
Data Privacy and Responsible AI Manager
Posted Aug 28

Posted Aug 28
This is a fully remote position, open to applicants in United States.
• Identify and evaluate privacy risks across enterprise processes, systems, vendors, and business initiatives.
• Offer practical, risk-based recommendations on data collection, usage, sharing, retention, and international transfers.
• Suggest and document mitigations that align with privacy, security, and enterprise risk management requirements.
• Execute PIAs and DPIAs for new or significantly altered processing activities, systems, applications, and third-party services.
• Document processing activities, evaluate privacy risks, and propose controls and safeguards.
• Coordinate assessments with Security and other key stakeholders, integrating reviews into business processes.
• Review DPAs, BAAs, and privacy-related contract terms for vendors, customers, and partners.
• Assess risks related to data use, sharing, retention, cross-border transfers, and third-party processing.
• Collaborate with Enterprise Security on privacy and security assessments, vendor evaluations, and third-party risk management.
• Assist in privacy-related incident assessments, investigations, and documentation alongside Security and Legal.
• Apply global privacy and data protection regulations, including HIPAA, GDPR, and UK GDPR.
• Aid in compliance reviews and assessments for cross-border data transfers.
• Support the implementation and daily operations of Accuray’s responsible AI program.
• Conduct AI risk and impact assessments for AI-enabled tools, services, vendors, and use cases.
• Collaborate with Legal, Security, GIS, Product, and business stakeholders to address AI-related risks.
• Evaluate third-party AI vendors, contractual provisions, and governance controls.
• Monitor emerging AI laws, regulations, and industry standards, contributing to governance policies, training, and documentation.
• Bachelor’s degree or equivalent professional experience in privacy, compliance, information security, risk management, or a related field.
• Extensive hands-on experience in conducting PIAs and DPIAs as an individual contributor.
• Practical experience in reviewing DPAs and privacy-related contractual clauses.
• Strong understanding of global privacy principles and regulatory expectations.
• Excellent communication skills to engage effectively with business, technical, and security stakeholders.
• Proven ability to take ownership of tasks and drive them to completion.
• Strong analytical capabilities and attention to detail, with the ability to independently handle multiple concurrent assessments.
• Familiarity with AI and Generative AI technologies is preferred.
• Experience in supporting AI governance, responsible AI initiatives, or managing emerging technology risks is preferred.
• Background in a regulated manufacturing environment, especially in medical devices or life sciences, is preferred.
• Understanding of cloud services, SaaS risk assessment, and third-party risk management is preferred.
• Experience working within, or closely aligned to, an information security function is preferred.
• Privacy certifications such as CIPP/E, CIPP/US, CIPM, or CIPT are preferred.
• Familiarity with ISO 27001, SOC 2, or NIST frameworks is preferred.
• Candidates must demonstrate proof of permanent authorization to work in the country of application without sponsorship.
• Some travel (<10%) may be necessary.
• An inclusive and collaborative work environment.
• Equal employment opportunity and consideration regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
anni.care
InnoData
Mercor
Mercor
Get handpicked remote jobs straight to your inbox weekly.