Privacy Analyst
On-siteWashington, District of Columbia, United States or Washington, United States
Job Summary
Prepare, review, and maintain Privacy Threshold Analyses, Privacy Impact Assessments, System of Records Notices, and related federal privacy compliance artifacts. Identify and document the collection, use, maintenance, sharing, retention, and disposal of personally identifiable information. Translate technical and operational details into accurate privacy documentation while reviewing materials for completeness, consistency, and adherence to applicable federal and departmental requirements. Identify potential privacy risks and assist stakeholders in documenting appropriate mitigation measures. Maintain accurate assessment records, status reports, and trackers while handling sensitive information with discretion and confidentiality. Requires U.S. citizenship and ability to satisfy federal background investigation requirements.
Required Qualifications
- Bachelor's degree in cybersecurity, information systems, information technology, public policy, legal studies, business, or a related field
- Relevant experience in place of a degree
- At least two years of experience supporting one or more of the following areas: Privacy compliance, Information governance, Cybersecurity governance, risk, and compliance, Risk Management Framework or authorization activities, Information-system security
- Experience gathering, analyzing, and documenting technical or operational requirements
- Understanding of personally identifiable information (PII), data flows, access controls, information sharing, retention, and privacy risk
- Strong analytical, research, writing, editing, and organizational skills
- Ability to manage multiple assessments and documentation requirements simultaneously
- U.S. citizenship and ability to satisfy applicable federal background investigation, suitability, or security requirements
Desired Qualifications
- Direct experience preparing or reviewing PTAs, PIAs, SORNs, or similar federal privacy compliance artifacts
- Experience supporting the Department of Homeland Security
- Experience with the NIST Risk Management Framework and NIST SP 800-53 security and privacy controls
- Previous experience as a privacy analyst, system analyst, ISSO, security control assessor, RMF analyst, or federal GRC analyst
- Knowledge of the Privacy Act of 1974, E-Government Act privacy requirements, Fair Information Practice Principles, and federal privacy policy
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.