Medidata Solutions

Privacy and RAI Engineer

Medidata Solutions$114K — $153K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in privacy engineering, data governance, or technical compliance, ideally in healthcare or SaaS sectors.
  • Understanding of data protection laws relevant to clinical research like GDPR and HIPAA.
  • Familiar with AI governance frameworks and relevant EU obligations.
  • Experience conducting DPIAs/PIAs and work with privacy management software.
  • Proficiency in Python or similar scripting language for privacy automation.

Responsibilities

  • Support design and implementation of technical privacy controls in the software development lifecycle.
  • Lead and conduct Privacy Impact Assessments for new or updated products focusing on personal data and AI/ML.
  • Collaborate on assessing data flow architectures for compliance with regulations.
  • Document risk assessments for AI systems and support compliance with the EU AI Act.
  • Track regulatory obligations and update compliance status across products.
  • Assist in generating model cards and AI disclosures for internal and client transparency.
  • Respond to Data Subject Access Requests and support technical aspects of privacy operations.

Benefits

  • Medical, dental, life and disability insurance.
  • 401(k) matching.
  • Family leave and flexible paid time off.
  • 10 paid holidays per year.
Full Job Description
Location: This is a hybrid remote/in-office role based in NYC

About the Team:

This is an opportunity to be part of the Privacy & AI team tackling some of the most complex questions at the intersection of privacy & AI law, technology and life sciences as part of our tight-knit, dynamic legal department at our U.S. headquarters in New York City. We're seeking a Privacy & AI Engineer to further mature our Privacy & AI Program. This role reports directly to Medidata's VP, Associate General Counsel, Privacy & AI, working closely with our highly collaborative, cross-functional partners. As a member of the broader legal team, you will play a pivotal role in (i) translating legal and regulatory requirements into product-embedded technical controls that our cross-functional partners can act upon, (ii) maturing our privacy and responsible AI programs in collaboration with our cross-functional partners, and (iii) further developing operational efficiencies of the broader legal and regulatory teams leveraging existing third-party tools, including generative AI service providers.

Responsibilities:

Privacy Engineering & Technical Implementation:
  • Support the design and implementation of technical privacy controls across Medidata's software development lifecycle (SDLC) in collaboration with partners in R&D, engineering, data science and information security.
  • Lead Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for new and materially modified products, with particular attention to personal data processing and AI/ML components.
  • Collaborate with partners in information security to evaluate and advise on the architecture of data flows involving clinical trial subject data, real-world data inputs, and sponsor datasets for compliance with applicable data protection frameworks.
Responsible AI Governance:
  • Partner with the AI product and data science teams to document AI system risk assessments and algorithmic impact analyses for Medidata AI products, including classification of systems under the EU AI Act risk tiers, NIST AI RMF governance mapping, and ISO 42001 standard.
  • Support Medidata's obligations under laws like the EU AI Act - including documentation, human oversight design, incident reporting readiness, and Fundamental Rights Impact Assessment (FRIA) scoping for high-risk AI use cases in clinical contexts.
  • Track applicable regulatory obligations, and the status of ongoing compliance activities across product lines.
  • Collaborate with cross-functional partners to generate model cards, and AI system disclosures to support both internal governance and client-facing transparency commitments, including enterprise AI data sheet responses.
Privacy Operations & Technical Program Management Support:
  • Support the Privacy Program Manager in evolving technical components of Medidata's privacy program infrastructure, including data mapping tooling, consent management platforms, and privacy management software (e.g., TrustArc or equivalent).
  • Collaborate with our privacy counsels to track regulatory developments and prepare technical briefings for the VP, Associate General Counsel, Privacy & AI and Chief Legal Officer on emerging privacy engineering and AI governance obligations relevant to Medidata's business.
  • Support the Privacy & AI team in responding to Data Subject Access Requests (DSARs) and data rights exercises involving clinical trial participants - including technical scoping, data mapping, and workflow automation.
  • Serve as a technical privacy and AI subject matter expert in client security and privacy assessments, vendor due diligence reviews, and responses to enterprise RFPs and information security questionnaires.
  • Support the broader legal team with initiatives relating to further adoption of AI in daily operations.
Qualifications:
  • 6+ years of experience in privacy engineering, data governance, or a related technical compliance role - preferably within a healthcare, life sciences, or enterprise SaaS organization.
  • Demonstrated understanding of data protection frameworks relevant to clinical research and/or healthcare contexts, including GDPR, HIPAA, UK GDPR, LGPD and US State Consumer Health Privacy Laws.
  • Working familiarity with AI governance frameworks, including NIST AI RMF 1.0, ISO 42001, and EU AI Act deployer, producer and provider obligations.
  • Hands-on experience with privacy engineering techniques such as data minimization, de-identification, pseudonymization, access control design, and audit logging.
  • Ability to translate complex legal and regulatory requirements into actionable technical specifications and product controls.
  • Experience contributing to or leading DPIAs/PIAs and cross-functional data protection reviews.
  • Strong oral and written communication skills with ability to produce clear policy documents, technical briefs, and executive-ready summaries for different audience types such as legal and/or R&D leadership personas.
  • Experience with privacy management platforms (e.g., OneTrust, Osano, Securiti) or data catalog/lineage tools.
  • Experience with implementing generative AI service provider tools like Claude, Gemini or ChatGPT.
  • Familiarity with open agentic AI standards including MCP, A2A, and emerging agent orchestration frameworks with particular attention to their data access, permissioning, and audit implications.
  • IAPP Certification(s): CIPT (Certified Information Privacy Technologist)
  • IAPP certification(s): AIGP, CIPP/E, CIPP/US, or CIPM.
  • Experience with clinical trial software (EDC, CTMS, eClinical platforms), RWD, and regulated healthcare IT environments.
  • Familiarity with HITRUST, HDS 2.0, NHS DSPT, FedRAMP, or similar security certification frameworks with privacy control intersections.
  • Prior experience with AI product governance, including model risk management, algorithmic bias assessment, or fairness/explainability tooling.
  • Proficiency in Python or equivalent scripting language for privacy automation, data analysis, or tooling development.
  • Bachelor's degree required, preferably in Computer Science, Information Systems, Data Science, or a related technical field.
  • Advanced degree in law, information privacy, or a relevant technical discipline is a plus. Equivalent professional experience and certification will be considered.
As with all roles, Medidata sets ranges based on a number of factors including function, level, candidate expertise and experience, and geographic location.

The salary range for positions that will be physically based in the NYC Metro Area is $114,750-153,000.

Base pay is one part of the Total Rewards that Medidata provides to compensate and recognize employees for their work. Most sales positions are eligible for a commission on the terms of applicable plan documents, and many of Medidata's non-sales positions are eligible for annual bonuses. Medidata believes that benefits should connect you to the support you need when it matters most and provides benefits, including medical, dental, life and disability insurance, 401(k) matching, family leave, flexible paid time off; and 10 paid holidays per year.

Note: Please be on the lookout for job scams. Medidata recruiters will never ask applicants for monetary compensation, credit card, or banking details.

We will accept applications on an ongoing basis until we fill the position.

#LI-EM1

#LI-Hybrid

Similar Jobs

More Jobs at Medidata Solutions

More Information Technology Jobs

Find similar Privacy and RAI Engineer jobs: