Acquisition Security & Privacy Analyst (Job 1456)

DLH

$115K — $125K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years of experience in reviewing IT acquisitions and cloud services for security and privacy compliance.
  • Knowledge of the Privacy Act, E-Government Act, HIPAA, and HHS privacy regulations.
  • Experience creating Privacy Impact Assessments (PIAs) and related documentation.
  • Familiarity with NIST 800-53 and federal compliance frameworks.
  • Experience in vendor risk assessments and privacy incident response.
  • Bachelor's degree in IT, Cybersecurity, or related field.
  • Relevant certifications such as CIPP/US, CompTIA Security+, or similar.

Responsibilities

  • Review and assess IT acquisitions and third-party solutions for security and privacy compliance.
  • Track and document privacy incidents involving PII and sensitive data.
  • Evaluate security and privacy requirements for procurement packages.
  • Identify relevant compliance clauses for acquisitions.
  • Coordinate information gathering and compliance issue resolution among teams.
  • Support process improvements and maintain standard operating procedures.

Benefits

  • Personal Time Off (PTO) policy.
  • Comprehensive medical, dental, and vision coverage.
  • Disability coverage and supplemental life insurance with AD&D.
  • 401(k) Retirement Plan with matching component.
  • Access to extensive training and professional development resources.
Full Job Description
Overview

DLH is seeking an Acquisition Security & Privacy Analyst to join our team. The Acquisition Security & Privacy Analyst is responsible for privacy compliance, acquisition security reviews, governance and risk activities, and security authorization support across enterprise systems, cloud services, and emerging technologies. This resource works with system owners, privacy officials, contract teams, cybersecurity personnel, and federal leadership to ensure technology procurements and operational systems comply with federal security, privacy, and regulatory requirements.

Responsibilities
  • Experience reviewing IT acquisitions, software purchases, cloud services, and third-party technology solutions for security and privacy considerations
  • Assist with tracking, documenting, and supporting remediation of privacy incidents involving PII and sensitive information
  • Assist in evaluating security and privacy requirements for procurement packages
  • Support identification of applicable security, privacy, and compliance clauses for acquisitions
  • Coordinate with acquisition teams, CORs, ISSOs, and system owners to gather required security and privacy information and resolve compliance issues
  • Support process improvement initiatives and maintenance of standard operating procedures

Qualifications
  • Minimum of three (3) years of experience reviewing and assessing IT acquisitions, cloud services, SaaS offerings, AI-enabled technologies, and software procurements for security, privacy, records management, and compliance requirements.
  • Experience supporting compliance with the Privacy Act, E-Government Act, HIPAA, and HHS privacy requirements
  • Prior experience developing and maintaining: Privacy Impact Assessments (PIAs), Privacy Threshold Analyses (PTAs), System of Record Notices (SORNs), Privacy Act Statements, and Privacy Notices and related documentation
  • Familiarity with NIST 800-53, FISMA, Privacy Act requirements, and federal compliance frameworks
  • Experience supporting privacy incident response and/or vendor risk assessments
  • Bachelor's degree in information technology, Cybersecurity, or a related field.
  • Relevant certifications (e.g., CIPP/US, CIPM, CompTIA Security+, OneTrust Privacy Management Professional) required
  • Excellent problem-solving and analytical skills.
  • Strong cross-team collaboration and coordination across diverse audiences and stakeholders
  • Familiarity with FedRAMP and cloud security concepts (preferred)
  • Experience with ServiceNow, Jira, Confluence, Microsoft 365, and compliance tracking tools (preferred)
  • Must be able to obtain a Public Trust clearance

Basic Compensation: $115,000 - $125,000 yearly salary

The salary range listed reflects what we reasonably expect to pay for this role at the time of posting. The final offer may vary based on skills, experience, geographic location, market conditions, and internal equity. Additional compensation may include performance incentives and program-specific awards. We do not use salary history to determine compensation, in line with applicable law.

Benefits

DLH Corp offers our employees an excellent benefits package, including Personal Time Off (PTO), medical, dental, vision, supplemental life with AD&D, disability coverage, flexible spending accounts, and more. We want our employees to save for their future; therefore, we offer a 401(k) Retirement Plan, which includes a matching component. DLH is dedicated to your career development, providing training to help drive success, with access to our best-in-class e-learning suite for formal and informal learning, professional and technical certification preparation, and education assistance at accredited institutions.

Similar Jobs

More Jobs at DLH

More Information Technology Jobs

Find similar Acquisition Security & Privacy Analyst (Job 1456) jobs: