Skip to main content
U.S. flag
Back to results

Federal Cybersecurity Risk Advisor

Department of Homeland Security
DHS Headquarters
This job announcement has closed

Summary

The Department of Homeland Security is recruiting for Federal Cybersecurity Risk Advisors in the Cybersecurity Division (CSD) Capacity Building (CB) Sub-Division of the Cybersecurity and Infrastructure Security Agency (CISA),

Overview

Help
Reviewing applications
Open & closing dates
05/20/2022 to 06/19/2022
Salary
$114,800 to - $170,830 per year

Range includes a 10% local cybersecurity talent market supplement, which is only available in certain geographic areas (metro Washington, D.C.)

Pay scale & grade
DC 2
Location
Many vacancies in the following location:
Arlington, VA
Remote job
No
Telework eligible
Yes—as determined by the agency policy.
Travel Required
Not required
Relocation expenses reimbursed
No
Appointment type
Permanent
Work schedule
Full-time
Service
Excepted
Promotion potential
None
Supervisory status
No
Security clearance
Sensitive Compartmented Information
Drug test
Yes
Position sensitivity and risk
Special-Sensitive (SS)/High Risk
Trust determination process
Announcement number
22-11497845-CBWQ
Control number
655401400

Duties

Help

As the Federal Cybersecurity Risk Advisor in the Cybersecurity and Infrastructure Security Agency (CISA) Cybersecurity Division (CSD) Capacity Building (CB) Sub-Division you will provide tailored improvement planning and program management to Federal Agencies by implementing existing and emerging Federal requirements and enhancing their incident response capabilities.

As a key member of the Federal Enterprise Improvement Team (FEIT), you will provide dedicated, expert support to Federal Civilian Executive Branch agencies' security operations, at both the executive and operational level.

You will continually enhance and apply your expertise in the technical capability of Cybersecurity Risk Management and Compliance to:

  • Develop strategic partnerships and foster collaborative opportunities to grow the FEIT and identify Federal cyber improvement priorities
  • Enhance tailored cyber incident response planning and assistance to Agencies, relative to their cybersecurity posture - to include providing Agencies with deeper understanding of enterprise requirements across their cybersecurity risk profile and offering direct assistance in developing plans of action and sustaining improvements, leveraging investments, shared service offerings, and technical assistance
  • Continually measure and evaluate FEIT progress and performance as they relate to CISA and White House Strategic direction to track Agency progress and identify internal process enhancements
  • Improve cyber risk governance and risk management that affects the entire Federal enterprise, and mature agency security operations functions to create a more integrated detection and response model
  • Serve as an expert consultant evaluator for functional teams, to assist them in anticipating, identifying, evaluating, mitigating, and minimizing risks associated with system vulnerabilities, and recommend appropriate technical strategies to resolve complex and persistent IT security challenges
  • Analyze agency policy, recommend improvements, and advise agencies on implementing higher-level security requirements, such as those resulting from laws, regulations, and Presidential directives, and consults system designers and system administrators on the consistency of proposed IT security strategies with these requirements.
  • Advise system managers on appropriate trade-offs to ensure IT systems are given a level of protection commensurate with their importance to the overall USA mission and with the mission risks introduced using relevant information technologies
  • Work closely with Agency subcomponents to assure appropriate project and resource integration are documented and justified and makes recommendations to achieve a sound information assurance and security environment is fully integrated within CISA strategy
  • Analyze agency policy and customize communications for different levels of agency leadership and target audiences to explain critical implications and recommend improvements
  • Develop highly effective, long-range plans for IT security systems
  • Review proposed new systems, networks, and software designs for potential security risks, and resolve integration issues related to the implementation of new systems with the existing infrastructure

Requirements

Help

Conditions of employment

  • You must be a U.S. Citizen or national.
  • You must be 18 years of age.
  • Must be registered for the Selective Service (if you are a male).
  • Must be able to obtain and maintain a TOP SECRET/SCI security clearance.
  • Must be able to submit to a drug test and receive a negative result.
  • Must be able to comply with ethics and standards of conduct requirements, including completing any applicable financial disclosure.
  • May be required to serve a 3 year probationary period.

Qualifications

This position is in the Technical Career Track at the Staff Cybersecurity Specialist Level. At this level, individuals generally:

  • Are considered a resident cybersecurity expert who applies significant technical expertise to develop solutions for critical, non-routine challenges
  • Have 8+ years of cybersecurity work experience
DHS Cybersecurity Service employees start at career levels and salaries matching their experience and expertise. To learn more about DHS Cybersecurity Service career tracks and levels, visit our application portal.

This position is focused on Cybersecurity Risk Management and Compliance.

DHS Cybersecurity Service jobs are structured cybersecurity specializations - called technical capabilities. To learn more about technical capabilities, visit our application portal.

