Lead Privacy Engineer / Technical De-Identification Architect
Remote
Contract
Role Summary
We are seeking a Lead Privacy Engineer / Technical De-Identification Architect to design, implement, and operationalize advanced de-identification, anonymization, pseudonymization, and encryption capabilities for Project Trinity. This role will be responsible for translating privacy, regulatory, security, and data usability requirements into technical controls that can be deployed across platform architecture, ingestion frameworks, data processing pipelines, and governed data access patterns.
This is a highly technical role requiring expertise in privacy engineering, secure data architecture, cryptographic controls, data transformation frameworks, and pipeline integration. The individual will define and implement de-identification and encryption strategies for sensitive datasets across structured, semi-structured, image, text, and machine-generated data, while supporting region-specific requirements where U.S. and international approaches may converge or diverge. The role will also drive vendor evaluation, workflow certification, residual risk scoring, runbook development, and production-scale execution for approved use cases.
Validation: this role summary is more technical and now explicitly includes encryption architecture and engineering expectations.
Preferred Qualifications
- Experience working with healthcare, clinical, imaging, machine, or medical device data in regulated environments
- Familiarity with privacy and data protection frameworks relevant to HIPAA, GDPR, pseudonymization, anonymization, and cross-border data handling
- Experience with cloud security and data services in AWS, including KMS/HSM-integrated architectures and secure pipeline design
- Experience with tokenization platforms, data discovery/classification tools, DLP-aligned controls, or privacy engineering toolchains
- Experience assessing re-identification risk and defining operational release thresholds for governed datasets
- Familiarity with structured, semi-structured, text, and image-based data de-identification methods
- Experience supporting global implementations where regional data handling patterns vary by jurisdiction
- Experience with synthetic data generation and validation for privacy control testing
Technical Skills
- De-identification, anonymization, pseudonymization, tokenization
- Field-level, column-level, and object-level encryption
- Key management, secrets management, certificate lifecycle concepts
- Privacy engineering and secure data architecture
- ETL/ELT, ingestion pipelines, workflow orchestration
- Metadata-driven controls and schema enforcement
- Risk scoring and residual re-identification analysis
- Structured and unstructured data transformation
- Technical vendor assessment and proof-of-concept design
- Architecture documentation and operational runbooks