Senior Enterprise Data Privacy Analyst
System One · Merrifield, VA · 2 wk ago
Information TechnologyContract
About the role
We are currently seeking a Senior Enterprise Privacy Governance and Risk-Management Analyst. The contractor will focus on privacy governance, risk management, regulatory compliance, PIAs/PRAs, third-party privacy oversight, and AI privacy governance. The role requires someone who can operate strategically while also producing practical governance documents, risk assessments, metrics, reports, and remediation plans. This is a multiyear contract position based in Vienna, VA, with a hybrid work schedule (onsite 3 days a week).
Responsibilities
- Mature and maintain the enterprise privacy governance framework, policies, standards, and procedures
- Oversee Privacy Impact Assessments (PIAs) and Privacy Risk Assessments (PRAs), including intake, review, tracking, escalation, and reporting
- Support privacy risk management, RCSA activities, control assessments, issue remediation, KRIs, and executive reporting
- Conduct third-party privacy reviews and coordinate privacy requirements with Procurement, Legal, Compliance, Security, and business teams
- Evaluate privacy risks associated with AI and advanced analytics and incorporate Privacy-by-Design principles
- Partner with Business Units to improve privacy awareness, training, adoption, and risk visibility
- Align privacy requirements with Data Governance, Data Sharing, Records Management, and AI Governance
- Support regulatory, audit, and risk management responses
- Translate regulatory requirements into practical policies, controls, and governance processes
- Work across Legal, Compliance, Security, Technology, Data Management, and business stakeholders
Requirements
- Minimum of 10 years of professional privacy program experience
- Minimum of 10 years of experience designing, implementing, and maturing enterprise privacy programs, ideally within a highly regulated financial institution
- Experience in a Second Line of Defense (2LOD) environment
- Experience with 2LOD oversight, PIAs/PRAs, governance, risk management, financial-services regulation, third-party privacy, and emerging AI privacy risks
- Experience standing up or enhancing privacy programs in the second line of defense at highly regulated financial environments
Qualifications
- Strong understanding of privacy principles and risk management concepts
- Understanding of Personally Identifiable Information (PII) and sensitive data handling
- Familiarity with Privacy-by-Design concepts
- Understanding of records management and data sharing dependencies
- Second Line of Defense mindset and effective challenge capability
- Governance document development and maintenance skills
- Policy, standard, and procedure interpretation skills
- Risk assessment and issue management experience
- Audit and regulatory response support experience
- Ability to identify trends and emerging risks
- Executive reporting and presentation development skills
- Data analysis and metric development skills
- Process mapping and control evaluation skills
- Ability to coordinate across Legal, Compliance, Security, Technology, Data Management, and Business Units
- Strong facilitation and stakeholder management capabilities
- Ability to translate regulatory requirements into practical governance expectations