Confidential mandate
Privacy-Engineering Board Examiner — Virtual Care
Planned Hiring / New
Privacy-Engineering Board Examiner mandate in Lisbon, Portugal · Virtual Care Platforms
A Portuguese virtual-care network seeks a nine-month board examiner to challenge privacy engineering in connected care journeys, sharpening architectural decisions without assuming clinical, compliance or executive authority.
The mandate
The board repeatedly asks whether new remote-monitoring and triage journeys are privacy-safe by design or merely surrounded by consent screens and policy controls. Data moves among devices, care teams, algorithm providers and patient support, while deletion, secondary use and caregiver access behave differently across products. Current compliance reporting does not reveal what the architecture prevents, detects or leaves to user behaviour.
The adviser will reserve two days each month for chair preparation, product-architecture challenge and paper review, plus four scheduled committee meetings. A written perspective on a material privacy incident or high-risk launch is expected within one Portuguese business day. Formal impact assessment, incident investigation or supervisory engagement beyond board challenge requires a separately authorised and conflict-reviewed scope.
The appointment runs nine months from February 2027. In month seven, the committee will review whether product and privacy leaders can apply the agreed engineering questions independently. The board may approve one three-month extension tied to a named launch, but management cannot renew the retainer, carry time forward or use advisory days as embedded privacy-engineering capacity.
This appointment holds no line authority, executive responsibility, data-protection-officer delegation, clinical sign-off, product approval or incident command. The adviser can challenge design and evidence but cannot determine lawful basis or speak for the organisation. Product, clinical, security and privacy executives retain their decisions, including recorded acceptance of residual risk after advice.
Two other non-competing appointments are permissible. Relationships with virtual-care providers, device makers, identity services, analytics vendors, insurers or regulators must be disclosed, alongside relevant investments and expert-network work. A paid role with a product supplier under selection requires recusal; overlapping access to patient or product strategy may be disqualifying even with formal information barriers.
Why the board wants this voice
The committee understands clinical governance and privacy law but lacks a practitioner who has embedded minimisation, separation and lifecycle control into care platforms. Management papers consequently describe compliance activities rather than testable system behaviour. Directors want an independent examiner able to connect architecture, patient agency and operational exception without becoming a substitute DPO or product executive.
What you will own
- Press directors to map patient, caregiver, clinician, support and algorithm journeys before accepting product-level privacy assurances.
- Test whether collection, inference, retention, deletion, access and secondary-use controls behave consistently across device, edge, platform and partner boundaries.
- Challenge consent designs where refusal, withdrawal, delegated access or emergency care creates a materially different technical path.
- Shape evidence thresholds for data minimisation, purpose separation, privacy defaults, re-identification risk and verified downstream deletion.
- Probe incident readiness for misdirected care data, compromised caregiver accounts, vendor retention and inference beyond the communicated purpose.
- Frame board decisions where clinical continuity, patient agency, fraud prevention and strict deletion point toward different architecture choices.
- Coach committee members to distinguish technical prevention, detectable violation, contractual obligation and residual dependence on human behaviour.
Candidate qualifications
- Led privacy engineering for digital health, connected devices, financial services or another sensitive multi-party product environment.
- Implemented minimisation, consent, deletion and purpose-separation controls across device, cloud and external processor boundaries.
- Challenged a compliant-looking design because actual system or exception behaviour contradicted the stated patient or user choice.
- Worked with clinical, product, security, legal and data-protection leaders while preserving their separate accountable decisions.
- Presented architecture-level privacy evidence to a board or regulator without turning a technical review into legal certification.
- Managed conflicts across technology suppliers, sensitive-data organisations, investors and public authorities in portfolio work.
Non-negotiables
- Can attend all four Lisbon committee meetings in person despite remote delivery of the regular two-day monthly cadence.
- Will disclose healthcare, device, identity, analytics, insurance and regulatory relationships before reviewing confidential product designs.
- Accepts that clinical, lawful-basis, DPO, product and incident decisions remain with authorised client executives.
- Must bring implemented privacy controls; privacy policy, legal or audit work without engineering accountability is insufficient.
- 49 words maximum. Describe a consent-compliant care journey whose technical exception undermined the intended patient choice.
- 49 words maximum. Which current healthcare, device, identity or analytics relationships could conflict with this appointment?
- 49 words maximum. How would you test deletion across device, platform, derived data and an external clinical processor?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.