Confidential mandate
Privacy-Enhancing Technology Deployment Director — Health Research Network
Planned Hiring / New
Privacy-Enhancing Technology Deployment Director mandate in Copenhagen, Denmark · Health Research Infrastructure
A Copenhagen research network needs an independent director to deploy privacy-enhancing analytics across hospitals, prove utility and disclosure controls, and deliver an accepted operating model within six months.
The mandate
Hospitals cannot pool sensitive cohorts, while a proposed analytics programme has not shown that privacy technology preserves valid research results. Rare-disease queries create small-cell disclosure risk, model updates may leak membership and institutional teams differ in their ability to operate cryptographic infrastructure. The defined problem is to deploy and test a bounded federated or protected-analysis pathway, not redesign all health-data governance.
Deliverables include use-case threat models, technique selection, architecture, privacy parameters, utility tests, disclosure controls, operating procedures and ethics evidence. The design must show who can submit a query, inspect intermediate results, spend a privacy budget, rotate keys, investigate misuse and stop analysis when cohort characteristics make output unsafe.
Milestone one on 30 October 2026 accepts use cases and threat models; milestone two on 18 December delivers prototype and quantified risk analysis; milestone three on 26 February 2027 concludes hospital pilots; final delivery on 31 March requires utility, attack and operator acceptance. Each institution signs its evidence before the corresponding invoice.
Acceptance requires approved queries to reproduce, privacy leakage tests to remain below threshold, statistical utility to meet researcher tolerances and hospital teams to operate the flow unaided. Reviewers will test a prohibited small cohort, a malicious participant update and key loss; the system must block or recover as designed without exporting identifiable records.
The client research network provides governed datasets, research protocols, secure environments and decision owners, with ethics and privacy questions resolved within agreed milestone windows. The consultant cannot approve research, determine lawful basis or move identifiable data outside authorised boundaries; institutional investigators remain responsible for scientific interpretation.
Why this is external work
Privacy and research teams favour different definitions of success. Internal engineers lack deployment experience across institutional boundaries. Independent delivery joins mathematical claims to operational and scientific acceptance.
What you will own
- Select bounded use cases whose privacy, disclosure, statistical utility and scientific reproducibility questions are independently measurable.
- Threat-model membership, reconstruction, linkage, malicious-participant, insider and output-disclosure risks for each research use case.
- Choose federated, differential, cryptographic or trusted-execution patterns with explicit privacy, utility, performance and operating trade-offs.
- Define parameters, participant authentication, key custody, query approval, output review and privacy-budget governance.
- Test scientific utility against accepted central or reference analysis.
- Conduct reconstruction, poisoning, membership and operator-misuse tests across hospital operating boundaries, role changes and failure states.
- Transfer architecture, parameter decisions, controls, attack evidence and runbooks through independently institution-operated analyses.
Candidate qualifications
- Deployed privacy-enhancing analytics across multiple health or regulated research institutions with independent ethics and privacy governance.
- Can evidence quantitative privacy leakage and statistical utility acceptance together for a live research use case.
- Implemented federated learning, differential privacy, secure computation or trusted execution beyond a laboratory demonstration.
- Governed keys, participant identity, queries, outputs, privacy budgets and emergency suspension operationally.
- Worked with researchers, ethics bodies, privacy officers, hospital data custodians and platform engineers through acceptance.
- Handed a production PET workflow to independent institutional teams.
Non-negotiables
- Available across Copenhagen, Aarhus and Stockholm milestones.
- Independent of PET vendors proposed for selection.
- Will not infer legal basis or research approval.
- Has principal or director-level privacy engineering authority.
- 49 words maximum. Which PET deployment produced an unacceptable utility loss and why?
- 49 words maximum. Describe a privacy leakage test that changed technical parameters.
- 49 words maximum. What operator evidence proves a multi-hospital workflow is accepted?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.