Skip to main content
U.S. flag

Chief Information Security Officer

Department of Commerce
Patent and Trademark Office
This job announcement has closed

Summary

Come work for the Patent and Trademark Office, we have been ranked as one of the best places to work in the federal government! The U.S. Patent and Trademark Office (USPTO) has been serving the economic interests of America for more than 200 years. We are responsible for granting US intellectual property rights for patents and trademarks. The USPTO is headquartered in Alexandria, Virginia, and has over 12,000 employees. For more information about the USPTO, please visit the USPTO Jobs Website.

Overview

Help
Hiring complete
Open date: 02/16/2022
Closed date: 03/18/2022
Location
1 vacancy in the following locations:
Work site options
Telework eligible
Yes—as determined by the agency policy.
Relocation expenses reimbursed
No
Salary
$135,468 - $203,700 per year
Pay scale & grade
ES 00
Promotion potential
00
Pay scale and grade determines the salary of the job.
Work schedule
Full-time - USPTO is open to a flexible duty station for this position.
Travel Required
Occasional travel - You may be expected to travel for this position.
Appointment type
Permanent
Occupations and job series
Supervisory status
Yes
Federal service type
This job is in the Senior Executive Service
Drug test
Yes
Security clearance
Top Secret
Position sensitivity and risk
High Risk (HR)
Jobs require a background check and some require a security clearance. The type depends on the job.
Background check type
Announcement number
EXRD - OCIO-22-11388711
Control number
637657700

Duties

Help

The United States Patent and Trademark Office (USPTO) is open to a flexible duty station for this position. Minimal travel to headquarters, Alexandria, VA, will be required and agreed upon between the agency and the selectee.

The United States Patent and Trademark Office (USPTO) is currently under a maximum telework posture due to the COVID-19 pandemic; therefore, this position is currently under a 100 percent telework schedule. The position's telework schedule will likely change in the future when USPTO moves away from its maximum telework posture. At that time, the incumbent will be expected to report to the physical work site in accordance with the updated status requirements of their supervisor. The nature and scope of future telework opportunities will be subject to the unit's telework policy, any applicable bargaining unit agreements, and supervisory approval. Payment of relocation expenses, as applicable, will be paid in accordance with this Job Opportunity Announcement.

To ensure compliance with an applicable preliminary nationwide injunction, which may be supplemented, modified, or vacated, depending on the course of ongoing litigation, the Federal Government will take no action to implement or enforce the COVID-19 vaccination requirement pursuant to Executive Order 14043 on Requiring Coronavirus Disease 2019 Vaccination for Federal Employees. Therefore, to the extent a Federal job announcement includes the requirement that applicants must be fully vaccinated against COVID-19 pursuant to E.O. 14043, that requirement does not currently apply. Federal agencies may request information regarding the vaccination status of selected applicants for the purposes of implementing other workplace safety protocols, such as protocols related to masking, physical distancing, testing, travel, and quarantine.

The Chief Information Security Officer (CISO) develops and maintains the USPTO IT security vision, strategy, policies, and program. The CISO ensures USPTO compliance with Executive Orders or Presidential Memoranda issued by the President and with policies or guidance issued by the Office of Management and Budget (OMB), minimum security requirements and standards promulgated by the National Institute of Standards and Technology, and Binding Operational Directives (BODs) developed by the Department of Homeland Security (DHS) which are developed in response to a known or reasonably suspected information security threat, vulnerability or risk. The CISO is responsible for all aspects of USPTO Cybersecurity.

Additionally, the incumbent performs the following functions, but not limited to:

  • Establish and maintain the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected.
  • Establish the strategy, direct, manage, and oversee all aspects of USPTO Cybersecurity program; include leadership and oversight.
  • Direct the development and implementation of cybersecurity solutions where necessary, and ensure their office directs its mission and resources toward enhancing agency cybersecurity.
  • Ensure proper implementation of the Risk Management Framework to ensure proper management of security and privacy risks.
  • Direct staff in identifying, developing, implementing, and maintaining technology and processes across the enterprise to reduce information and information technology (IT) security and privacy risks.
  • Provide direction to the CIO, Deputy CIO and business units on all aspects necessary to assess risk and determine the appropriate level of protections for IT assets.
  • Provide security architecture direction for all ongoing architecture, design, software development, development environments, deployment and operations and maintenance.
  • Develop and establish information security policies, procedures, and control techniques to address all applicable government-wide requirements.
  • Ensure USPTO compliance with Federal reporting requirements (e.g. FISMA) including progress on remedial actions documented in Plan of Action and Milestones (POA&M).
  • Report breaches and major incidents to the US-Computer Emergency Readiness Team operated by DHS within mandatory timelines.
  • Lead collaborations with business and technical teams to review IT security conflicts/gaps between functional goals and existing capabilities.
  • Create, drive, and realize complex end to end enterprise IT security solutions and how decision / design impact IT service delivery.
  • Ensure information security staff members are trained and that all agency personnel are held accountable for complying with the agency-wide information security program.
  • Participate in annual IT planning and budgeting process.

