Data Privacy and Compliance Analyst (Mid-Level) - ICD - Open Rank (Hybrid)
Georgia Tech Research InstituteAbout the role
Overview:
The Georgia Tech Research Institute (GTRI) is the nonprofit, applied research division of the Georgia Institute of Technology (Georgia Tech). Founded in 1934 as the Engineering Experiment Station, GTRI has grown to more than 2,900 employees, supporting eight laboratories in over 20 locations around the country and performing more than $940 million of problem-solving research annually for government and industry. GTRI's renowned researchers combine science, engineering, economics, policy, and technical expertise to solve complex problems for the U.S. federal government, state, and industry.
Georgia Tech's Mission and Values
Georgia Tech's mission is to develop leaders who advance technology and improve the human condition. The Institute has nine key values that are foundational to everything we do:
1. Students are our top priority.
2. We strive for excellence.
3. We thrive on diversity.
4. We celebrate collaboration.
5. We champion innovation.
6. We safeguard freedom of inquiry and expression.
7. We nurture the wellbeing of our community.
8. We act ethically.
9. We are responsible stewards.
Over the next decade, Georgia Tech will become an example of inclusive innovation, a leading technological research university of unmatched scale, relentlessly committed to serving the public good; breaking new ground in addressing the biggest local, national, and global challenges and opportunities of our time; making technology broadly accessible; and developing exceptional, principled leaders from all backgrounds ready to produce novel ideas and create solutions with real human impact.
Location
Atlanta, GA (Hybrid)
Project/Unit Description
The Information and Cybersecurity Department (ICD) provides enterprise cybersecurity services in protection of GTRI's unclassified information assets. ICD consists of two components: The Governance, Risk, and Compliance (GRC) Team and the Information Security Operations Center (ISOC). The GRC Team provides services in cybersecurity policy, risk management, data governance, privacy, awareness and training, and ensuring compliance with Federal, state, and local cybersecurity requirements. The ISOC provides technical cybersecurity expertise via services in continuous monitoring, incident response, and vulnerability management.
Job Purpose
The Data Privacy and Compliance Analyst is responsible for assessing business policies, procedures, and operations to ensure the organization meets privacy requirements and government regulations for the protection of sensitive information. Privacy and Compliance Analysts manage the legal and operational risks related to sensitive and critical information assets, continuously assess business unit operations, and develop policies, procedures and user training necessary to meet or exceed privacy requirements.
Key Responsibilities
- Assists with difficult cybersecurity questions and requests from GTRI customers.
- Direct sponsor engagement as required to review current and planned requirements for secure infrastructures that require compliance.
- Guide requirements gathering and analysis.
- Leads validation of security control configuration on systems, ensure all systems are configured to to necessary controls, such as NIST, DFARS 252.204-7012, CMMC, and other similar requirements.
- Articulates privacy requirements into product life-cycle including definition, requirements analysis, synthesis, cyber engineering analysis and implementation.
- Conducts privacy impact analyses and identify areas needing improvement and recommend necessary enhancements to achieve privacy goals.
- Reviews modifications to critical information systems and directs implementation of configuration changes.
- Mentors lower-level cybersecurity and IT professionals across the enterprise.
Additional Responsibilities
- Develop and implement incident response plans and procedures, ensuring a swift and effective response to security incidents or breaches.
- Coordinate incident investigations, containment, and recovery efforts as needed.
- In-depth knowledge of incident response protocols and remediation techniques.
- Plan and conduct incident response exercises to include table tops, simulations, and actual disruptions.
- Incident investigation and response experience, including the ability to work with IR stakeholders to gather required information for reporting.
- Submit all required IR reports to governing bodies within parameters set by law, regulation, contract, or policy.
- Consult with various partners, publications, websites, news sources, and cyber forums to provide daily updates on threats relativ
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s