Dave O'Brien

Product Manager

Suwanee, Georgia, United States19 yrs 5 mos experience
Highly Stable

Key Highlights

  • Expert in building practical AI governance systems.
  • Led privacy engineering for over 550 technologies annually.
  • Deep expertise in privacy and security frameworks.
Stackforce AI infers this person is a Privacy and AI Governance Specialist with extensive experience in SaaS compliance and risk management.

Contact

Skills

Core Skills

Privacy EngineeringRisk AssessmentData GovernanceAccess GovernancePrivacy ComplianceGdpr ComplianceUser Acceptance TestingCompliance CoordinationPrivacy AssessmentPrivacy ProjectsSecurity Services

Other Skills

OneTrustTeam DevelopmentSaaS OnboardingData ClassificationCCPA CompliancePrivacy TrainingVendor AssessmentStakeholder ConsensusAutomated Tools DevelopmentFramework DevelopmentDocumentation AssessmentBusiness DevelopmentClient Relationship BuildingPrivacy ServicesData Privacy

About

I build AI governance systems that help organizations move fast without losing rigor. As AI Governance Lead at EisnerAmper, I design and operationalize enterprise AI governance for professional services—where speed, trust, and professional accountability all matter. My focus isn’t on policy for policy’s sake, but on building practical governance systems that teams actually use: risk assessment workflows, control frameworks, and tools that engage early and scale safely. My work is grounded in established frameworks—NIST AI RMF, Google SAIF, NIST Privacy Framework, ISO 27001/27701—but intentionally implementation-first. I spend as much time translating controls into executable workflows and user stories as I do defining standards. Governance only works when it meets technical teams where they are. I bring deep privacy and security expertise (FIP, CIPP/US, CIPT, CISSP) to AI governance challenges, helping organizations navigate the intersection of AI risk, data protection, security, and regulatory expectations. My guiding principle: AI can scale expertise, but it cannot replace professional accountability. I work closely across technology, legal, risk, HR, and business teams to design governance that is rigorous, auditable, and operationally practical. I’m particularly interested in how governance systems can enable innovation—by reducing ambiguity, surfacing risk early, and aligning incentives toward responsible use.

Experience

19 yrs 5 mos
Total Experience
3 yrs 1 mo
Average Tenure
7 mos
Current Experience

Eisneramper

AI and Data Governance Senior Manager

Sep 2025Present · 7 mos · Suwanee, Georgia, United States · Remote

Deloitte

Senior Manager

Oct 2018Sep 2025 · 6 yrs 11 mos · Suwanee, Georgia, United States

  • Led a remote international team responsible for privacy engineering and risk assessment of 550+ technologies per year using OneTrust, including generative AI technologies.
  • Grew and developed a team of over 20 professionals to address technology risk.
  • Improved privacy compliance processes with customer centric perspective that led to a significant decrease in time required to complete privacy impact assessments.
  • Led all aspects of SaaS identification, onboarding, and configuration for B2B SaaS technologies including OneTrust, Microsoft 365, Smartsheet, Box.com, and Workiva.
  • Led data governance efforts for multiple technologies including legacy shared drives, Microsoft Outlook, SharePoint, and other SaaS tools to improve reliability and accessibility.
  • Led deployment of data classification and encryption technology (Microsoft Azure Information Protection) to over 180k professionals.
  • Implemented access governance controls and process for cross business CRM tool (Salesforce) and 20+ downstream systems.
  • Led CCPA compliance efforts including review of in-scope systems and updates to privacy notices.
  • Managed development and deployment of new hire and annual privacy training.
  • Mentors junior level professionals working on pro bono projects for local non-profits.
Privacy EngineeringRisk AssessmentOneTrustTeam DevelopmentPrivacy ComplianceSaaS Onboarding+5

Unitedhealth group

Compliance Consultant

Jan 2016Oct 2018 · 2 yrs 9 mos · Greater Atlanta Area

  • Led creation of requirements, development, and implementation for Archer product to comply with the General Data Protection Regulation (GDPR). Created requirements for six distinct applications and gained consensus from multiple stakeholders within enterprise. Led user acceptance testing including scenario development, defect tracking, and remediation. Created and executed implementation strategy involving privacy and business stakeholders.
  • Led website and mobile application compliance program. Coordinated compliance efforts among multiple stakeholders across the enterprise. Created automated tools and forms that provided a better user experience.
  • Developed and supported vendor assessment solution based on Fair Information Practice Principles (FIPPs). Tracked completion of assessments, developed monthly scorecard, and presented status to senior leadership.
  • Supported quarterly board of directors reporting for legal and compliance function.
GDPR ComplianceUser Acceptance TestingVendor AssessmentStakeholder ConsensusAutomated Tools Development

Sunera llc

Manager

Oct 2015Jan 2016 · 3 mos · Greater Atlanta Area

  • Led privacy assessment for Aerospace Corporation. Created framework for assessment utilizing Generally Accepted Privacy Principles (GAPP), conducted on-site interviews, assessed documentation, and delivered actionable recommendations.
Privacy AssessmentFramework DevelopmentDocumentation Assessment

Deloitte

Manager

Feb 2012Sep 2015 · 3 yrs 7 mos · Washington D.C. Metro Area

  • Led privacy projects for clients including Royal Philips of the Netherlands, the Department of Health and Human Services (HHS), and the National Institute for Standards and Technology (NIST). Participated in business development activities including proposal writing, development of methodologies, and client relationship building. See projects section below for additional information.
Privacy ProjectsBusiness DevelopmentClient Relationship Building

Sra international

Privacy Analyst

Sep 2007Jan 2012 · 4 yrs 4 mos · Washington D.C. Metro Area

  • Provided security and privacy services for clients including the State Department, the Department of Homeland Security (DHS), the Securities and Exchange Commission (SEC), the Social Security Administration (SSA), and the Department of Veteran’s Affairs (VA). Participated in business development activities including proposal writing, development of methodologies, and client relationship building. See projects section below for additional information.
Security ServicesPrivacy ServicesBusiness Development

Encore legal solutions

Customer Service Representative

Sep 2006Sep 2007 · 1 yr · Washington D.C. Metro Area

  • Supported client relationships with law firms throughout the DC area.

Education

George Mason University

Master's Degree — Public Policy

Jan 2008Jan 2011

Lafayette College

Bachelor of Arts - BA — Government and Law / History

Jan 2002Jan 2006

Stackforce found 100+ more professionals with Privacy Engineering & Risk Assessment

Explore similar profiles based on matching skills and experience