AI Privacy Engineer
About YellowIpe Our mission is to inspire the connection of technology with people; we foster the best in our professionals through our expertise in finding and attracting the best talent for the best projects. Focus on People, Collaboration, and Commitment are the pillars that guide us on this journey. Join the yellow team as our new AI Privacy Engineer! Responsibilities: Translate GDPR regulations, EU AI legislation, and internal data protection requirements into practical technical controls and specific implementation guidelines for AI environments;
Perform Data Protection Impact Assessments (DPIAs) and AI risk assessments for AI solutions and platforms, ensuring that data protection principles are integrated from the start of development;
Ensure that Privacy by Design and Privacy by Default principles are incorporated throughout the entire AI development lifecycle, promoting compliance with data protection standards while supporting innovation;
Proactively collaborate with AI engineering, information security, platform engineering, and product teams to implement privacy controls at scale, continuously seeking improvements and innovations;
Review AI architectures, data flows, and processing activities to identify privacy and compliance risks, and provide detailed and actionable recommendations for mitigation;
Define and monitor mitigation plans for privacy-related risks and compliance gaps, regularly reporting progress to stakeholders;
Support the implementation of data minimization, retention, transparency, legal basis, and purpose limitation requirements, promoting a culture of accountability throughout the organization;
Maintain up-to-date documentation related to AI systems, data processing activities, controls, and compliance evidence, facilitating audits and reviews;
Act as the primary point of contact for privacy issues in AI use cases and provide informed recommendations on project approval or rejection decisions;
Support the management of data subject rights requests and privacy incidents involving AI systems, promoting an environment of trust and security;
Contribute to AI governance initiatives and help establish scalable privacy processes within the organization, including the creation of strategic working forums.
Requirements: Bachelor's or Master's degree in Computer Science, Engineering, Law, or a related field (or equivalent experience), combined with solid experience in Data Protection, Privacy, Technology Law, or AI Governance. Relevant certifications, such as CIPP/E, CIPM, or CIPT, are highly valued;
Minimum of 3 years of experience in Privacy Engineering, Data Protection, AI Governance, Compliance, or Cybersecurity Governance;
Deep knowledge of GDPR and EU data protection principles, with the ability to apply this knowledge in complex technology environments;
Proven experience in conducting DPIAs and privacy risk assessments, with a track record of successful implementation of protection measures;
Solid understanding of AI and Generative AI technologies, including: Large Language Models (LLMs);
Retrieval-Augmented Generation (RAG);
AI Agents;
Vector Databases / Vector Stores;
AI platform integrations;
Experience working with interdisciplinary teams, involving engineering, legal, compliance, and security stakeholders, promoting a collaborative environment;
Strong analytical and documentation skills, as well as stakeholder management skills, capable of negotiating compromises and influencing decisions;
Ability to challenge solution designs with a pragmatic and business-oriented mindset, balancing security and innovation;
Fluency in English is mandatory.
Differentials: Experience with AI platforms such as Azure AI, Azure OpenAI, OpenAI, Anthropic, or similar, including the ability to integrate privacy frameworks into these platforms;
Experience with Microsoft 365 Copilot or AI adoption programs in companies, contributing to maximizing the value of AI technologies;
Familiarity with EU AI legislation and AI governance frameworks, with the ability to help shape robust policies and practices;
Experience in multinational or multicultural environments, adapting privacy strategies to different regulatory contexts;
Certifications such as CIPP/E, CIPM, CIPT, ISO 27701, ISO 27001, or equivalents, demonstrating a commitment to excellence in data protection;
Academic background or practical experience in Privacy Engineering, AI Security, Risk Management, or Data Governance.
Important information: Location: Portugal
Modality: flexible hybrid work;
International environment with global stakeholders, promoting diversity and collaboration;
Candidates must reside in Portugal;
Fluency in English is mandatory.
Application: View the job and apply at YellowIpe