×
Register Here to Apply for Jobs or Post Jobs. X

Federal Privacy Assessor (CIPP​/US Certified

Job in Washington, District of Columbia, 20022, USA
Listing for: Endictus
Full Time position
Listed on 2026-08-23
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity
Salary/Wage Range or Industry Benchmark: 140000 - 190000 USD Yearly USD 140000.00 190000.00 YEAR
Job Description & How to Apply Below
Position: Federal Privacy Assessor (CIPP/US Certified)

Description

ENDICTUS is seeking an experienced Federal Privacy Assessor to lead an independent assessment of a federal agency privacy program. The selected professional will evaluate the effectiveness and maturity of privacy policies, procedures, controls, documentation, and operational practices, with particular emphasis on NIST SP 800-53 Revision 5 privacy controls.

The Privacy Assessor will review Privacy Impact Assessments (PIAs), Systems of Records Notices (SORNs), Privacy Act Statements, data inventories, policies, procedures, and supporting control evidence; assess implementation and effectiveness of applicable privacy controls; identify privacy risks and control deficiencies; develop actionable remediation recommendations; and prepare assessment documentation and executive-level findings.

This position requires substantive hands‑on federal privacy assessment experience. General cybersecurity, RMF, or security‑control experience alone is not sufficient unless it includes direct privacy‑control assessment responsibilities.

Requirements

Key Responsibilities Privacy Program Assessment
  • Plan and execute an independent assessment of a federal agency privacy program.
  • Develop and maintain an assessment plan defining scope, methodology, schedule, assessment activities, evidence requirements, and stakeholder engagement.
  • Evaluate the design, implementation, and effectiveness of applicable privacy controls.
  • Review the agency's privacy governance structure, policies, procedures, standards, and supporting artifacts.
  • Assess whether documented privacy practices align with applicable federal requirements and agency procedures.
  • Identify gaps, weaknesses, inconsistencies, and areas of privacy risk.
  • Maintain objective, evidence-based traceability between assessment criteria, supporting evidence, findings, risk ratings, and recommendations.
NIST SP 800-53 Rev. 5 Privacy Control Assessment
  • Assess applicable NIST SP 800-53 Rev. 5 privacy controls.
  • Review evidence demonstrating control implementation and effectiveness.
  • Map agency privacy documentation and practices to applicable NIST SP 800-53 Rev. 5 privacy controls.
  • Evaluate whether controls are adequately documented, implemented, and operating as intended.
  • Identify missing, incomplete, ineffective, or inadequately supported privacy controls.
  • Document control‑level findings and supporting evidence.
  • Develop assessment results that clearly map findings to applicable NIST SP 800-53 Rev. 5 privacy controls.
  • Ensure assessment documentation supports defensible conclusions and Government review.
Privacy Documentation Review

Review and analyze privacy documentation including, as applicable:

  • Privacy Impact Assessments (PIAs)
  • Systems of Records Notices (SORNs)
  • Privacy Act Statements
  • Data inventories
  • Privacy policies and procedures
  • Privacy control documentation
  • Information collection and data‑use documentation
  • Data‑flow documentation
  • Records retention practices
  • Data‑sharing practices
  • Data minimization practices
  • Privacy risk documentation
  • Plans of Action and Milestones (POA&Ms)
Risk Analysis and Remediation
  • Identify and evaluate privacy‑related risks and control deficiencies.
  • Assign risk ratings using Low, Moderate, and High classifications, as applicable.
  • Determine the operational and compliance significance of identified findings.
  • Develop prioritized, practical, and actionable remediation recommendations.
  • Support development or refinement of POA&Ms for missing, incomplete, or inadequate controls and documentation.
  • Recommend resources, processes, documentation, or control improvements needed to address outstanding privacy issues.
  • Ensure recommendations are traceable to assessment evidence and applicable NIST privacy controls.
  • Develop final findings, risk ratings, and recommendations suitable for inclusion in a formal federal privacy assessment report.
Stakeholder Engagement
  • Conduct interviews and working sessions with agency Privacy Office personnel, system owners, information system security personnel, program stakeholders, and other relevant subject matter experts.
  • Request, review, and validate assessment evidence.
  • Resolve evidence gaps and clarify control implementation through structured stakeholder…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary