Skip to main content
U.S. flag
 

Chief Information Security Officer (CISO), EM-2210-00 (Merit Promotion)

Federal Deposit Insurance Corporation

Summary

This position is located in the Chief Information Officer Organization (CIOO), Office of the Chief Information Security Officer (OCISO) of the Federal Deposit Insurance Corporation and provides support in Washington, D.C.

Salary reflects a pay cap for this position of $315,000.

Overview

Help
Location
1 vacancy in the following location:
Work site options
Telework eligible
Yes—As determined by the agency policy.
Remote job
No
Relocation expenses reimbursed
No
Salary
$280,000 - $315,000 per year
Pay scale & grade
EM 00
Promotion potential
EM - 00
Pay scale and grade determines the salary of the job.
Work schedule
Full-time
Travel Required
Occasional travel - Occasional travel may be required.
Appointment type
Permanent
Occupations and job series
Supervisory status
Yes
Federal service type
This job is in the Competitive Service
Represented by a union
No
Drug test
Yes
Security clearance
Sensitive Compartmented Information
Position sensitivity and risk
Critical-Sensitive (CS)/High Risk
Jobs require a background check and some require a security clearance. The type depends on the job.
Financial disclosure required
Yes - This position requires the selectee to file a public financial disclosure report (OGE Form 278e) as a condition of employment.
Some jobs require financial disclosure to identify conflicts of interests.
Announcement number
2026-EM-MP-0196
Control number
878581500

Duties

Help

  • As the Chief Information Security Officer (CISO) and Director of the Office of the Chief Information Security Officer, the incumbent provides the necessary technical expertise and leadership required to assure FDIC information and manage risks related to the use, processing, storage, and transmission of information, including the protection of the integrity, availability, authenticity, non-repudiation, and confidentiality of user data. Working with FDIC executives and senior leadership and under the direction of the CIO, the CISO establishes an agency-wide information security vision and strategy, including the creation and maintenance of FDIC's information security and privacy policy, risk assessment, compliance, oversight, and ensuring continuity of operations. Program responsibilities include information security architecture and engineering; activities to identify, protect, detect, respond, and recover from cybersecurity threats; assessments and authorizations; information security and privacy risk management; and information security/privacy awareness and training. Additionally, the incumbent is responsible for management and oversight of the FDIC's privacy program and demonstrating compliance with all relevant federal laws and regulations.
  • Provides executive leadership, management and oversight for effective strategic planning and budget control, workforce planning, policy and standards development, resource management, knowledge management, information security architecture, engineering, and infrastructure planning, auditing, and information security management.
  • Represents the FDIC at executive-level meetings with federal organizations such as OMB, the Government Accountability Office (GAO), and other federal government agencies (Departments), other FIRREA organizations, as well as non-profit and private sector companies and organizations.
  • Proactively works with business units to implement practices that meet defined policies and standards for information security and will also oversee a variety of risk management activities.
  • Maintains ongoing knowledge of: (a) Federal legislation, regulation, policies, and practices related to cybersecurity, privacy and information systems security; (b) methodologies and best practices that are commonly used in the information systems security industry; (c) the status of Federal Information Systems Security initiatives that offer opportunities for or pose requirements to be met by the FDIC; (d) the review of IT architectures used at all FDIC locations including microcomputer, server, mainframe processing levels and related peripheral products to assess and remediate weaknesses to information systems security; (e) Cloud or COTS software packages; custom developed software applications; Code libraries, and network and telecommunications products and technologies; and (f) threats and vulnerabilities that could impact FDIC value assets and information.
  • Directs Corporation-wide information security and privacy programs that comply with federally mandated requirements and commonly accepted industry best practices. 
  • Oversees vulnerability assessments and supports audits as appropriate to: (a) ascertain the current state of information system security and to highlight areas of high, medium and low risk to agency management; (b) identify systems that process or store personally identifiable information (PII) or sensitive business information, and advise and support the identification and remediation of their associated risks, lead the assessment and authorization process to ensure systems are implemented with the appropriate security/privacy controls prior to being released into production.
  • Proactively works with managers overseeing system architecture, proactively advising and monitoring to promote compliance with Federal and industry requirements, and to minimize the risk of disruption to operations through the necessary controls to maintain the confidentiality, integrity, and availability needs of information and systems.
  • Exercises supervisory personnel management authority directly or indirectly through subordinate senior managers to include: planning, assigning, and reviewing work products of subordinates; establishing guidelines and performance expectations; and evaluating work performance and providing feedback. Identifies training and developmental needs for staff and provides regular recognition of staff. Works in collaboration with the appropriate Human Resources and Legal staff to administer disciplinary action. Hears and resolves grievances or other disputes as appropriate. Approves/disapproves requests for leave, telework, travel, training, etc. Ensures that programs are administered effectively and in accordance with broadly stated objectives and priorities.

Requirements

Help

Conditions of employment

2-page Resume Requirement: Please limit your résumé to 2 pages (minimum 10-point font).  If more than 2 pages are submitted, only the first 2 pages will be reviewed to determine your eligibility/qualifications.

Registration with the Selective Service.

U.S. Citizenship is required.  

Employment Conditions.

Completion of Confidential Financial Disclosure may be required.

Top Secret with Sensitive Compartmented Information (SCI) required.

Ability to obtain and maintain a Top-Secret security clearance.

Applicant tentatively selected for this position will be required to submit to urinalysis to screen for illegal drug use prior to appointment and will be subject to random drug tests.

Must be able to obtain and maintain an interim and/or final security clearance prior to entrance on duty. Failure to obtain and maintain the required level of security clearance may result in the withdrawal of a job offer or removal.

