Federal Privacy Assessor (CIPP/US Certified)

Endictus
Washington, DC
Job Description
Role Overview

The selected professional will evaluate the effectiveness and maturity of privacy policies, procedures, controls, documentation, and operational practices, with particular emphasis on NIST SP 800-53 Revision 5 privacy controls.

What You Will Do

Review Privacy Impact Assessments (PIAs), Systems of Records Notices (SORNs), Privacy Act Statements, data inventories, policies, procedures, and supporting control evidence; assess implementation and effectiveness of applicable privacy controls; identify privacy risks and control deficiencies; develop actionable remediation recommendations; and prepare assessment documentation and executive-level findings.

Why It Might Be a Fit

This position requires substantive hands-on federal privacy assessment experience. The successful candidate should demonstrate strong working knowledge of NIST SP 800-53 Rev. 5 privacy controls, federal privacy program assessment methodologies, and federal data inventories.

Requirements

  • Active Certified Information Privacy Professional/United States (CIPP/US) certification maintained through the International Association of Privacy Professionals (IAPP)
  • Minimum five years of experience conducting privacy assessments for federal agencies
  • Demonstrated experience evaluating federal privacy programs, privacy controls, and associated documentation
  • In-depth understanding of compliance issues associated with federal privacy legislation, directives, regulations, policies, and federal guidance
  • Minimum five years of experience utilizing NIST SP 800-53 Rev. 5 privacy-assessor knowledge and application
  • Demonstrated experience reviewing documentation used by a federal Privacy Office to satisfy applicable NIST SP 800-53 Rev. 5 privacy controls
  • Experience assessing privacy controls within a mid-sized federal agency or comparable environment with a Moderate security categorization
  • Demonstrated ability to determine whether privacy controls are adequately documented, implemented, supported by objective evidence, and operating effectively
  • Experience developing control assessment results that map findings to specific NIST SP 800-53 Rev. 5 privacy controls
  • Experience developing and/or supporting Plans of Action and Milestones (POA&Ms) addressing missing, incomplete, or inadequate controls and documentation
  • Experience developing actionable remediation recommendations for federal Privacy Offices
  • Experience preparing formal privacy assessment reports that document assessment methodology, findings, supporting evidence, risk ratings, and recommendations
  • Experience incorporating Government review comments into final assessment documentation
  • Experience developing and delivering executive-level briefings summarizing privacy risks, findings, and remediation priorities
  • Ability to communicate technical and regulatory privacy issues to both technical stakeholders and executive leadership
]]>