Data Privacy and Responsible AI Manager

Posted 4hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Data privacy and responsible AI manager for Accuray’s cancer radiotherapy systems. Assessing privacy, vendor, AI, and regulatory risks across enterprise operations.

Responsibilities:

  • Identify and assess privacy risks across enterprise processes, systems, vendors, and business initiatives
  • Provide practical, risk-based guidance on data collection, use, sharing, retention, and international transfers
  • Recommend and document mitigations aligned with privacy, security, and enterprise risk management requirements
  • Conduct PIAs and DPIAs for new or materially changed processing activities, systems, applications, and third-party services
  • Document processing activities, assess privacy risks, and recommend controls and safeguards
  • Coordinate assessments with Security and other stakeholders and integrate reviews into business processes
  • Review DPAs, BAAs, and privacy-related contract terms for vendors, customers, and partners
  • Assess risks involving data use, sharing, retention, cross-border transfers, and third-party processing
  • Partner with Enterprise Security on privacy and security assessments, vendor reviews, and third-party risk management
  • Support privacy-related incident assessments, investigations, and documentation with Security and Legal
  • Apply global privacy and data protection requirements, including HIPAA, GDPR, and UK GDPR
  • Support compliance reviews and cross-border data transfer assessments
  • Support implementation and daily operation of Accuray’s responsible AI program
  • Conduct AI risk and impact assessments for AI-enabled tools, services, vendors, and use cases
  • Partner with Legal, Security, GIS, Product, and business stakeholders to mitigate AI-related risks
  • Evaluate third-party AI vendors, contractual provisions, and governance controls
  • Monitor emerging AI laws, regulations, and industry standards and contribute to governance policies, training, and documentation

Requirements:

  • Bachelor’s degree or equivalent professional experience in privacy, compliance, information security, risk management, or a related discipline
  • Significant hands-on experience conducting PIAs and DPIAs as an individual contributor
  • Practical experience reviewing DPAs and privacy-related contractual clauses
  • Strong working knowledge of global privacy principles and regulatory expectations
  • Ability to communicate clearly to business, technical, and security stakeholders
  • Ability to take ownership of tasks and guide to completion
  • Strong analytical skills and attention to detail, with the ability to manage multiple concurrent assessments independently
  • Familiarity with AI and Generative AI technologies (preferred)
  • Experience supporting AI governance, responsible AI initiatives, or emerging technology risk management (preferred)
  • Experience in a regulated manufacturing environment, particularly medical devices or life sciences (preferred)
  • Familiarity with cloud services, SaaS risk assessment, and third-party risk management (preferred)
  • Experience working within, or closely aligned to, an information security function (preferred)
  • Privacy certifications such as CIPP/E, CIPP/US, CIPM, or CIPT (preferred)
  • Familiarity with ISO 27001, SOC 2, or NIST frameworks (preferred)
  • Candidates must provide proof of permanent authorization to work in the country of application without sponsorship

Benefits:

  • Some travel (<10%) may be required
  • Inclusive and collaborative work environment
  • Equal employment opportunity and consideration regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status