DESIRED TOOLS/INDUSTRY EXPERIENCE:Knowledge of federal cybersecurity requirements (e.g., Federal Information Security Management Act (FISMA), relevant Executive Orders, Office of Management and Budget (OMB) memoranda, CISA directives). Exposure to tools/technologies required to implement or oversee hardware/software asset management; identity, credential, and access management; data discovery; secure cloud services; intrusion detection and prevention; endpoint detection and response; cyber threat intelligence; enterprise cybersecurity risk management; supply chain risk management.

DESIRED CERTIFICATION:
  • Certified Cloud Security Professional (CCSP)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)

Education

Degrees are not required for jobs in the DHS Cybersecurity Service, but DHS is interested in your level of education and the topics you studied. As you submit initial application information, you will be asked questions about your education.

Additional information

Benefits: DHS Cybersecurity Service employees receive a range of federal employment benefits designed to support their professional and personal lives. To learn more about benefits, visit our application portal.

More information about the specific benefits available to you will be provided as you progress through the application process.

Background Investigation: To ensure the accomplishment of its mission, the Department of Homeland Security (DHS) requires each and every employee to be reliable and trustworthy. To meet those standards, all selected applicants must undergo and successfully complete a background investigation for a security clearance as a condition of placement in this position. This review includes financial issues such as delinquency in the payment of debts, child support and/or tax obligations, as well as certain criminal offenses and illegal use or possession of drugs.

Pursuant to Executive Order 12564 and DHS policy, DHS is committed to maintaining a drug-free workplace and, therefore, conducts random and other drug testing of its employees in order to ensure a safe and healthy work environment. Headquarters personnel in safety- or security-sensitive positions are subject to random drug testing and all applicants tentatively selected for employment at DHS Headquarters are subject to drug testing resulting in a negative test result.

How you will be evaluated

You will be evaluated for this job based on how well you meet the qualifications above.

All DHS Cybersecurity Service applicants participate in a multi-phase assessment process, which varies by career track. For the Technical Career Track, applicants participate in a three-phase assessment process:

  • You must successfully complete each phase to advance to the next phase.
  • The total time commitment for all three phases is approximately 5-6 hours (many applicants require less time!).
  • Before each phase, DHS will e-mail you instructions and information to help you prepare.
  • Assessments are time sensitive, so monitor your e-mail to ensure you have plenty of time to complete them prior to any deadlines.
PHASE I: ONLINE ASSESSMENTS
  • Unproctored - you choose the time and location.
  • Includes two assessments: (1) a work styles inventory that will take about 30 minutes to complete; (2) a work simulation that you will have up to 2 hours to complete.
  • The two assessments take about 90 minutes (on average) to complete.
  • Requires a computer with audio (speakers or headphones) and a reliable internet connection.
  • No knowledge of DHS or cybersecurity is required for these assessments, which measure non-technical capabilities that are important for professional success in the DHS Cybersecurity Service. This includes how you communicate, analyze information, and collaborate with others:
    • The work styles inventory presents you with questions about your work-related interests and preferences.
    • The work simulation presents you with realistic, work-related scenarios and asks you to respond to them.

PHASE II: TECHNICAL CAPABILITY ASSESSMENT

  • Proctored - must be scheduled in advance and completed at a designated assessment center.
  • There is a different assessment for each DHS Cybersecurity Service technical capability (visit Jobs to learn more about the technical capabilities).
  • Most individuals only have a primary technical capability and complete only one Technical Capability Assessment, but in limited circumstances, you may complete a second Technical Capability Assessment.
  • You will have up to 2.5 hours to complete each Technical Capability Assessment; each takes about 90 minutes (on average) to complete
  • Assessments present realistic, work-related cybersecurity scenarios and questions to assess technical skills.
  • Cybersecurity knowledge is assessed, but no knowledge of DHS is required.
PHASE III: STRUCTURED INTERVIEW*
  • Online, recorded video interview - you choose the time and location.
  • 45 minutes to complete.
  • Record and review your responses to interview questions.
  • Requires a computer, phone, or tablet with a reliable internet connection, webcam, and audio.
  • No knowledge of DHS or cybersecurity is required for this assessment, which measures non-technical capabilities that are important for professional success in the DHS Cybersecurity Service:
    • You will be asked to verbally respond to a series of questions focused on your previous experience and hypothetical work situations or scenarios.
*Some applicants who successfully complete Phase III may be asked to participate in a Phase IV: Advanced Technical Interview. This scenario-based interview is used to further assess an applicant's proficiency in a technical capability. More information will be provided to such applicants as they progress through the application process. To learn about the assessment process for this Technical Track position, visit our application portal and read the "Assessment Process" guide.

Your session is about to expire!

Your USAJOBS session will expire due to inactivity in 8 minutes. Any unsaved data will be lost if you allow the session to expire. Click the button below to continue your session.