Role Description
ENDICTUS is seeking an experienced Federal Privacy Assessor to lead an independent assessment of a federal agency privacy program. The selected professional will evaluate the effectiveness and maturity of privacy policies, procedures, controls, documentation, and operational practices, with particular emphasis on NIST SP 800-53 Revision 5 privacy controls.
The Privacy Assessor will:
-
Review Privacy Impact Assessments (PIAs), Systems of Records Notices (SORNs), Privacy Act Statements, data inventories, policies, procedures, and supporting control evidence.
-
Assess implementation and effectiveness of applicable privacy controls.
-
Identify privacy risks and control deficiencies.
-
Develop actionable remediation recommendations.
-
Prepare assessment documentation and executive-level findings.
This position requires substantive hands-on federal privacy assessment experience. General cybersecurity, RMF, or security-control experience alone is not sufficient unless it includes direct privacy-control assessment responsibilities.
This is a fully remote position. Candidates can work from anywhere in the United States. However, preference will be given to applicants residing in the Washington, D.C. metropolitan area.
Qualifications
-
Active Certified Information Privacy Professional/United States (CIPP/US) certification maintained through the International Association of Privacy Professionals (IAPP).
-
Minimum five years of experience conducting privacy assessments for federal agencies.
-
Demonstrated experience evaluating federal privacy programs, privacy controls, and associated documentation.
-
In-depth understanding of compliance issues associated with federal privacy legislation, directives, regulations, policies, and federal guidance.
-
Demonstrated experience planning and executing privacy assessments from initial scoping through final findings and executive reporting.
-
Minimum five years of experience utilizing NIST SP 800-53 Rev. 5 privacy-assessor knowledge and application.
-
Experience assessing privacy controls within a mid-sized federal agency or comparable environment with a Moderate security categorization.
-
Experience developing and delivering executive-level briefings summarizing privacy risks, findings, and remediation priorities.
Requirements
-
Plan and execute an independent assessment of a federal agency privacy program.
-
Develop and maintain an assessment plan defining scope, methodology, schedule, assessment activities, evidence requirements, and stakeholder engagement.
-
Evaluate the design, implementation, and effectiveness of applicable privacy controls.
-
Review the agency's privacy governance structure, policies, procedures, standards, and supporting artifacts.
-
Identify gaps, weaknesses, inconsistencies, and areas of privacy risk.
-
Maintain objective, evidence-based traceability between assessment criteria, supporting evidence, findings, risk ratings, and recommendations.
-
Assess applicable NIST SP 800-53 Rev. 5 privacy controls.
-
Review evidence demonstrating control implementation and effectiveness.
-
Document control-level findings and supporting evidence.
-
Identify and evaluate privacy-related risks and control deficiencies.
-
Develop prioritized, practical, and actionable remediation recommendations.
-
Conduct interviews and working sessions with agency Privacy Office personnel, system owners, information system security personnel, program stakeholders, and other relevant subject matter experts.
-
Prepare draft and final privacy assessment documentation that clearly describes assessment scope and methodology, control assessment results, findings and supporting evidence, risk ratings, control deficiencies, and recommended corrective actions.
Benefits
-
Fully remote position.
-
Opportunity to work with federal agencies.
-
Engagement with senior leadership and stakeholders.