Requirements

Help

Conditions of employment

  • You must be a U.S. Citizen or a National.
  • Required to pass a background investigation and fingerprint check.
  • Must be registered for Selective Service, if applicable (www.sss.gov).
  • Submit a Financial Disclosure Report (OGE-278) upon appointment.
  • You must use the questionnaire text boxes when submitting narrative responses to the PTQs and ECQs (10,000 character limit each)
  • Your resume and question responses must demonstrate the job-related competencies.

Qualifications

Specialized experience for this position includes but not limited to:

  • Demonstrate work experience having led and managed both security compliance and security operations functions as part of an agency-wide information security program.
  • Extensive experience providing expert guidance to other C-level executives on matters of risk, compliance, and information protection from a strategic and tactical business objective perspective.
  • Knowledge of and/or experience with the categorization of data and privacy; securing data in agile development by identifying gaps or concerns using penetration testing and applications scanning to ensure security and privacy at every step of the development and deployment pipeline.
  • Knowledge of and/or experience with leading security incident resolution; the testing and execution that ensures all personnel know where to go and what to do in case of a cyber security breach.

Experience must have been at a sufficiently high level of difficulty to clearly show that the candidate possesses the required professional/technical qualifications set forth below.

Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic; religious; spiritual; community, student, social). Volunteer work helps build critical competencies, knowledge, and skills and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.

Please provide your narrative responses to the Professional Technical Qualification (PTQs) and Executive Core Qualifications (ECQs) questions - Do not write "see resume".

Applicants are required to input narrative responses to the PTQs and ECQs in the text boxes as prompted by USAJobs. Each PTQ and each ECQ have a 10,000-character limit (to include spaces) and must be adhered to.

Professional Technical Qualifications: Applicants must clearly demonstrate in their application materials that they possess technical attributes in the Professional/Technical Qualifications (PTQs). The PTQs for this position are:

  1. Demonstrate your experience managing the performance and completion of a major Information Technology Security program including managing large product or project budgets and meeting strategic goals.
  2. Demonstrate your senior level experience driving security and/or privacy compliance, risk management, security operations, and communicating complex technical issues and solutions to technical and non-technical stakeholders, peers, and all levels of leadership.
  3. Demonstrated senior level experience applying a range of analytical skills to effectively plan, organize, implement, and measure cybersecurity related program objectives and progress.
  4. Demonstrate your senior level experience working with a broad and diverse user community to gather requirements, develop and validate cybersecurity solutions. Demonstrated ability in translating business requirements into security solutions, with experience developing blended multi-disciplinary teams in a matrix environment.
Please Note: Current career SES members, former career SES members with reinstatement eligibility, and SES Candidate Development Program graduates who have been certified by OPM, only need to submit a resume and narrative statement covering each of the PTQs requirements and do NOT need to address the ECQs.
For the following five Executive Core Qualifications (ECQs), you are required to submit a narrative response addressing your specific knowledge, skills, and abilities that demonstrate your possession of these qualifications. Be sure to provide specific examples of what you've done that demonstrates your possession of each ECQ. For more information about the Executive Core Qualifications please visit this site: : https://www.opm.gov/policy-data-oversight/senior-executive-service/reference- materials/guidetosesquals_2012.pdf

Leading Change - This core qualification involves the ability to bring about strategic change, both within and outside the organization, to meet organizational goals. Inherent to this ECQ is the ability to establish an organizational vision and to implement it in a continuously changing environment.

Leading People - This core qualification involves the ability to lead people toward meeting the organization's vision, mission, and goals. Inherent to this ECQ is the ability to provide an inclusive workplace that fosters the development of others, facilitates cooperation and teamwork, and supports constructive resolution of conflicts.

Results Driven - This core qualification involves the ability to meet organizational goals and customer expectations. Inherent to this ECQ is the ability to make decisions that produce high quality results by applying technical knowledge, analyzing problems and calculating risks.

Business Acumen - This core qualification involves the ability to manage human, financial and information resources strategically.

Building Coalitions - This core qualification involves the ability to build coalitions internally and with other Federal agencies, State and local governments, nonprofit and private sector organizations, foreign governments, or international organizations to achieve common goals.

Applicants are encouraged to follow the Challenge, Context, Action and Result (C-C-A-R) model outlined in the Guide To SES Qualifications.

Challenge - Describe a specific problem or goal.

Context - Describe the individuals and groups you worked with, and/or the environment in which you worked, to address a particular challenge (e.g., clients, co-workers, members of Congress, shrinking budget, low morale).

Action - Discuss the specific actions you took to address a challenge.

