Skip to main content
U.S. flag
 

IT Specialist - Governance, Risk, and Compliance (GRC) Lead

Securities and Exchange Commission
Office of Information Technology

Summary

The Office of Information Technology (OIT) is seeking an Information Technology Specialist (INFOSEC) (IT Specialist - Governance, Risk, and Compliance (GRC) Lead). As a GRC Lead, you will report to the Branch Chief of Cyber Risk and Governance, leading the implementation of automated governance, risk, and compliance toolsets. The role also requires participation in cybersecurity risk analysis, Federal compliance initiatives, and audit management.

Overview

Help
Accepting applications
Posted yesterday · Apply by 06/25/26
Due by 11:59 p.m. ET on June 25, 2026
Location
1 vacancy in the following location:
Work site options
Telework eligible
No
Remote job
No
Relocation expenses reimbursed
No
Salary
$153,114 - $259,402 per year
Pay scale & grade
SK 14
Promotion potential
14
Pay scale and grade determines the salary of the job.
Work schedule
Full-time
Travel Required
Occasional travel - You may be expected to travel for this position.
Appointment type
Permanent
Occupations and job series
Supervisory status
No
Federal service type
This job is in the Competitive Service
Represented by a union
Yes
Drug test
No
Security clearance
Other
Position sensitivity and risk
High Risk (HR)
Jobs require a background check and some require a security clearance. The type depends on the job.
Background check type
Financial disclosure required
Yes
Some jobs require financial disclosure to identify conflicts of interests.
Announcement number
26-IN-12979706-SMP
Control number
872531300

This job is open to

Help

Clarification from the agency

Well-qualified surplus/displaced SEC employees ((i.e. CTAP) in the local area and current SEC employees in permanent competitive service positions (i.e. status candidates)

Duties

Help

In this role as a IT Specialist - Governance, Risk, and Compliance (GRC) Lead, you will be responsible for:

  • Developing, implementing, maintaining cybersecurity governance, risk, and compliance toolsets;
  • Proposing innovative approaches to optimize technology usage for the cybersecurity GRC program;
  • Transforming existing manual processes into streamlined and efficient digitally-supported workflows;
  • Leading initiatives that support compliance with existing and new Federal cybersecurity requirements;
  • Authoring enterprise information security policies, procedures and templates; and
  • Leading audit management activities including audit response.

Requirements

Help

Conditions of employment

  • CITZENSHIP: You must be a US Citizen.
  • SELECTIVE SERVICE: Males born after 12/31/59 must be registered or exempt from Selective Service (see https://www.sss.gov/).
  • DRUG TESTING: This position may be subjected to drug testing requirements.
  • PERMANENT CHANGE OF STATION (PCS): Moving/Relocation expenses are not authorized.
  • DIRECT DEPOSIT: All Federal employees are required to have Federal salary payments made by direct deposit to a financial institution of their choosing.
  • The duties of this position may require the incumbent to carry a cell phone and be on call 24 hours a day, seven days a week on a rotational basis, based on the needs of the organization.

Qualifications

Time-in-grade for this announcement is one year at the GS/SK-13 level.

Applicants are responsible for confirming all required materials are submitted by the closing date of the announcement. Please check the How You Will Be Evaluated and Required Documents sections carefully, as missing documents will render the application incomplete and ineligible for review.

Qualifying experience may be obtained in the private or public sector. Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic; religious; spiritual; community, student, social). Volunteer work helps build critical competencies, knowledge, and skills and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience. All qualification requirements must be met by the closing date of this announcement.

BASIC REQUIREMENT: For all positions individuals must have IT-related experience demonstrating each of the four competencies listed below:

  1. Attention to Detail - Is thorough when performing work and conscientious about attending to detail.
  2. Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services.
  3. Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately.
  4. Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations.

MINIMUM QUALIFICATION REQUIREMENT: In addition to meeting the basic requirement, applicants must also meet the minimum qualification requirement below.

SK-14: Applicant must have at least one year of specialized experience equivalent to the GS/SK-13 level:
  1. Implementing process improvements for cybersecurity governance, risk, and compliance activities;
  2. Designing workflows for governance, risk, and compliance toolsets;
  3. Performing cybersecurity risk analysis; and
  4. Coordinating audit testing and response activities.

ACCOMPLISHMENT RECORD COMPETENCIES: Your Accomplishment Record narratives should address the following competencies. See the How You Will Be Evaluated section below for more information:
  • Technology Expertise: Knowledge of the principles and methods of specialized technologies, tools, and delivery systems, including security, risk management, governance, functionality, and user interface in area of expertise (e.g., programming languages, server, web, applications, network)
  • Business Process Improvement: Uses business process reengineering methods, metrics, tools, and techniques to improve quality, speed, and service.
  • Problem Solving and Decision Making: Ability to identify and solve important problems relevant to program areas through sound and timely decision making, even in less than ideal situations, with little or no guidance.
  • Risk Management and Disaster Recovery: Uses methods and tools for risk assessment and mitigation of risk, including the identification, assessment, and prioritization of risks to minimize, monitor, and control the probability and/or impact of events.

Additional information

Supplementary vacancies may be filled in addition to the number stated in this announcement and may be filled from any division or office within the agency.

SEC COMPENSATION PROGRAM: Total salary (base pay + locality) is dependent upon duty location. The overall salary range listed above is provided for informational purposes. The pay for current SEC employees will be determined according to the procedures specified in the agency's policy.

IMPORTANT INFORMATION FOR SURPLUS OR DISPLACED FEDERAL EMPLOYEES: If you have never worked for the federal government, you are not I/CTAP eligible. To receive selection priority for this position, you must: (1) meet CTAP or ICTAP eligibility criteria; the questionnaire asks you to identify your ICTAP/CTAP eligibility (2) be rated well-qualified; and, (3) submit the appropriate documentation to support your CTAP or ICTAP eligibility. View information about I/CTAP eligibility on OPM's Career Transition Resources website.

Disability Employment: For information on disability appointments, click here.

Reasonable Accommodation: If you are an applicant who needs a reasonable accommodation to participate in the SEC application process due to a medical disability, please contact reasonableaccommodation@sec.gov. For religious-based accommodations, please contact religiousaccommodation@sec.gov . Please be sure to submit your request at least 5 business days in advance of the date you need the requested accommodation.

Equal Employment Opportunity (EEO) Information for SEC Job Applicants: For more information, please click here.

The Fair Chance Act prohibits specific inquiries concerning an applicant's criminal or credit background unless the hiring agency has made a conditional offer of employment to the applicant. An applicant may submit a complaint, or any other information, to the agency within 30 calendar days of the date of alleged non-compliance by contacting the Legal and Policy Office in the Office of Human Resources at ElliottT@sec.gov.

Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution.

How you will be evaluated

You will be evaluated for this job based on how well you meet the qualifications above.

Your resume and application package will first be reviewed to determine whether you meet the minimum qualification requirements outlined in the announcement.

If you are found minimally qualified, the Office of Human Resources will contact you to request an Accomplishment Record. You will have 3 business days from the date of the request to submit it. Failure to submit the Accomplishment Record on time will remove you from further consideration. Because of the short turnaround time, you are strongly encouraged to begin preparing your Accomplishment Record in advance.

Once your Accomplishment Record is received, a rating panel will review both your resume and your narrative responses. Your Accomplishment Record must clearly demonstrate your proficiency in the competencies listed in the Qualifications section. Click here for guidance on writing your Accomplishment Record.

Your resume must provide evidence that supports the claims in your Accomplishment Record. Each narrative must describe one specific, relevant example from your experience or training. Responses are limited to 300 words per competency; any text beyond this limit will not be reviewed.

You must upload one document containing your narrative responses for all four competencies. Failure to address each competency annotated on the announcement or failure to provide the correct document will result in loss of further consideration. Please note: A Performance Appraisal does not satisfy the requirement for an Accomplishment Record.

Required Accomplishment Record Format:

Applicant First Name and Last Name
Competency Title

  • Position title and dates from your resume that this experience was obtained
  • Describe the situation (i.e., the challenged faced, the problem solved)
  • Describe the specific actions you took
  • State the outcome, results, or long-term impact of your accomplishment
  • Name and email address of someone who can verify this information
Reference checks may be conducted as part of the final selection process, and you will be notified before any contacts are made.

Basis for Rating: The rating panel will evaluate applicants' accomplishment records and resume, then place them into one of the following categories:
  • Highly Qualified - Meets the minimum qualification requirements and has extensive skills and experience in most of the job related competencies.
  • Well Qualified - Meets the minimum qualification requirements and has a moderate amount of skills and experience in most of the job related competencies.
  • Qualified - Meets the minimum qualification requirements, but may have a limited amount of experience in several of the job related competencies.
Top ranked applicants will be referred to the hiring office for further review and consideration. The hiring office may directly contact recommended candidates for interview(s).

To preview the Questionnaire, click https://apply.usastaffing.gov/ViewQuestionnaire/12979706

Securities and Exchange Commission

Our mission includes advocating for investors who seek to secure a future for their family, providing guidance and regulations for the nation's securities industry in an increasingly global market, and taking action with an eye toward promoting the capital formation necessary to sustain economic growth.

A career with the Securities and Exchange Commission (SEC) offers work that is exciting, challenging and rewarding. You can contribute to securities regulation and enforcement while making a positive difference for the American investing public. The SEC provides:

  • Careers that broaden and deepen your already accomplished knowledge, skills and abilities;
  • An environment that allows you to work and learn with the nation's experts;
  • Benefits, compensation and career expansion opportunities; and
  • A balance between your professional and family life.
The SEC offers a number of enhanced pay and benefits plus the standard Federal benefits. Please be sure to visit the SEC's compensation and benefits program pages.

Agency contact information

ask HR
Email
askHR@sec.gov
Address
Office of Information Technology
100 F Street NE
Washington, DC 20549
US

Visit our careers page

Learn more about what it's like to work at Securities and Exchange Commission, what the agency does, and about the types of careers this agency offers.

https://www.sec.gov.

Your session is about to expire!

Your USAJOBS session will expire due to inactivity in 8 minutes. Any unsaved data will be lost if you allow the session to expire. Click the button below to continue your session.