LEAD PRIVACY ENGINEER/TECHNICAL DE-IDENTIFICATION ARCHITECT

BIRDSVUE LLC

Dunstable (MA)

Hybrid

USD 130,000 - 210,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

401(k)

Job summary

BirdsVue LLC seeks a Lead Privacy Engineer/Technical De-Identification Architect to design and implement de-identification, anonymization, and encryption across data pipelines. You will bridge policy and technical controls, shaping secure data use in regulated environments.

The role emphasizes architecture, validation, and production operations, with flexible work-from-home options and strong emphasis on cryptographic patterns and data protection engineering.

Qualifications

  • Bachelor’s or Master’s degree in a technical field.
  • 7+ years of privacy and data protection engineering experience.
  • Hands-on experience with de-identification, anonymization, or pseudonymization controls.
  • Strong understanding of cryptographic concepts and encryption patterns.
  • Experience integrating privacy controls into cloud data pipelines and analytics platforms.
  • Ability to translate legal/privacy requirements into technical specs.

Responsibilities

  • Architect de-identification and encryption solutions.
  • Engineer de-identification and anonymization rules.
  • Integrate pipelines and workflows for data processing.
  • Test, validate, and certify privacy controls.
  • Document standards, runbooks, and reference architectures.
  • Provide production support for privacy-related data use.

Skills

Privacy engineering
Security architecture
Data pipeline integration
Schema design
Encryption concepts
Tokenization

Education

Bachelor's or Master's degree in a technical field

Tools

KMS/HSM
Key management
Secrets management
Certificate lifecycle management

Job description

Benefits:

  • 401(k)
Lead Privacy Engineer/Technical De-Identification Architect

Introduction

Responsibilities

  1. Technical architecture for de-identification and encryption
  2. De-identification and anonymization rules engineering
  3. Pipeline integration and workflow implementation
  4. Testing, validation, and certification
  5. Documentation, standards, and operationalization
  6. Production execution and support for use-case data

Requirements

Required Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Data Engineering, Biomedical Informatics, Information Security, or related technical field
  • 7+ years of experience in privacy engineering, data protection engineering, security architecture, data platform engineering, or closely related technical roles
  • Hands‑on experience designing and implementing de-identification, anonymization, or pseudonymization controls for sensitive or regulated data
  • Strong understanding of cryptographic concepts and enterprise encryption patterns, including data‑at‑rest encryption, transport encryption, key management, secrets management, and certificate‑based trust models
  • Experience designing secure handling patterns for identifiers, tokenization systems, mapping tables, and access‑restricted re‑linkage mechanisms
  • Experience integrating privacy and security controls into cloud‑native or enterprise data pipelines, APIs, and analytics platforms
  • Strong technical experience with schema design, transformation logic, metadata‑driven processing, validation rules, and control automation
  • Experience evaluating commercial or open‑source de‑identification or privacy‑enhancing technologies from both architecture and implementation perspectives
  • Ability to convert legal, privacy, and regulatory requirements into enforceable technical specifications and control frameworks
  • Strong documentation skills, including reference architectures, technical standards, interface definitions, and runbooks

Preferred Qualifications

  • Experience working with healthcare, clinical, imaging, machine, or medical device data in regulated environments
  • Familiarity with privacy and data protection frameworks relevant to HIPAA, GDPR, pseudonymization, anonymization, and cross‑border data handling
  • Experience with cloud security and data services in AWS, including KMS/HSM‑integrated architectures and secure pipeline design
  • Experience with tokenization platforms, data discovery/classification tools, DLP‑aligned controls, or privacy engineering toolchains
  • Experience assessing re‑identification risk and defining operational release thresholds for governed datasets
  • Familiarity with structured, semi‑structured, text, and image‑based data de‑identification methods
  • Experience supporting global implementations where regional data handling patterns vary by jurisdiction
  • Experience with synthetic data generation and validation for privacy control testing

Technical Skills

  • De‑identification, anonymization, pseudonymization, tokenization
  • Field‑level, column‑level, and object‑level encryption
  • Key management, secrets management, certificate lifecycle concepts
  • Privacy engineering and secure data architecture
  • ETL/ELT, ingestion pipelines, workflow orchestration
  • Metadata‑driven controls and schema enforcement
  • Risk scoring and residual re‑identification analysis
  • Structured and unstructured data transformation
  • Technical vendor assessment and proof‑of‑concept design
  • Architecture documentation and operational runbooks

The ideal candidate is a deeply technical privacy and data protection engineer who can move from policy and risk requirements into architecture, code‑adjacent design, workflow implementation, control validation, and production operations. They should be comfortable designing encryption and de‑identification controls together, isolating sensitive linkage assets, integrating with platform engineering teams, and building repeatable technical patterns for secure, scalable data use.

Flexible work from home options available.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Privacy Architect - De-Identification & Encryption
Remote Privacy Architect - De-Identification & Encryption

BIRDSVUE LLC • Dunstable (MA)

Hybrid
USD 130,000 - 210,000
401(k)
Data Privacy Lead
Data Privacy Lead

Equifax • Alpharetta (GA)

On-site
USD 90,000 - 130,000
Software Engineer, Data Privacy Technologies
Software Engineer, Data Privacy Technologies

Paradigm Operations LP-AL • Albuquerque (NM)

On-site
USD 90,000 - 140,000
Software Engineer, Data Processing
Software Engineer, Data Processing

Mondo • San Francisco (CA)

On-site
USD 165,312 - 275,520
Health insurance
Dental insurance
Vision insurance
+1
Data Protection & Data Risk Management Lead
Data Protection & Data Risk Management Lead

Apollo Solutions • New York (NY)

On-site
USD 140,000 - 180,000
Sr Data Protection Engineer
Sr Data Protection Engineer

Burtch Works • New York (NY)

On-site
USD 140,000 - 190,000
Data Security Principal Architect
Data Security Principal Architect

Compunnel, Inc. • Cumberland (RI)

On-site
USD 120,000 - 160,000
Cloud Engineer - Enterprise Data Security (Remote - US)
Cloud Engineer - Enterprise Data Security (Remote - US)

Jobgether • United States

On-site
USD 120,000 - 170,000
Competitive compensation and bonus eligibility
Core benefits including medical, dental, vision, and 401(k) with company match
Flexible work environment: fully remote, hybrid, or in-office options
+3
Data Security Engineer
Data Security Engineer

Unisys • United States

On-site
USD 130,000 - 180,000
Software Engineer (Privacy & Data Governance)
Software Engineer (Privacy & Data Governance)

Figure • San Jose (CA)

On-site
USD 150,000 - 350,000