Skip to main content
U.S. flag
Back to results

Chief Information Security Officer

Federal Deposit Insurance Corporation
This job announcement has closed

Summary

The Chief Information Security Officer (CISO) is a principal member of the Chief Information Officer’s (CIO) management team. The incumbent, in conjunction with the CIO and Director of the Division of Information Technology (DIT), manages, controls, and operates the Office of the CISO (OCISO) and coordinates with the other principals to manage, control, and operate the CIO organization. The mission of the CIO organization is to provide information security and privacy leadership and services including: policy and program direction; information systems development, implementation and maintenance; telecommunications network management; hardware and software management; IT resource and data protection; and other critical information technology functions.

Salary reflects a pay cap for this position of $269,600.

Applicants must be able to successfully undergo a Single Scope Background Investigation (SSBI) and maintain a TS/SCI national security clearance.
FDIC Executive Managers (EM) are in the Federal competitive service and not the Senior Executive Service (SES). As an EM at the FDIC, you will provide executive leadership and managerial direction over substantive activities related to planning, developing, executing, and coordinating the Corporation's programs and policies.

Announcement amended on 10/27/2017 to remove a major duty statement erroneously included in original posting.

Overview

Help
Reviewing applications
Open & closing dates
10/26/2017 to 11/13/2017
Salary
$205,312 to - $269,600 per year
Pay scale & grade
EM 00
Location
1 vacancy in the following location:
Washington DC, DC
1 vacancy
Relocation expenses reimbursed
Yes—Relocation provided.
Appointment type
Permanent - Permanent, Full-Time.
Work schedule
Full-time - Competitive Service.
Service
Promotion potential
00
Supervisory status
Yes
Security clearance
Sensitive Compartmented Information
Announcement number
2017-EM-0055
Control number
482878600

This job is open to

Help

Duties

Help

The need for information security within the government and in private industry continues to increase to a point that it has taken center stage within both business units and IT reflecting a priority on protecting data from predators both within and outside of FDIC.

The position of CISO involves a wide range of management activities that typically extend and apply across FDIC. The incumbent is responsible for overseeing and directing security programs and security efforts across the agency, including information technology, protection of agency data and personnel data, and FDIC's IT infrastructure and communications. This includes ensuring protection of FDIC systems, data, and employees from outside intrusion or harm.

As CISO, the incumbent is also responsible for strategic planning and budget control, workforce planning, policy and standards development, resource management, knowledge management, architecture and infrastructure planning, auditing, and information security management. The incumbent establishes the numerous functions of security, privacy, risk management, security technology assessment, Public Key Infrastructure, independent security reviews, access administration, virus protection, disaster recovery, security monitoring and reporting, and security awareness and training.

Due to the ever increasing importance of IT Security and Privacy, this position has direct access to agency executives and business unit managing directors supporting them with strategic planning, standards and process development, regulatory and internal compliance monitoring, investigations, and incident response. Further, this position supports the business development process through discussions and negotiations with clients. The incumbent conducts strategic planning to support the business objectives, develops, implements, and directs FDIC security, privacy, and risk management programs to safeguard operations, global systems, personnel, facilities, and physical assets. The incumbent represents the FDIC at executive level meetings with other federal organizations such as OMB and the Government Accountability Office (GAO), as well as, private sector companies and organizations.

Requirements

Help

Conditions of employment

Employment Conditions.

High Risk Position - Background Investigation (BI) required.

Occasional travel may be required.

Registration with the Selective Service.

Completion of Confidential Financial Disclosure may be required.

Qualifications

In order to qualify, applicants must possess one year of specialized experience at the GS/CG-15 level or above. Specialized experience is experience directing nationwide enterprise operations for information technology security and privacy programs. In addition, the incumbent must have experience in the following:

A. Building an agency-wide security strategy and vision to include the creation and maintenance of information security policies, security risk assessment efforts, information technology risk assessments; disaster recovery; security monitoring; security awareness and training program, security protection architecture, and cyber-security solutions, including security measures for all computers, electronic storage devices and communications systems; and,

B. Identifying, evaluating, and reporting information security risks in a manner that meets compliance and regulatory requirements, and aligns with and supports the risk posture of the enterprise.

Qualifying experience may be obtained in the private or public sector. Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g. Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic, religious/spiritual; community; student, social). Volunteer work helps build critical competencies, knowledge, and skills and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience. Additional qualifications information can be found here click here.

Education

There is no substitution of education for the experience for this position.

Additional information

To read about your rights and responsibilities as an applicant for Federal employment, click here.

If selected, you may be required to serve a supervisory/managerial probationary period.

If selected, you may be required to serve a probationary period.

How you will be evaluated

You will be evaluated for this job based on how well you meet the qualifications above.

Your resume will be reviewed, including the online assessment questionnaire, to determine whether you meet the qualification requirements outlined in this announcement. Therefore, it is imperative that your resume contain sufficiently detailed information upon which to make the qualification determination.
Please ensure that your resume contains specific information such as position titles, beginning and ending dates of employment for each position, average number of hours worked per week, and if the position is/was in the Federal government, you should provide the position series and grade level.

Your resume will also be evaluated to measure your responses to the assessment questions. If you rated yourself higher on the questionnaire than what is supported by your resume, your overall qualifications assessment may be adversely affected.

The competencies/knowledge, skills, and abilities (KSAs) you will be assessed on are listed below. Top ranked candidates will be referred to the selecting official for further review and consideration.

1. Knowledge of information security management principles, methods, and techniques.

2. Ability to plan, design, develop, and manage integrated security system solutions.

3. Ability to manage a portfolio of multiple, concurrent information security systems development activities and projects of high complexity.

4. Knowledge of federal statutes and regulations affecting information security and privacy.

5. Knowledge of information security regulations and standards including the Federal Information Security Management Act (FISMA), Federal Risk and Authorization Management Program (FedRAMP), Federal Information Processing Standard (FIPS), National Institute of Standards and Technology (NIST), Health Insurance Portability and Accountability Act (HIPPA), Personally Identifiable Information (PII) definitions, and various other laws and regulations including Executive Orders.

6. Knowledge of and ability to work with state-of-the-art information security technologies and tools including commercially available, Government supplied, and custom developed (e.g., maintaining security assessing and evaluating security; security incident forensic work).

7. Comprehensive knowledge and mastery of cyber security, intelligence and application including applicable federal law, policy, and guidelines.

8. Knowledge of the intelligence community and a clear understanding of the role of intelligence sharing with and among intelligence agencies.

You do not need to respond separately to these KSAs. Your resume will serve as supporting documentation that you do or do not possess these competencies.


To preview questions please click here.

Your session is about to expire!

Your USAJOBS session will expire due to inactivity in 8 minutes. Any unsaved data will be lost if you allow the session to expire. Click the button below to continue your session.