Role OverviewThe selected professional will evaluate the effectiveness and maturity of privacy policies, procedures, controls, documentation, and operational practices, with particular emphasis on NIST SP 800-53 Revision 5 privacy controls.
What You Will Do
Review Privacy Impact Assessments (PIAs), Systems of Records Notices (SORNs), Privacy Act Statements, data inventories, policies, procedures, and supporting control evidence; assess implementation and effectiveness of applicable privacy controls; identify privacy risks and control deficiencies; develop actionable remediation recommendations; and prepare assessment documentation and executive-level findings.
Why It Might Be a Fit
This position requires substantive hands-on federal privacy assessment experience. The successful candidate should demonstrate strong working knowledge of NIST SP 800-53 Rev. 5 privacy controls, federal privacy program assessment methodologies, and federal data inventories.
Requirements
- Active Certified Information Privacy Professional/United States (CIPP/US) certification maintained through the International Association of Privacy Professionals (IAPP)
- Minimum five years of experience conducting privacy assessments for federal agencies
- Demonstrated experience evaluating federal privacy programs, privacy controls, and associated documentation
- In-depth understanding of compliance issues associated with federal privacy legislation, directives, regulations, policies, and federal guidance
- Minimum five years of experience utilizing NIST SP 800-53 Rev. 5 privacy-assessor knowledge and application
- Demonstrated experience reviewing documentation used by a federal Privacy Office to satisfy applicable NIST SP 800-53 Rev. 5 privacy controls
- Experience assessing privacy controls within a mid-sized federal agency or comparable environment with a Moderate security categorization
- Demonstrated ability to determine whether privacy controls are adequately documented, implemented, supported by objective evidence, and operating effectively
- Experience developing control assessment results that map findings to specific NIST SP 800-53 Rev. 5 privacy controls
- Experience developing and/or supporting Plans of Action and Milestones (POA&Ms) addressing missing, incomplete, or inadequate controls and documentation
- Experience developing actionable remediation recommendations for federal Privacy Offices
- Experience preparing formal privacy assessment reports that document assessment methodology, findings, supporting evidence, risk ratings, and recommendations
- Experience incorporating Government review comments into final assessment documentation
- Experience developing and delivering executive-level briefings summarizing privacy risks, findings, and remediation priorities
- Ability to communicate technical and regulatory privacy issues to both technical stakeholders and executive leadership
]]>