Privacy Lead
Job in
Bethesda, Montgomery County, Maryland, 20811, USA
Listed on 2026-08-23
Listing for:
Gunnison Consulting Group
Part Time
position Listed on 2026-08-23
Job specializations:
-
IT/Tech
Information Security & Data Protection, Cybersecurity
Job Description & How to Apply Below
Description
* This position is contingent upon a future opening with Gunnison.
Salary: $130,000 - $145,000/year
Work location
:
Hybrid, 2-3 days per week on-site in Bethesda, MD.
- Serve as the Privacy Lead supporting NIH CIT systems and services, ensuring privacy compliance across enterprise, cloud, network, hosting, collaboration, identity, endpoint, and other FISMA-reportable environments.
- Lead development, review, update, and maintenance of privacy compliance artifacts, including Privacy Threshold Analyses (PTAs), Privacy Impact Assessments (PIAs), System of Records Notices (SORNs), data inventories, privacy requirements documentation, and supporting approval packages.
- Evaluate NIH systems, data flows, system interfaces, business processes, and proposed changes to identify privacy risks involving Personally Identifiable Information (PII), Protected Health Information (PHI), sensitive data, and other information requiring protection.
- Interpret and apply applicable privacy laws, regulations, policies, standards, and guidance, including the Privacy Act, E-Government Act, FISMA-related privacy requirements, HHS privacy policies, NIH privacy procedures, and relevant federal records and data‑protection requirements.
- Partner closely with System Owners, ISSOs, security engineers, program managers, legal/privacy offices, and other stakeholders to collect system information and ensure privacy requirements are incorporated throughout the system lifecycle.
- Lead the collection, analysis, validation, and documentation of information from FISMA systems to support privacy reviews, system authorizations, data inventories, compliance reporting, and management decision‑making.
- Review proposed systems, enhancements, integrations, cloud migrations, data‑sharing arrangements, and new uses of data to identify privacy implications and recommend appropriate safeguards, mitigations, and compliance actions.
- Provide practical privacy-law and policy guidance to Government stakeholders on system design, data collection, data minimization, notice, consent where applicable, data retention, access, sharing, disclosure, and incident/breach considerations.
- Track privacy risks, findings, action items, and remediation activities; maintain status reporting and elevate high-risk privacy issues, overdue actions, and material compliance gaps to program leadership.
- Prepare clear privacy assessments, risk memoranda, compliance reports, executive briefings, status dashboards, and recommendations for technical and nontechnical audiences.
- Develop and deliver privacy‑awareness training, targeted guidance, job aids, and briefings for system owners, technical personnel, program staff, and other stakeholders.
- Monitor changes in federal privacy legislation, HHS and NIH policy, agency guidance, and leading practices; assess program impact and recommend updates to processes, artifacts, controls, and training.
- Lead and mentor privacy analysts or supporting personnel; establish work priorities, conduct quality reviews, and ensure privacy deliverables are complete, accurate, timely, and consistent.
Minimum of three (3) to five (5) years of progressively responsible experience in federal privacy, privacy compliance, privacy program management, cybersecurity/privacy governance, information assurance, or a related discipline.
Candidates should demonstrate experience in:
- Developing and maintaining PTAs, PIAs, SORNs, privacy compliance documentation, data inventories, and related artifacts.
- Reviewing enterprise, cloud, hybrid, or FISMA-reportable systems for privacy risks and compliance obligations.
- Assessing the collection, use, retention, sharing, protection, and disposal of PII, PHI, sensitive data, or other regulated information.
- Applying federal privacy requirements, including the Privacy Act, E‑Government Act privacy provisions, FISMA‑related privacy requirements, HHS policies, and NIH procedures.
- Working directly with System Owners, technical teams, security personnel, program managers, legal/privacy stakeholders, and leadership.
- Collecting and validating system, data‑flow, and business‑process information needed for privacy reviews and reporting.
- Provid…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×