Result - Give specific examples of measures/outcomes that had some impact on the organization. These accomplishments demonstrate the quality and effectiveness of your leadership skills.

Note: Submit only the documents requested. Additional documents will not be reviewed by the rating panel. Uploaded documents addressing the PTQ's and ECQs will not be accepted.

Education

There is no education requirement for this position.

Preferred - a minimum of a Bachelor's degree in Computer science, Cybersecurity, Business Management, or related fields.

Current Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), and/or Certified Chief Information Security Officer (CCISO) certifications

Additional information

Probationary Period: You will be required to serve a one-year probationary period unless you previously completed the probationary period in the SES.

Mobility: Organizational and geographical mobility is essential in developing and managing SES leaders and generally is a key to advancement. Therefore, applicants are expected to be mobile and once appointed SES members may be reassigned at the discretion of the appointing authority.

If you are a male applicant born after December 31, 1959, you must certify that you have registered with the Selective Service System. If you are exempt from registration under Selective Service Law, you must provide appropriate proof of exemption. Please visit the Selective Service System website for more information.

This is a Non-Bargaining Unit position. This is a Public Trust position and has a risk level designation of "high" risk.

The incumbent is required to submit to a drug test to screen for illegal drug use prior to appointment and, if appointed, the incumbent may be subjected to random drug testing procedures.

Background Investigation: If selected for this position, you may be required to complete a Declaration for Federal Employment (OF-306), which includes a fingerprint and credit check, to determine your suitability for Federal employment and to authorize a background investigation.

The USPTO participates in E-Verify. For more information on E-Verify, please visit http://www.dhs.gov/files/programs/gc_1185221678150.shtm

All Federal employees are required to have Federal salary payments made by direct deposit to a financial institution of their choice.

Relocation Expenses are not authorized and will not be paid.

Veteran preference does not apply to the Senior Executive Service.

More than one selection may be made from this announcement if additional identical vacancies in the same title, series, grade, and unit occur within 90 days from the date the certificate was issued.

The Ethics in Government Act of 1978, as amended, requires senior officials in the executive, legislative and judicial branches to file public reports of their finances as well as other interests outside the Government. If selected for this position you will be required to file a Financial Disclosure Report (OGE Form 278). The OGE 278 is available to the public. The primary purpose of disclosure is to assist agencies in identifying potential conflicts of interest between a filer's official duties and the filer's private financial interests and affiliations.

The United States Patent and Trademark Office is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or other non-merit factors. If you believe that you have been discriminated against and would like to file an EEO complaint, you must do so within 45 days of the date of the alleged discriminatory act. Claims of employment discrimination must be submitted to the attention of the USPTO's Office of Equal Employment Opportunity & Diversity via email (oeeod@uspto.gov) or phone (571-272-8292).

How you will be evaluated

You will be evaluated for this job based on how well you meet the qualifications above.

You will be evaluated for this job based on how well you meet the qualifications above.
In order to be considered for this position, you must demonstrate in your application package that you meet the minimum specialized experience as defined under the "Qualifications" section, answer the Professional Technical Qualifications (PTQs), Executive Core Qualifications (ECQs), and submit a detailed resume that supports your answers to the PTQs, ECQs, and specialized experience.

Your responses to the PTQs, ECQs, and resume will be evaluated by a Human Resources Specialist and/or a subject matter expert. Falsifying your background, education, and/or experience is cause for not hiring you or for changing your scored responses to questions you've answered, which may affect your overall final score. Please note that a complete application is required for consideration. (Please review the "Required Documents" section of this job announcement to see what must be included in a complete application).

Candidates who are evaluated by an executive rating panel based on the degree to which they meet the PTQs, ECQs, and considering the applicant's education, work-related experience, training, awards, and professional recognition, as set forth in the materials submitted by the candidates and placed in one of the pre-defined quality categories. These categories are "Highly Qualified", "Well Qualified" and "Qualified." Candidates placed in the "highest quality category" will be identified for referral to the hiring manager and may be invited for an interview.

Patent and Trademark Office

Come work for the Patent and Trademark Office, we have been ranked as one of the best places to work in the federal government! The U.S. Patent and Trademark Office (USPTO) has been serving the economic interests of America for more than 200 years. We are responsible for granting US intellectual property rights for patents and trademarks. The USPTO is headquartered in Alexandria, Virginia, and has over 12,000 employees. For more information about the USPTO, please visit the USPTO Jobs Website.

Agency contact information

Brian Bobo
Phone
571-272-1175
Email
brian.bobo@uspto.gov
Address
EXRD - Office of the Chief Information Officer
550 Elizabeth Lane
Alexandria, VA 22314
US

Your session is about to expire!

Your USAJOBS session will expire due to inactivity in 8 minutes. Any unsaved data will be lost if you allow the session to expire. Click the button below to continue your session.