Data Privacy and Responsible AI Manager
Job Summary
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Data Privacy and Responsible AI Manager based in the United States. This senior individual-contributor role sits at the intersection of privacy, technology, cybersecurity, legal compliance, and responsible AI.
About the Role
You will help identify and mitigate privacy risks across enterprise systems, cloud services, SaaS platforms, vendors, and data-sharing arrangements. The role also contributes to the development and operation of a responsible AI governance program. You will advise business, technical, security, and legal stakeholders on complex privacy and emerging technology risks. Your work will help ensure data and AI are used responsibly while supporting innovation in a highly regulated environment.
Responsibilities
- Privacy Risk & Business Advisory: Identify, assess, document, and mitigate privacy risks across enterprise processes, systems, vendors, business initiatives, and third-party relationships, particularly within cloud and SaaS environments.
- PIAs & DPIAs: Independently conduct Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for new or materially changed processing activities, applications, systems, and third-party services.
- Risk Mitigation: Recommend practical, risk-based controls and safeguards covering data collection, use, sharing, retention, international transfers, and third-party processing.
- Contractual Privacy Review: Review Data Processing Agreements (DPAs), Business Associate Agreements (BAAs), and privacy-related contract provisions, identifying risks and recommending appropriate contractual protections.
- Security & Incident Response: Collaborate with Enterprise Security on privacy and security assessments, vendor and third-party risk reviews, and privacy-related incident investigations and documentation.
- Global Privacy Compliance: Apply global privacy and data protection requirements, including HIPAA, GDPR, UK GDPR, and other applicable regulations, supporting compliance reviews and cross-border data transfer assessments.
- Responsible AI Governance: Support the implementation and day-to-day operation of responsible AI governance, including AI risk and impact assessments for AI-enabled tools, services, vendors, and proposed use cases.
- AI Vendor & Technology Risk: Evaluate third-party AI providers, contractual provisions, governance controls, and emerging technology risks in collaboration with Legal, Security, IT, Product, and business stakeholders.
- Regulatory Monitoring: Track emerging AI laws, regulations, standards, and industry developments and contribute to AI policies, governance guidance, training, and documentation.
- Stakeholder Partnership: Translate complex privacy, security, and AI requirements into practical recommendations for technical, business, legal, and security audiences.
- Project Ownership: Independently manage multiple assessments and initiatives, maintain thorough documentation, prioritize competing demands, and drive assigned actions through completion.
Requirements
- Educational Background: Bachelor’s degree or equivalent professional experience in privacy, compliance, information security, risk management, or a related discipline.
- Privacy Experience: Significant hands-on experience conducting PIAs and DPIAs as an individual contributor, combined with practical experience reviewing DPAs and privacy-related contractual clauses.
- Regulatory Expertise: Strong working knowledge of global privacy principles and regulatory expectations, including HIPAA, GDPR, UK GDPR, and international data-transfer requirements.
- Responsible AI: Experience supporting AI governance, responsible AI programs, emerging technology risk management, or related initiatives is preferred, with familiarity with AI and generative AI technologies.
- Technology & Third-Party Risk: Familiarity with cloud services, SaaS risk assessments, vendor management, and third-party technology risks is preferred.
- Security Knowledge: Experience working within or closely alongside an information security function is advantageous.
- Industry Background: Experience in a regulated manufacturing environment, particularly medical devices, healthcare, or life sciences, is preferred.
- Frameworks: Familiarity with security and compliance frameworks such as ISO 27001, SOC 2, or NIST is a plus.
- Certifications: Privacy certifications such as CIPP/E, CIPP/US, CIPM, or CIPT are preferred.
- Skills: Strong analytical and problem-solving abilities, excellent attention to detail, and the capacity to independently manage multiple concurrent assessments.
- Communication: Excellent written and verbal communication skills, with the ability to explain complex privacy, security, and AI concepts clearly to both technical and non-technical stakeholders.
- Ownership: Demonstrated ability to take initiative, prioritize effectively, manage deadlines, and guide work through completion.
Benefits
- Work Arrangement: Remote position within the United States, with a hybrid option available in Madison, Wisconsin.
- Career Development: Opportunity to deepen expertise across data privacy, cybersecurity, responsible AI, technology risk, and regulatory compliance.
- Mission-Driven Work: Contribute to responsible technology practices within an organization focused on improving healthcare and patient outcomes.
- Growth Opportunities: Exposure to evolving privacy regulations, AI legislation, governance frameworks, and emerging technology.
- Flexibility: Remote work environment designed to support effective collaboration and work-life balance.
Application Instructions
How Jobgether Works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
Why Apply Through Jobgether: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans.