Padmi
Microsoft logo
Microsoft

cloud computing (Azure) · AI and machine learning (Copilot, CoreAI)

Member of Technical Staff - Privacy Engineer, Health

London · OnsitePosted 12 days ago
Software engineeringStaff+Full Time
Apply at Microsoft

Opens the source posting on apply.careers.microsoft.com

Source description

About the role

View original

Be the primary point of contact for privacy, compliance, and regulatory matters within the engineering team - the person product and engineering turn to for guidance, design review, and decisions. Ensure products such as Copilot Health are designed and built in a privacy-preserving way, embedding data minimization, purpose limitation, and privacy-by-design into architecture from the outset. Translate complex health and data-protection regulations - including UK and EU GDPR, HIPAA, and the EU AI Act - into concrete technical requirements, engineering guardrails, and automated, continuously verifiable controls. Lead privacy and security design reviews and threat modeling for new features and models, identifying risks early and architecting practical, scalable mitigations. Design and build foundational privacy infrastructure: data classification, policy-driven access controls, consent and preference management, audit logging, data lineage, and retention and lifecycle controls. Evaluate and apply privacy-enhancing technologies - such as differential privacy, de-identification, secure enclaves, and federated approaches - where they meaningfully reduce risk to users. Build reusable libraries, patterns, and tooling that let every engineer ship privacy-preserving features by default, and raise the team's privacy and compliance fluency through mentorship and clear standards. Partner across legal, compliance, security, and product to balance strong user protections with product velocity, and to support audits, certifications, and regulator-facing evidence. Stay ahead of emerging health-privacy regulation and industry practice, bringing that perspective into roadmaps before requirements become blockers. Extensive professional software engineering experience building and operating production systems at scale, with significant depth in privacy, security, or data protection. Strong programming skills in at least one major language (e.g., C#, Python, Go, Java, or similar) and a track record of shipping reliable backend and infrastructure systems. Demonstrated ability to translate privacy and regulatory requirements (such as GDPR or HIPAA) into technical designs and enforceable controls. Hands-on command of privacy and security fundamentals: privacy-by-design, data minimization, access-control models (RBAC/ABAC), encryption, audit logging, and data lifecycle management. Experience conducting privacy and security reviews, threat modeling, and risk assessments. Excellent cross-functional communication - able to influence product, engineering, legal, and compliance stakeholders and explain trade-offs clearly. Bachelor's degree in Computer Science or a related field, or equivalent practical experience. Experience in health technology (strongly preferred), or in another highly regulated industry such as financial services, government, or insurance (acceptable). Familiarity with health-data standards and governance frameworks (e.g., HIPAA, HITRUST, ISO 27001/27701, NHS data governance, FHIR and clinical data handling). Practical experience applying privacy-enhancing technologies - differential privacy, anonymization/de-identification, secure enclaves, or federated learning. Experience with AI/ML systems and the privacy considerations of training and inference on sensitive data. Experience with cloud platforms (Azure preferred) and large-scale data systems. Relevant certifications such as CIPP/E or CIPT.

More at Microsoft

Related open roles

View all roles