Privacy and RAI Engineer
Listed on 2026-09-05
-
IT/Tech
Information Security & Data Protection, AI Engineer (Applied/Software), Data Analyst, Cybersecurity
Location
: This is a hybrid remote/in-office role based in NYC
Medidata follows a hybrid office policy in which employees who are hired for an in-person position are expected to work on site a certain number of days per week following Company policy.
About our Company
:
Medidata is powering smarter treatments and healthier people through digital solutions to support clinical trials. Celebrating over 25 years of ground-breaking technological innovation across more than 38,000 trials and 12 million patients, Medidata offers industry-leading expertise, analytics-powered insights, and one of the largest clinical trial data sets in the industry. More than 1 million registered users across approximately 2,300 customers trust Medidata's seamless, end-to-end platform to improve patient experiences, accelerate clinical breakthroughs, and bring therapies to market faster.
A Dassault Systèmes brand (Euronext Paris: FR0014003TT8, DSY.PA), Medidata is headquartered in New York City and has been recognized as a Leader by Everest Group and IDC. Discover more at . Listen to our latest podcast, from Dreamers to Disruptors , and follow us at @Medidata.
About the Team
:
This is an opportunity to be part of the Privacy & AI team tackling some of the most complex questions at the intersection of privacy & AI law, technology and life sciences as part of our tight-knit, dynamic legal department at our U.S. headquarters in New York City. We're seeking a Privacy & AI Engineer to further mature our Privacy & AI Program.
This role reports directly to Medidata's VP, Associate General Counsel, Privacy & AI, working closely with our highly collaborative, cross-functional partners. As a member of the broader legal team, you will play a pivotal role in (i) translating legal and regulatory requirements into product-embedded technical controls that our cross-functional partners can act upon, (ii) maturing our privacy and responsible AI programs in collaboration with our cross-functional partners, and (iii) further developing operational efficiencies of the broader legal and regulatory teams leveraging existing third-party tools, including generative AI service providers.
Responsibilities
:
Privacy Engineering & Technical Implementation:
Support the design and implementation of technical privacy controls across Medidata's software development lifecycle (SDLC) in collaboration with partners in R&D, engineering, data science and information security.
Lead Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for new and materially modified products, with particular attention to personal data processing and AI/ML components.
Collaborate with partners in information security to evaluate and advise on the architecture of data flows involving clinical trial subject data, real-world data inputs, and sponsor datasets for compliance with applicable data protection frameworks.
Responsible AI Governance:
Partner with the AI product and data science teams to document AI system risk assessments and algorithmic impact analyses for Medidata AI products, including classification of systems under the EU AI Act risk tiers, NIST AI RMF governance mapping, and ISO 42001 standard.
Support Medidata's obligations under laws like the EU AI Act — including documentation, human oversight design, incident reporting readiness, and Fundamental Rights Impact Assessment (FRIA) scoping for high-risk AI use cases in clinical contexts.
Track applicable regulatory obligations, and the status of ongoing compliance activities across product lines.
Collaborate with cross-functional partners to generate model cards, and AI system disclosures to support both internal governance and client-facing transparency commitments, including enterprise AI data sheet responses.
Privacy Operations & Technical Program Management Support:
Support the Privacy Program Manager in evolving technical components of Medidata's privacy program infrastructure, including data mapping tooling, consent management platforms, and privacy management software (e.g., Trust Arc or equivalent).
Collaborate with our privacy counsels to track regulatory developments and prepare technical…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).