Privacy & Disclosure-Risk Analyst
Steampunk • McLean, Virginia • Full Time
Posted on Sat, Sep 5, 2026
Overview
We are seeking a Privacy & Disclosure-Risk Analyst responsible for evaluating privacy and data disclosure risks associated with AI/ML models and federated learning environments. This role will perform technical privacy testing to identify potential exposure of sensitive or training data through model leakage, membership inference, federated-update reconstruction, and related disclosure-risk techniques.
The Privacy & Disclosure-Risk Analyst will analyze testing results, assess the potential impact of identified privacy vulnerabilities and information exposure, and collaborate with technical teams to identify and validate appropriate risk mitigation measures. This role requires a strong understanding of machine learning concepts, data privacy risks, applicable privacy requirements, and technical approaches for evaluating potential information disclosure from AI/ML systems.
Responsibilities
- Assess privacy and disclosure risks associated with AI/ML models, training data, and federated learning environments
- Conduct model-leakage testing to identify potential exposure of sensitive, protected, or training data
- Perform membership-inference testing to evaluate whether information about training data can be inferred from model behavior or outputs
- Conduct federated-update reconstruction testing to evaluate potential disclosure of sensitive information from federated learning workflows
- Evaluate AI/ML systems for privacy vulnerabilities, unintended information exposure, and potential disclosure risks
- Develop and execute technical test scenarios and methodologies for evaluating model and data privacy risks
- Analyze testing results to determine the likelihood, severity, and potential impact of identified disclosure risks, including potential impacts to individuals whose information may be exposed
- Evaluate the effectiveness of privacy-preserving controls and recommend appropriate risk mitigation measures
- Collaborate with machine learning engineers, data scientists, cybersecurity teams, and other technical stakeholders to identify and address privacy risks
- Conduct follow-up testing to validate remediation and privacy risk mitigation measures
- Document testing methodologies, technical findings, supporting evidence, risk assessments, and recommended mitigation actions
- Communicate technical privacy and disclosure risks to technical and non-technical stakeholders
- Maintain awareness of emerging AI/ML privacy attacks, disclosure-risk techniques, privacy-preserving machine learning approaches, and evolving AI privacy and risk management guidance
Qualifications
- Ability to obtain and maintain a government security clearance
- Bachelor’s degree in Computer Science, Data Science, Artificial Intelligence, Machine Learning, Cybersecurity, Information Technology, or a related technical discipline, or equivalent relevant experience
- 5+ years of experience in cybersecurity, data privacy, machine learning, AI/ML security, or related technical disciplines
- Experience assessing privacy, data exposure, or disclosure risks within technical systems or data environments
- Strong understanding of machine learning concepts, model training, model outputs, and associated data privacy risks
- Knowledge of AI/ML privacy attack techniques, including model leakage, membership inference, reconstruction, or related disclosure-risk methods
- Experience conducting technical security, privacy, data risk, or adversarial assessments
- Understanding of federated learning or distributed machine learning concepts and associated privacy risks
- Knowledge of privacy-preserving techniques and controls used to reduce unintended information disclosure
- Knowledge of AI risk management principles and frameworks, including the NIST AI Risk Management Framework (AI RMF) or similar guidance
- Ability to analyze technical testing results and assess the potential impact and severity of identified privacy risks
- Experience documenting technical testing methodologies, findings, risks, and recommended mitigation actions
- Strong analytical, problem-solving, communication, and collaboration skills
Preferred:
- Hands-on experience conducting model-leakage, membership-inference, model inversion, reconstruction, or similar AI/ML privacy testing
- Hands-on experience assessing privacy and disclosure risks within federated learning environments
- Experience with differential privacy or other privacy-preserving machine learning techniques
- Experience with privacy-enhancing technologies, data minimization, de-identification, anonymization, or related data protection techniques
- Experience using Python or other programming languages for technical privacy, security, or machine learning analysis
- Knowledge of applicable federal privacy laws, regulations, policies, and standards related to sensitive data and information disclosure
- Familiarity with privacy requirements applicable to health, biomedical, research, or other sensitive data
- Experience working with sensitive, health, biomedical, research, or other protected data
- Experience working within federal government or other highly regulated environments
- Relevant privacy, cybersecurity, data science, or AI/ML certification
AuditFriendly salary estimate
The employer did not post a salary for this role. Based on AuditFriendly's salary intelligence model (comparable live postings, role, seniority, and location), we estimate base pay of $90,000–$113,000 per year (median ~$102,000). This is an AuditFriendly estimate, not an employer-provided figure.
More live risk_analyst roles
- Senior Financial Crime Risk Analyst, Regulatory Matters at TD Bank — Toronto, Ontario, Canada
- Program Evaluation and Risk Analyst at Internal Revenue Service (Remote)
- Risk Analyst - AML & Financial Crimes — Charlotte, North Carolina, US
- Risk Analyst at Federal Emergency Management Agency — Washington, District of Columbia, United States
- Emergency Management Specialist (Risk Analyst) at Federal Emergency Management Agency — Washington, District of Columbia, US
- Risk Analyst at CGI — Montréal, Quebec, Canada
- Capital Markets & Risk Analyst Finance Risk Management at Capital One — Richmond, Virginia, United States
- Senior Program Risk Analyst at CGI Group, Inc. — Huntsville, Alabama, United States
- Enterprise Risk Analyst Sr. at Flagstar Bank — New York, United States
- 2027 Risk Analyst Summer Internship Program at Barclays — Wilmington, North Carolina, United States
- Credit Risk Analyst Manager at KCU — Bremerton, Washington, United States
- Operational Risk Analyst at Family Health Centers of Southwest Florida — Fort Myers, FL, US
- Risk Analyst-Multisite FT (Days) at Adena Health — Chillicothe, Ohio, US
- Senior Risk Analyst at Zip (Remote)
- Risk Analyst Graduate Program at Barclays — Wilmington, North Carolina, United States
- Middle Office Market Risk Analyst at Aramco Americas — Houston, Texas, United States
- Collateral Risk Analyst II at Columbia Bank — Roselle, New Jersey, United States
- Insurance Risk Analyst at Marsh McLennan — Southfield, Michigan, United States
- Senior Trading Credit Risk Analyst (Margin & Options) at Altruist — Dallas, Texas, United States
- Risk Analyst at CCBill (Remote)
- Risk Analyst at Western AgCredit — South Jordan, Utah, US
- Risk Analyst at Invesco — Atlanta, Georgia, United States
- Model Risk Analyst at Live Oak Banking — Wilmington, NC, US
- Credit Risk Analyst at Citizens Business Bank — Ontario, California, US
- Risk Analyst - 2027 Summer Internship Program at Verisk Analytics — Boston, MA, US
- Junior Risk Analyst at Stellar — Jacksonville, Florida, United States
- Sr. Risk Analyst at RogueSearch — Atlanta, Georgia, United States
- Associate Weather Risk Analyst at DTN — Bloomington, Minnesota, United States
- Risk Analyst I at Wilson — United States
- Senior Market Risk Analyst at TD Bank — Toronto, ON, Canada