About the job AI Privacy Engineer - Hybrid Lisbon (1-2 days/week office)
AI Privacy Engineer (GDPR/EU AI Act/LLM) – Hybrid / Lisbon (1-2 days/week)
ABOUT THE OPPORTUNITY
Join a fast-moving Central AI team at one of Europe's largest parcel and logistics networks, operating across ~40 countries, 120+ hubs and 1,600+ depots. This organisation is executing a major, multi-country AI transformation, from Agentic AI platforms and specialised AI Hubs delivering advanced use cases, to Everyday AI tooling (think Microsoft 365 Copilot-scale rollouts) reaching every employee's desk.
This is a newly created, embedded role sitting directly inside AI delivery, not a standalone review function. You will be the first line data protection voice in the room with engineers, product owners and country teams, making AI adoption lawful, defensible and scalable from day one.
Work model: Flexible hybrid based at the office in Lisbon. Initial expectation of 1–2 days per week on-site, with the possibility of reducing to 1–2 visits per month as the role matures.
PROJECT & CONTEXT
The organisation runs a two-engine AI model: specialised AI Hubs building advanced use cases (RAG pipelines, LLM agents, vector stores, tool-use architectures) and an Agentic Platform enabling countries to deploy and run their own agents. Everyday AI tooling across the workforce multiplies data flows that require protection at scale.
You will work hands-on with AI engineers, platform teams and security to embed GDPR and EU AI Act compliance by design — automating controls, building reusable components and ensuring every use case is built with lawful basis, purpose limitation, data minimisation, retention controls and transparency baked in. You partner closely with the Corporate Data Protection function (which owns legal interpretation and approvals), Group CISO, AI Security Engineer, Workplace IT, and country DP and IT leads.
Key areas of responsibility include:
- Owning the AI data protection gate for all Central AI use cases, producing decision-ready evidence and go/no-go recommendations
- Translating GDPR, EU AI Act and internal policy requirements into actionable technical guidance for AI engineers
- Conducting DPIAs and AI risk analyses across LLM, RAG, agent and agentic platform architectures
- Establishing and maintaining structured documentation: data flows, RoPAs, design decisions, controls and safeguards
- Coordinating data subject rights requests involving AI systems and leading readiness for AI-related personal data incidents
- Enabling scalable, auditable compliance governance across a multi-country environment
WHAT WE'RE LOOKING FOR (Required)
- Degree in Computer Science, Engineering or a related technical field, or a fully qualified lawyer in an EU jurisdiction with substantial technology experience
- Additional qualification in law or privacy: LL.B., LL.M., CIPP/E or equivalent EU-recognised credential
- 3+ years of hands-on experience in data protection engineering or privacy roles, ideally in an international corporate environment
- Strong working knowledge of the GDPR — lawful basis, data subject rights, international transfers, accountability obligations
- Solid technical understanding of modern AI systems: LLMs (e.g. GPT-4, Claude), RAG architectures, vector stores (e.g. Pinecone, Azure AI Search), agents and tool-use patterns
- Practical experience conducting DPIAs and managing international data transfers at scale
- Demonstrated ability to challenge solution design and influence technical and non-technical stakeholders at all levels
- Comfortable operating under ambiguity; pragmatic and outcome-driven
- Fluent English (written and spoken) — mandatory
NICE TO HAVE (Preferred)
- Experience in federated or multi-country data protection environments
- Hands-on exposure to LLM or agent platforms: Azure AI Foundry, OpenAI, Anthropic Claude, AWS Bedrock
- Familiarity with Microsoft 365 Copilot data protection considerations or comparable Everyday AI deployments
- Professional certifications: CIPP/E, CIPT, CIPM (IAPP); CDPSE (ISACA); EIPM; PECB; CNIL; BCS; DEKRA or similar
- Experience with AI governance frameworks or model risk management (e.g. NIST AI RMF, ISO 42001)
- Additional European language (German, French, Spanish, Dutch, etc.)
Compensation: €2,200 – €2,900/month net, depending on experience and seniority level.
Why HumanIT people stay (4.4 Glassdoor, 89% recommend)
- 15th month salary
- Health insurance covering your family
- Birthday off
- Mobility program for digital nomads
- Real work-life balance
Full benefits https://www.humanit.pt/careers/#perks
What it's really like https://www.humanit.pt/careers/#work-at