Skip to main content
U.S. flag
Back to results

IT Specialist (Cybersecurity), CG-2210-14

Federal Deposit Insurance Corporation
This job announcement has closed

Summary

This position is located in the Chief Information Officer Organization, Office of the Chief Information Security Officer, Cyber Risk Management Section of the Federal Deposit Insurance Corporation (FDIC). The incumbent is responsible for leading and managing cyber risk management efforts focused on DevSecOps and Application Security.”

Additional selections may be made from this vacancy announcement to fill identical vacancies that occur subsequent to this announcement.

Overview

Help
Reviewing applications
Open & closing dates
12/20/2024 to 01/06/2025
Salary
$153,507 to - $250,360 per year
Pay scale & grade
CG 14
Location
Washington, DC
1 vacancy
Remote job
No
Telework eligible
Yes—TELEWORK OPTIONS ARE SUBJECT TO CHANGE.
Travel Required
Occasional travel - Occasional travel may be required. (25% or less)
Relocation expenses reimbursed
No
Appointment type
Permanent
Work schedule
Full-time
Service
Competitive
Promotion potential
14
Supervisory status
No
Security clearance
Other
Drug test
No
Position sensitivity and risk
High Risk (HR)
Trust determination process
Financial disclosure
Yes
Bargaining unit status
No
Announcement number
2024-CIOO-DH986
Control number
825139500

This job is open to

Help

Clarification from the agency

This position is open to All United States Citizens. This is a Direct-Hire Public Notice.

Duties

Help

  • Conducts assessments of controls, threats and vulnerabilities, determine deviations from acceptable configurations, enterprise or local policy, assesses the level of risk, and develop and/or recommend appropriate mitigation countermeasures in all situations.
  • Plan and conduct cybersecurity assessment and authorization activities as systems are deployed to production for the first time and after they are transitioned to continuous monitoring. Develop assessment and authorization strategies, concepts, processes for managing cybersecurity risks through DevSecOps methods. Review assessment and authorization documents and artifacts to confirm that the level of risk is within acceptable limits for each software application, system, and network. Develop cybersecurity compliance processes and/or assessments for external services (e.g., cloud service providers, external data centers).
  • Participate in Risk Governance process to provide security risks, mitigations, and input on other technical risks. Provide input to the Risk Management Framework process activities and related documentation (e.g., security categorization worksheets, system security plans, configuration management plans, business impact analysis, contingency plans, concept of operations, operational procedures, maintenance training materials, security categorization worksheets, configuration management plans).
  • Verify that controls are implemented as stated, any deviations and gaps are documented, and required actions to correct those deviations are tracked through Plan of Action and Milestones (POA&Ms). Ensure that POA&Ms or remediation plans are in place for vulnerabilities identified during security and privacy control assessments, audits, inspections, and etc.

Requirements

Help

Conditions of employment

Registration with the Selective Service.

U.S. Citizenship is required.  

Employment Conditions.

Completion of Confidential Financial Disclosure may be required.

 Background Investigation (BI) required

Qualifications

Qualifying experience may be obtained in the private or public sector. Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g. Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic, religious spiritual; community; student, social). Volunteer work helps build critical competencies, knowledge, and skills and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.  Additional qualifications information can be found here.  
To qualify, applicants must have completed at least one year of specialized experience equivalent to at least the 13-grade level or above in the Federal service.  Specialized experience is defined as: experience developing solutions to integration/interoperability issues; designing, developing, and assisting with managing IT security systems that meet current and future business requirements; and providing advice on solutions on issues that comply with federal security requirements and guidance while meeting current and future business requirements.
Use of Selective Placement Factor - If there is a selective placement factor(s), include the following statement as part of the qualification requirements:

“In addition to the qualification requirements listed above, you must also meet the following selective placement factor to be considered eligible for this job. The selective placement factor is defined as:

You must have Information Technology (IT)-related experience which demonstrates proficiency in each of the following competencies:

• Attention to Detail - Is thorough when performing work and conscientious about attending to detail.

• Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services.

• Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately.

• Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations.

Education

There is no substitution of education for the experience for this position.

Additional information

Selectee(s) for this position will be required to report to their duty station office two days per week.

To read about your rights and responsibilities as an applicant for Federal employment, click here.

If selected, you may be required to serve a probationary period.

How you will be evaluated

You will be evaluated for this job based on how well you meet the qualifications above.

This is a Direct-Hire Public Notice.  Applications will be accepted for the location identified in the public notice.  Veteran’s preference and traditional rating and ranking of applicants DO NOT apply to positions filled under this public notice. 

All complete applications (transcripts must be included, if applicable) will be verified for eligibility requirements and will be submitted to the hiring official upon request.

https://www.opm.gov/policy-data-oversight/hiring-information/direct-hire-authority/#url=Governmentwide-Authority

Upon the submission of your application package to USAJobs.gov, you will receive an automatic reply informing you that your application has been submitted, received and is being processed. If you provided an email address, you will receive an email message acknowledging the receipt of your application. Your application will remain active through the open period of this Public Notice. You will not receive any additional notifications, and your resume may not be reviewed for qualifications unless a position is requested to be filled by the hiring official. After you submit your application, you will be contacted only if further evaluation or interviews are required or upon your selection.”

If requested by Management, your application will be reviewed to determine whether you meet the qualification requirements outlined in this announcement. Therefore, it is imperative that your resume contain sufficiently detailed information upon which to make the qualification determination. Please ensure that your resume contains specific information such as position titles, beginning and ending dates of employment for each position, average number of hours worked per week, and if the position is/was in the Federal government, you should provide the position series and grade level.

You do not need to respond separately to these KSAs. Your resume will serve as responses to the KSAs.

  1. Knowledge of Security Assessment and Authorization process.
  2. Skill applying IT principles, concepts, methods, standards, and practices.
  3. Skill in applying methods for evaluating, implementing, and disseminating IT security tools and procedures to coordinate activities designed to ensure, protect, and restore IT systems, services, and capabilities.
  4. Skill in recognizing and categorizing types of vulnerabilities and associated attacks.
  5. Skill in performing security impact/risk assessments and preparing Security Assessment Reports.
  6. Skill applying theories and new developments to information security problems not susceptible to treatment by accepted method and design new ways to conduct valid and reliable assessments.

You may preview questions for this vacancy.

Your session is about to expire!

Your USAJOBS session will expire due to inactivity in 8 minutes. Any unsaved data will be lost if you allow the session to expire. Click the button below to continue your session.