Support the development, review, and maintenance of Privacy Impact Assessments (PIAs), System of Records Notices (SORNs), and other compliance documentation
Assist in privacy compliance activities under the Privacy Act of 1974, E-Government Act of 2002, and OMB privacy directives
Map and assess organizational policies and procedures against NIST 800-37, 800-53, 800-122, 800-171, and 800-53 Rev. 4/Rev. 5 controls
Conduct initial privacy risk assessments and track remediation actions
Support integration of privacy requirements into the Risk Management Framework (RMF) and Authorization to Operate (ATO) process
Contribute to training, awareness, and reporting activities related to privacy risks and compliance obligations
Assist with preparing responses to audits, data calls, and inquiries from CFTC leadership or oversight bodies
Work with senior privacy, cybersecurity, and compliance staff to identify and mitigate privacy risks
Requirements
Bachelor’s degree in Cybersecurity, Information Assurance, Information Systems, Law/Policy, or related field (or equivalent experience)
2+ years of relevant privacy, compliance, or information security experience
Knowledge of federal privacy requirements and NIST 800 series standards (including Rev. 4 & Rev. 5)
Familiarity with RMF, ATO processes, and control families related to privacy
Strong written and verbal communication skills
U.S. citizenship required
Preferred: Experience supporting federal agencies such as CFTC, SEC, Treasury, DHS, or DoD
Preferred: Familiarity with FISMA, CMMC, or other compliance frameworks
Preferred: Privacy certifications (CIPP/G, CIPM, or CAP) or security certifications (Security+, CAP, CISSP-Associate)
Understanding of data governance, privacy engineering, or Zero Trust frameworks
Benefits
Fully Remote
📊 Resume Score
Upload your resume to see if it passes auto-rejection tools used by recruiters
Check Resume Score
ATS Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
Privacy Impact AssessmentsSystem of Records NoticesNIST 800-37NIST 800-53NIST 800-122NIST 800-171Risk Management FrameworkAuthorization to Operateprivacy risk assessmentsdata governance
Soft skills
strong written communicationstrong verbal communication