Data Privacy and Responsible AI Manager
Accuray · United States
قدّم وتابع مع أبلاي إيدجGive hope. Give health. Make your mark in the fight against cancer.At Accuray, we make a direct and powerful impact on the lives of cancer patients every day — helping them live longer, better lives. But our commitment to innovation offers a truly unique opportunity: the chance to change the fight against cancer — helping to develop, introduce and support new treatment delivery systems and software that will give new hope and new health to cancer patients and cancer survivors around the world.Accuray develops, manufactures and sells radiotherapy systems for alternative cancer treatments. Our radiation therapy for cancer makes treatment shorter, safer, personalized and more effective, ultimately enabling patients to live longer, better lives.Job DescriptionPOSITION TITLE: Data Privacy and Responsible AI ManagerDEPARTMENT: Accuray Global Legal DepartmentLOCATION: Madison, WI (Hybrid) or Remote (U.S.)Company StatementGive hope. Give health. Make your mark in the fight against cancer.At Accuray, we make a direct and powerful impact on the lives of cancer patients every day — helping them live longer, better lives. But our commitment to innovation offers a truly unique opportunity: the chance to change the fight against cancer — helping to develop, introduce and support new treatment delivery systems and software that will give new hope and new health to cancer patients and cancer survivors around the world.Accuray develops, manufactures and sells radiotherapy systems for alternative cancer treatments. Our radiation therapy for cancer makes treatment shorter, safer, personalized and more effective, ultimately enabling patients to live longer, better lives.SummaryThe Data Privacy and Responsible AI Manager is a senior individual contributor responsible for assessing, advising on, and mitigating privacy risks across enterprise operations and third-party relationships. The role will also support our responsible AI governance program. The role partners with Legal, Security, IT, and business stakeholders to support compliance, risk management, and responsible use of data and AI technologies.The primary focus is on enterprise systems, cloud services, SaaS platforms, vendor relationships, data sharing arrangements, and AI-enabled technologies.REPORTING TO/DEPARTMENT Reports to the , Accuray Global Legal Department with dotted line to the Chief Legal Officer.Essential Duties And ResponsibilitiesPrivacy Risk Assessment & Business AdvisoryIdentify and assess privacy risks across enterprise processes, systems, vendors, and business initiatives. Provide practical, risk-based guidance regarding data collection, use, sharing, retention, and international transfers.Evaluate risks related to data collection, internal use, external sharing, retention, and international transfers, particularly in cloud-based and third-party environments. Recommend and document appropriate mitigations aligned with privacy, security, and enterprise risk management requirements. Privacy Impact Assessments (PIAs) & DPIAsConduct PIAs and DPIAs for new or materially changed processing activities, systems, applications, and third-party services. Document processing activities, assess privacy risks, and recommend appropriate controls and safeguards. Coordinate assessment with Security and other stakeholders and integrate reviews into relevant business processes. Data Processing Agreements & Contractual Privacy ReviewReview DPAs, BAAs, and privacy-related contract terms for vendors, customers, and partners. Assess privacy risks associated with data use, sharing, retention, cross-border transfers, and third-party processing. Provide risk-based recommendations regarding contractual protections, controls, and compliance obligations. Collaboration with Enterprise Security & Incident ResponsePartner with Enterprise Security on privacy and security risk assessments, vendor reviews, and third-party risk management activities.Support privacy-related incident assessments, investigations, and documentation in coordination with Security and Legal. Global Privacy Regulatory ApplicationApply global privacy and data protection requirements, including HIPAA, GDPR, UK GDPR, and other applicable laws. Support compliance reviews, cross-border data transfer assessments, and related documentation. Responsible AI GovernanceSupport the implementation and day-to-day operation of Accuray's responsible AI program.Conduct AI risk and impact assessments for AI-enabled tools, services, vendors, and proposed use cases.Partner with Legal, Security, GIS, Product, and business stakeholders to identify, assess, and mitigate AI-related risks.Support evaluation of third-party AI vendors, contractual provisions, and governance controls.Monitor emerging AI laws, regulations, and industry standards, and contribute to AI governance policies, guidance, training, and documentation.TravelSome travel (<10%) may be required.QualificationsRequiredBachelor’s degree or equivalent professional experience in privacy, compliance, information security, risk management, or a related discipline. Significant hands-on experience conducting PIAs and DPIAs as an individual contributor. Practical experience reviewing DPAs and privacy-related contractual clauses. Strong working knowledge of global privacy principles and regulatory expectations. Ability to communicate clearly to business, technical, and security stakeholders. Ability to take ownership of tasks and guide to completion.Strong analytical skills and attention to detail, with the ability to manage multiple concurrent assessments independently.PreferredExperience supporting AI governance, responsible AI initiatives, or emerging technology risk management, including familiarity with AI and Generative AI technologies.Experience in a regulated manufacturing environment, particularly medical devices or life sciences. Familiarity with cloud services, SaaS risk assessment, and third-party risk management. Experience working within, or closely aligned to, an information security function. Privacy certifications such as CIPP/E, CIPP/US, CIPM, or CIPT. Familiarity with security and compliance frameworks such as ISO 27001, SOC 2, or NIST. WORKING CONDITIONSSedentary Work: This role involves extended periods of sitting and working at a desk, requiring good ergonomic practices.Computer Usage: Proficiency with computers, including software applications and communication tools, is essential for tasks and collaboration.Structured Schedule: This position usually follows regular business hours, promoting a consistent and predictable work routine.To qualify for this position, candidates must be able to furnish proof that they are authorized to work in the country they are applying on a permanent basis without sponsorship.EEO StatementAt Accuray, our commitment to patient-first outcomes drives an inclusive and collaborative work environment where the best ideas rise to the top — and everyone works to push them further. We value diversity in both the professional and personal backgrounds of our employees, as this variety adds rich energy to every team, every project and every work day. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity or national origin – including individuals with disabilities and veterans.