
Federal Privacy Assessor, CIPP/US Certified
Posted Aug 21

Posted Aug 21
This is a fully remote position, open to applicants in Washington.
• Plan and carry out an independent evaluation of a federal agency's privacy program.
• Create and uphold the assessment plan, encompassing scope, methodology, schedule, evidence requirements, and stakeholder engagement.
• Analyze the design, implementation, and effectiveness of relevant privacy controls.
• Review privacy governance frameworks, policies, procedures, standards, and supporting documents.
• Evaluate the consistency of documented privacy practices with federal mandates and agency protocols.
• Identify privacy risks, gaps, weaknesses, inconsistencies, and deficiencies in controls.
• Ensure evidence-based traceability among criteria, evidence, findings, risk ratings, and recommendations.
• Assess and map NIST SP 800-53 Rev. 5 privacy controls.
• Review PIAs, SORNs, Privacy Act Statements, data inventories, policies, procedures, control documentation, data-use and information-collection documentation, data flows, records retention, data sharing, data minimization, risk documentation, and POA&Ms.
• Assign Low, Moderate, and High risk ratings while evaluating operational and compliance significance.
• Formulate prioritized remediation recommendations and assist in the development or refinement of POA&Ms.
• Conduct interviews and collaborative sessions with Privacy Office personnel, system owners, security staff, program stakeholders, and subject matter experts.
• Request, review, and verify evidence; address evidence gaps and clarify control implementation.
• Convey preliminary observations and findings and assist with Government review and adjudication.
• Compile draft and final privacy assessment reports that include scope, methodology, findings, evidence, risk ratings, deficiencies, corrective actions, and remediation priorities.
• Create and present executive-level briefings for senior leadership.
• Ensure that assessment documentation and presentation materials meet Section 508 accessibility standards.
• Active Certified Information Privacy Professional/United States (CIPP/US) certification, maintained through the International Association of Privacy Professionals (IAPP).
• At least five years of experience conducting privacy assessments for federal agencies.
• Proven experience in evaluating federal privacy programs, privacy controls, and related documentation.
• Comprehensive understanding of federal privacy legislation, directives, regulations, policies, and guidance.
• Demonstrated experience in planning and executing privacy assessments from initial scoping to final findings and executive reporting.
• Minimum of five years of experience applying NIST SP 800-53 Rev. 5 privacy assessor knowledge.
• Experience in reviewing federal Privacy Office documentation that meets NIST SP 800-53 Rev. 5 privacy controls.
• Experience assessing privacy controls within a mid-sized federal agency or a similarly categorized Moderate security environment.
• Ability to determine if privacy controls are adequately documented, implemented, supported by objective evidence, and functioning effectively.
• Experience in mapping findings to specific NIST SP 800-53 Rev. 5 privacy controls.
• Experience developing or assisting with POA&Ms and actionable remediation recommendations.
• Experience in preparing formal privacy assessment reports and incorporating comments from Government reviews.
• Experience in crafting and delivering executive-level briefings.
• Capability to communicate technical and regulatory privacy issues to technical stakeholders and executive leadership.
• Strong working knowledge of NIST SP 800-53 Rev. 5 privacy controls, federal privacy assessment methodologies, Privacy Act requirements, PIAs, SORNs, Privacy Act Statements, data inventories, privacy risk analysis, control testing, evidence evaluation, data minimization, records retention, information sharing, data-flow analysis, POA&M development, federal assessment reporting, and executive communication.
• Must be eligible to successfully complete a National Agency Check with Inquiries (NACI).
• Must comply with Government regulations regarding the handling of sensitive, proprietary, Privacy Act, and Government information.
• Must maintain strict confidentiality.
• Active DoD Secret clearance is preferred but not mandatory.
• Comprehensive benefits package including health, dental, and vision insurance.
• Retirement plans with employer contributions.
• Opportunities for professional development and continuing education.
• Flexible work hours and remote work options.
NEVER ENDING TRAVELS
Float Health
Innovaderm Research Inc.
Mercor
Get handpicked remote jobs straight to your inbox weekly.