Posted 1w ago

Privacy Policy Analyst

@ TechOp Solutions International
Arlington, Virginia, United States
RemoteFull Time
Responsibilities:align privacy, conduct assessments, update policies
Requirements Summary:Bachelor’s Degree; 2+ years in privacy policy/oversight/compliance for a government agency; knowledge of GDPR, CCPA, HIPAA; strong communication; research/analytic skills; privacy certifications a plus; US Citizenship or Green Card; security eligibility.
Technical Tools Mentioned:NIST, FedRAMP, PIA, SORN, Privacy Framework
Save
Mark Applied
Hide Job
Report & Hide
Job Description

TechOp Solutions International is looking for a skilled and motivated Privacy Policy Analyst to join our team and support of our client. In this role, the Privacy Policy Analyst is responsible for ensuring the Commission’s compliance with the Privacy Act of 1974, the E-Government Act of 2002, and OMB/NIST mandates. This role requires a blend of policy drafting, IT risk assessment, and incident management.

This is a remote position; however, you must reside in the DMV area (DC, Maryland, or Virginia).

 

Key Responsibilities:

Align the NIST Privacy Framework with existing NIST 800-53 controls to support the Commission’s Enterprise Risk Management (ERM) program.

Conduct privacy control assessments and review FedRAMP authorization packages for cloud-based investments.

Assist in suspected breach investigation, assessments, and annual breach response tabletop exercises.

Participate in IT capital investment plans to integrate "Privacy by Design."

Assist in the development, implementation, and maintenance of privacy policies and procedures to ensure compliance with applicable laws and regulations.

Collaborate with various departments components and programs to educate and train staff on matters pertaining to privacy compliance.

Stay up to date with changes in privacy laws, regulations, and best practices affecting the organization's operations.

Maintain the enterprise-wide PII holding inventory and assist efforts to reduce or eliminate the collection of Social Security Numbers.

Conduct and update Privacy Impact Assessments (PIA) and prepare new or update System of Records Notices (SORN)

Performs additional duties as assigned