The Data Protection Manager, AI (DPMAI) reviews and advises on compliance aspects and risks of technical solutions that process personal data and involve artificial intelligence, machine learning, or automated decision making (including, but not limited to GenAI-based solutions).
The DPMAI adds technical AI expertise as well as in-depth knowledge of applicable laws, regulations and guidance to BCG’s Data Protection Office and collaborates closely with the DP Office members, Information Security Architects, case teams and functional teams. Activities include consultation, initial assessments, risk and compliance assessments of IT systems, both data protection and data transfer impact assessments, development and review of policies and risk mitigation measures.
The ideal candidate has a background in information security or information technology and data protection with work experience in a data protection team, preferably in a multinational professional services environment.
YOU'RE GOOD AT
1. Responsibility for assessment of applications and services with AI components (Ensuring GDPR, CCPA and other data protection compliance requirements)
2. Identify privacy risks and translate to scalable, pragmatic controls for data collection, storage, access, usage, and deletion, in an AI context
3. Establishing and maintaining guidelines for technical teams and case teams that ensure compliance of technical and organizational data protection measures, including, but not limited to the use of personal data for training and application of AI, security-by-design, privacy-by-default, data minimization, anonymization or pseudonymization
4. Execution of Data Transfer Impact Assessments and Data Protection Impact Assessments
5. Audits of data protection controls (both technical and procedural)
YOU BRING (EXPERIENCE & QUALIFICATIONS)
1. The ideal candidate will have knowledge of data protection laws, regulations, and guidance (e.g., GDPR, DPA 2018, ePrivacy Regulation, CCPA, LGPD), and an IAPP or other certifications.
2. Solid understanding of neural networks and machine learning technologies, including concepts of bias, hallucination and drift
3. Existing knowledge of AI related regulations and guidance documents and the willingness and ability to keep this knowledge updated
4. Experience in carrying out data protection impact assessments
5. Demonstrable IS and IT skills, including software development skills (e.g., Python, C# or C++)
6. Experience with Agile methodologies and product development frameworks
7. Work experience in a multinational organization
8. Ability to research and distil information to solve complex commercial data issues
9. Ability to handle information and business affairs with secrecy and confidentiality as appropriate
10. Proven ability to complete tasks and to effectively manage multiple priorities under time pressure
11. Strong communication skills, both written and verbal; fluent in English
12. Excellent academic credentials
Role requires occasional (<5%) travel to office and Global Services hub locations.
#J-18808-Ljbffr