Certified Woman & Minority Owned

Business Analyst - Privacy Program


Reference Number: 156301

Business Analyst - Privacy Program
experience  Not Disclosed
location  Madison, WI
duration  2.5 Months
salary  Not Disclosed
jobtype  Not Disclosed
Industry  Government - State
duration  $56.57/hour - $61.57/hour
Job Description

Primarily remote with 1 day PER MONTH onsite at office.

Description:

The client is looking for Business Analyst/Consultant IV

Privacy Program Contractor/IT Business Analyst IV

Overview:

Seeking an experienced contractor to design, develop, and help stand up a comprehensive privacy program at the client. The contractor will be responsible for developing, documenting, and, as feasible, implementing or operationalizing, privacy program policies and plans to enhance privacy governance, compliance, and risk management practices for the client, that can later inform enterprise recommendations for all executive branch agencies.

Scope of Work: Along with legal counsel and others, the contractor will perform the following tasks:
1. Policy & Governance Framework Development:
o Establish privacy procedures tailored to the client's operations.
o Establish a privacy governance structure, including roles and responsibilities.
o Define key performance indicators (KPIs) for privacy program success.

2. Regulatory Compliance & Risk Management:
o Create processes to ensure compliance with federal, state, and local privacy laws and regulations.
o Create processes for Privacy Threshold Assessments (PTAs) and Privacy Impact Assessments (PIAs).
o Identify systems that process personally identifiable information (PII) and other regulated data, and identify key stakeholders associated with those systems per NIST Risk Management Frameworks (e.g., system owner, authorizing official, etc.).

3. Training & Awareness:
o Create privacy communication materials, best practice guidelines, and training.
o Develop/recommend best practices to foster a culture of privacy compliance within the client.

4. Incident Response & Data Breach Management:
o Along with Chief Information Security Officer (CISO) and legal counsel, develop privacy mandates within existing incident response plans.
o Along with CISO and legal counsel, establish procedures for reporting and remediating privacy incidents.

5. Vendor & Third-Party Risk Management:
o Along with legal counsel, conduct privacy assessments of key vendors and partners.
o Along with legal counsel, recommend strategies to standardize contracting and data sharing agreements (DSAs) and/or templatize appropriate data protection and privacy clauses within contracts.

6. Privacy Technology & Automation:
o Assess and recommend privacy-enhancing technologies (PETs) and automation tools.
o Support integration of data/privacy tools and controls into the client IT systems, including the governance, risk, and compliance (GRC) platform.
o Collaborate with IT and security teams to embed privacy by design principles into all aspects of the system development lifecycle (SDLC).

Required Qualifications & Competencies (8-10 Years of Relevant Experience Required):
Excellent communication skills and the ability to engage with stakeholders at all levels, translating complex technical and legal ideas to business stakeholders and decision-makers.
Demonstrated experience in privacy program process development and implementation.
Strong knowledge of NIST Risk Management Frameworks (e.g., NIST RMF, NIST PF, NIST CSF).

Well Qualified Applicant Qualifications & Competencies:
Knowledge of privacy laws and regulations (e.g., GDPR, CCPA, HIPAA).
Strong project management skills.
Ability to execute strategic privacy initiatives independently, with general/minimal oversight.
Professional certifications such as Certified Information Privacy Professional (CIPP), Certified Information Privacy Manager (CIPM), Certified Information Privacy Technologist (CIPT) or similar preferred.


Required Skills

Excellent communication skills and the ability to engage with stakeholders at all levels, translating complex technical and legal ideas to business stakeholders and decision-makers. (8-10+ years)
Ability to engage with stakeholders at all levels, translating complex technical and legal ideas to business stakeholders and decision-makers. (8-10+ years)
Demonstrated experience in privacy program process development and implementation. (8-10+ years)
Strong knowledge of privacy laws and regulations (e.g., GDPR, CCPA, HIPAA) and NIST Risk Management Frameworks (e.g., NIST RMF, NIST PF, NIST CSF). (8-10+ years)

Preferred Skills
Expertise in risk management, data governance, and compliance frameworks.
Experience conducting privacy impact assessments and developing privacy processes.
Strong project management skills with the ability to execute strategic privacy initiatives.



Notes:
Primarily remote with 1 day PER MONTH onsite at office.


VIVA is an equal opportunity employer. All qualified applicants have an equal opportunity for placement, and all employees have an equal opportunity to develop on the job. This means that VIVA will not discriminate against any employee or qualified applicant on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status

Apply for this Job





(Please ensure email matches your resume email)



(document types allowed: doc/docx/rtf/pdf/txt) (max 2MB)

By submitting this form, you are consenting to the VIVA team contacting you via Phone/Email

Related Jobs

Join VIVA and grow

VIVA is faster, easier and you still have complete control