT (Certified Information Privacy Technologist)
  • IAPP certification(s): AIGP, CIPP/E, CIPP/US, or CIPM.
  • Experience with clinical trial software (EDC, CTMS, eClinical platforms), RWD, and regulated healthcare IT environments.
  • Familiarity with HITRUST, HDS 2.0, NHS DSPT, FedRAMP, or similar security certification frameworks with privacy control intersections.
  • Prior experience with AI product governance, including model risk management, algorithmic bias assessment, or fairness/explainability tooling.
  • Proficiency in Python or equivalent scripting language for privacy automation, data analysis, or tooling development.
  • Bachelor's degree required, preferably in Computer Science, Information Systems, Data Science, or a related technical field.
  • Advanced degree in law, information privacy, or a relevant technical discipline is a plus. Equivalent professional experience and certification will be considered.

As with all roles, Medidata sets ranges based on a number of factors including function, level, candidate expertise and experience, and geographic location.

The salary range for positions that will be physically based in the NYC Metro Area is $114,750-153,000.

Base pay is one part of the Total Rewards that Medidata provides to compensate and recognize employees for their work. Most sales positions are eligible for a commission on the terms of applicable plan documents, and many of Medidata's non-sales positions are eligible for annual bonuses. Medidata believes that benefits should connect you to the support you need when it matters most and provides benefits, including medical, dental, life and disability insurance, 401(k) matching, family leave, flexible paid time off; and 10 paid holidays per year.

#LI-EM1

#LI-Hybrid

Salary Pay Transparency

Compensation for the role will be commensurate with experience. The total expected compensation range will be between $114750 and $153000, representing the base salary (or annualized salary based on estimated hourly compensation) and target bonus.

About Dassault Systemes

Dassault Systemes SE is a French software company that specializes in the production of 3D design software, 3D digital mock-up and product lifecycle management (PLM) solutions. The company was founded in 1981 by Avions Marcel Dassault to develop computer-aided design (CAD) software for their own use. The company's software is used by a variety of industries, including aerospace, automotive, consumer goods, and industrial machinery. Dassault Systemes is headquartered in Velizy-Villacoublay, France and has offices in over 80 countries.
Learn more about Dassault Systemes
Size
20,000 employees
Industry

Similar Jobs

More Jobs at Dassault Systemes

More Information Technology Jobs

Find similar Privacy and RAI Engineer jobs: