Benefits:
401(k)
Lead Privacy Engineer/Technical De-Identification Architect
Introduction
We are seeking a Lead Privacy Engineer / Technical De-Identification Architect to design, implement, and operationalize advanced de-identification, anonymization, pseudonymization, and encryption capabilities for Project Trinity. This role will be responsible for translating privacy, regulatory, security, and data usability requirements into technical controls that can be deployed across platform architecture, ingestion frameworks, data processing pipelines, and governed data access patterns.
Responsibilities
Technical architecture for de-identification and encryption
De-identification and anonymization rules engineering
Pipeline integration and workflow implementation
Testing, validation, and certification
Documentation, standards, and operationalization
Production execution and support for use-case data
Requirements
Required Qualifications
Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Data Engineering, Biomedical Informatics, Information Security, or related technical field
7+ years of experience in privacy engineering, data protection engineering, security architecture, data platform engineering, or closely related technical roles
Hands-on experience designing and implementing de-identification, anonymization, or pseudonymization controls for sensitive or regulated data
Strong understanding of cryptographic concepts and enterprise encryption patterns, including data-at-rest encryption, transport encryption, key management, secrets management, and certificate-based trust models
Experience designing secure handling patterns for identifiers, tokenization systems, mapping tables, and access-restricted re-linkage mechanisms
Experience integrating privacy and security controls into cloud-native or enterprise data pipelines, APIs, and analytics platforms
Strong technical experience with schema design, transformation logic, metadata-driven processing, validation rules, and control automation
Experience evaluating commercial or open-source de-identification or privacy-enhancing technologies from both architecture and implementation perspectives
Ability to convert legal, privacy, and regulatory requirements into enforceable technical specifications and control frameworks
Strong documentation skills, including reference architectures, technical standards, interface definitions, and runbooks
Preferred Qualifications
Experience working with healthcare, clinical, imaging, machine, or medical device data in regulated environments
Familiarity with privacy and data protection frameworks relevant to HIPAA, GDPR, pseudonymization, anonymization, and cross-border data handling
Experience with cloud security and data services in AWS, including KMS/HSM-integrated architectures and secure pipeline design
Experience with tokenization platforms, data discovery/classification tools, DLP-aligned controls, or privacy engineering toolchains
Experience assessing re-identification risk and defining operational release thresholds for governed datasets
Familiarity with structured, semi-structured, text, and image-based data de-identification methods
Experience supporting global implementations where regional data handling patterns vary by jurisdiction
Experience with synthetic data generation and validation for privacy control testing
Technical Skills
De-identification, anonymization, pseudonymization, tokenization
Field-level, column-level, and object-level encryption
Key management, secrets management, certificate lifecycle concepts
Privacy engineering and secure data architecture
ETL/ELT, ingestion pipelines, workflow orchestration
Metadata-driven controls and schema enforcement
Risk scoring and residual re-identification analysis
Structured and unstructured data transformation
Technical vendor assessment and proof-of-concept design
Architecture documentation and operational runbooks
Success Profile
The ideal candidate is a deeply technical privacy and data protection engineer who can move from policy and risk requirements into architecture, code-adjacent design, workflow implementation, control validation, and production operations. They should be comfortable designing encryption and de-identification controls together, isolating sensitive linkage assets, integrating with platform engineering teams, and building repeatable technical patterns for secure, scalable data use.
andard.
Flexible work from home options available.