Privacy Compliance Auditor (SME)

RELI GROUP INCWoodlawn, MD
6d$125,000 - $175,000

About The Position

RELI Group is seeking an experienced Privacy Compliance Auditor Subject Matter Expert (SME) to support privacy-focused audits and assessments under Task 8 of the Information Security and Privacy Services (ISPS), part of the Marketplace System Security and Privacy Support Services (MSSPSS) contract. The Privacy Compliance Auditor SME will provide expert-level evaluation of CMS ACA and NST systems to ensure compliance with the Privacy Act, HIPAA, OMB guidance, and CMS privacy policies. This role includes advising on privacy risk mitigation, assessing compliance documentation, conducting audit readiness reviews, and engaging with stakeholders to enhance privacy governance and transparency.

Requirements

  • Bachelor’s degree in Privacy, Cybersecurity, Law, Public Policy, or a related field.
  • 7+ years of experience in privacy compliance auditing, privacy impact assessments, or data protection in a federal setting.
  • Strong understanding of the Privacy Act, HIPAA, OMB Circular A-130, and FISMA privacy requirements.
  • Experience conducting audits or assessments for CMS, HHS, or similar agencies.
  • Exceptional written and verbal communication skills, with experience developing formal audit deliverables.
  • Ability to translate complex privacy policies into actionable compliance and audit strategies.

Nice To Haves

  • Experience supporting ACA-related programs and systems.
  • Certifications such as CIPP/G, CIPM, CHPC, or CISA.
  • Familiarity with CMS privacy templates, requirements, and privacy governance structures.
  • Understanding of privacy-enhancing technologies, Zero Trust, and secure data-sharing models.
  • Experience advising CMS leadership or supporting responses to federal audits (e.g., OIG, GAO, OCR)

Responsibilities

  • Conduct comprehensive privacy compliance audits of CMS systems, ensuring adherence to federal privacy laws and CMS privacy requirements
  • Evaluate Privacy Impact Assessments (PIAs), System of Records Notices (SORNs), and Data Use Agreements (DUAs) for completeness and accuracy
  • Support CMS in meeting audit requirements from OMB, OIG, OCR, and internal privacy oversight bodies
  • Provide recommendations for privacy control improvements and develop audit remediation plans
  • Monitor and document privacy risks, data handling processes, and potential noncompliance issues
  • Collaborate with Privacy Officers, ISSOs, legal counsel, and system owners to ensure ongoing compliance and audit readiness
  • Develop privacy audit checklists, frameworks, and compliance dashboards
  • Author formal audit reports, briefing documents, and stakeholder communications
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service