Privacy Program Specialist
Listed on 2026-09-21
-
Security
Information Security & Data Protection
Duties
The Privacy Program Specialist assists the Smithsonian Privacy Officer (SPO) with the day-to-day administration of the information privacy program and all privacy-related activities for the Smithsonian Institution.
In This Position, You Will- Serve as a privacy subject matter specialist, responsible for the coordination, implementation, and management of the daily operations of the program.
- Develop policy and procedural guidance for use by Smithsonian employees and affiliated persons.
- Independently conduct reviews and assessments of information technology and paper records systems to ensure compliance with applicable privacy laws and SI policy.
- Develop and facilitate training workshops on privacy programs and initiatives for managers and employees.
- Provide breach/incident response planning and response support to incidents involving the suspected or confirmed breaches of personally identifiable information.
- Pass Pre-employment Background Investigation
- May need to complete a Probationary Period
- Maintain a Bank Account for Direct Deposit/Electronic Transfer
- Males born after 12/31/59 must be registered with Selective Service.
Qualification requirements, including one year time-in-grade at the next lower grade level for promotion candidates, must be met within 30 days of the job announcement closing date. See the 'Required Documents' section for additional information.
For information on qualification requirements, see Qualification Standards Handbook for General Schedule Positions viewable on
QualificationsExperience: You qualify for this position if you have one year of specialized experience equivalent to at least the GS-12 level in the Federal Service.
For this position, specialized experience is defined as experience performing at least five of the following: (1) conducting reviews and analysis of contracts with privacy and information security implications; (2) conducting research on U.S. state and foreign privacy laws to ensure proper implementation of privacy requirements; (3) coordinating incident response activities; (4) developing and delivering briefings on the privacy or security implications of existing or emerging technology (e.g., Artificial Intelligence);
(5) conducting privacy risk assessments within a governance risk and compliance tool; and (6) coordinating responses to annual information security audits.
Your resume must be no more than two (2) pages and should clearly demonstrate how your experience aligns with the responsibilities and specialized experience required for this position. Do not copy language directly from the vacancy announcement, as you will be deemed ineligible for consideration. Instead, provide detailed, descriptive information about your actual experience.
Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, Ameri Corps) and other organizations (e.g., professional; philanthropic; religious; spiritual; community, student, social). Volunteer work helps build critical competencies, knowledge, and skills and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.
Part-time and/or unpaid experience related to this position will be considered to determine the total number of years and months of experience. Be sure to note the number of paid or unpaid hours worked each week.
EducationThis job does not have an education qualification requirement.
Additional information- This position is not included in the bargaining unit.
Recruitment Incentive: Recruitment incentive(s) may be authorized for this position.…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).