Employee may be relocated to any duty location to meet management needs.

Qualifications

To meet the minimum qualifications, applicants must possess the leadership and technical experiences listed below. These qualifications would typically be gained through progressively responsible management or executive-level assignments.
Qualifying experience may be obtained in the private or public sector. Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic, religious/spiritual; community; student, social). Volunteer work helps build critical competencies, knowledge, skills, and abilities and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.

MINIMUM QUALIFICATIONS: All applicants must submit a resume that addresses each minimum qualification experience. Examples should be clear, concise, and emphasize your level of responsibilities; the scope and complexity of the programs, activities, or services you managed; program accomplishments; policy initiatives undertook; level of contacts; the sensitivity and criticality of the issues you addressed; and the results of your actions. You should use action-oriented leadership words to describe your experience and accomplishments and quantify your experience wherever possible to demonstrate your accomplishments (e.g., number of employees supervised). Leadership experiences identified must have been performed in an official supervisory role.

Leadership Experience 1: Experience in overseeing and coordinating the work of organizational units directly and indirectly through subordinate supervisors, including assigning work, directing changes to programs and priorities, and evaluating performance against goals; AND

Leadership Experience 2: Experience in managing employee performance and growth directly and indirectly through subordinate supervisors, including evaluating employee readiness for successive roles, recognizing accomplishments, providing feedback and development opportunities, and addressing performance/conduct issues; AND

Leadership Experience 3: Experience in overseeing implementation of and improvements to recruiting, hiring, training, utilization, and succession readiness of staff; AND

Technical Experience 1: Experience in directing information security and/or privacy programs impacting large organizations; AND

Technical Experience 2: Experience in translating business requirements into business solutions with information technology to include the development, implementation and maintenance of cybersecurity and privacy programs responsive to the organization's mission.

Education

There is no substitution of education for the experience for this position.

Additional information

If selected, you may be required to serve a probationary or trial period as applicable to appointment type. During the probationary or trial period, you will be evaluated for fitness and whether your continued employment advances the public interest. In determining if your employment advances the public interest, we may consider: 

  • your performance and conduct;
  • the needs and interests of the agency;
  • whether your continued employment would advance organizational goals of the agency or the Government; and
  • whether your continued employment would advance the efficiency of the Federal service.

Upon completion of your probationary or trial period your employment will be terminated unless you receive certification, in writing, that your continued employment advances the public interest. 

To read about your rights and responsibilities as an applicant for Federal employment, click here.

If selected, you may be required to serve a supervisory/managerial probationary period.

Additional selections may be made from this vacancy announcement to fill identical vacancies that occur subsequent to this announcement.

FDIC Executive Managers (EM) are in the Federal competitive service and not the Senior Executive Service (SES). As an EM at the FDIC, you will provide executive leadership and managerial direction over substantive activities related to planning, developing, executing, and coordinating the Corporation's programs and policies.

Current or Former Political Appointees: The Office of Personnel Management (OPM) must authorize employment offers made to current or former political appointees. If you are currently, or have been within the last 5 years, a political Schedule A, Schedule C or Non-Career SES employee in the Executive Branch, you must disclose this information to the HR Office.

Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution.

How you will be evaluated

You will be evaluated for this job based on how well you meet the qualifications above.

Your resume will be reviewed, to determine whether you meet the qualification requirements outlined in this announcement. Therefore, it is imperative that your resume contains sufficiently detailed information upon which to make the qualification determination. 

If you are found minimally qualified, a Management Rating Panel (MRP) will review your qualifications and experience against pre-established benchmarks. The rating panel will place applications in one of three quality categories, i.e., Best Qualified, Highly Qualified, or Qualified. These category assignments are a measure of the degree in which your background and responses to the assessment questions match the competencies listed below. 

Top ranked (Best Qualified) candidates will be referred to the selecting official for further review and consideration.

The competencies/KSAs you will be assessed on are listed below.

  1. Strategic Thinking
  2. Managing Risk
  3.  Organizational Awareness
  4. Interpersonal Relationships
  5.  External Awareness
  6.  Financial and Resource Management
  7.  Change Management
  8.  Organizational Stewardship
  9. Knowledge of and ability to work with emerging and/or state-of-the-art information security techniques, technologies and tools whether commercially available, Government supplied, or custom developed (e.g., maintaining information security/privacy, monitoring, assessing and evaluating security; security forensics work).
  10. Knowledge and experience in developing information security and privacy programs, policies and procedures, as well as successfully executing these to meet organization objectives and drive excellence in a dynamic environment. 
  11. Knowledge of legacy and modern IT infrastructures, principles, architecture, and associated risk analysis methods and techniques to evaluate, develop and implement security strategies that align with business goals.

You do not need to respond separately to these competencies/KSAs. Your resume will serve as responses to the competencies/KSAs.

Applicants must provide details of the duties performed as they relate to the qualifying experience and competencies/KSAs. Experience must be explicitly stated in the resume as experience not specifically described in the resume cannot be assumed. Resumes that are vague or don't address specific requirements will not receive maximum consideration.


You may preview questions for this vacancy.

Federal Deposit Insurance Corporation

At the FDIC, we work diligently to ensure financial safety for depositors across America. Since FDIC insurance began in 1934, not a single depositor has lost a cent of insured funds as a result of a failure. It takes many different skills to accomplish the vital mission of the FDIC. Find out where you fit in at the FDIC. Join the FDIC Team

Agency contact information

Chiquita Evans
Phone
571-438-3980
Email
chevans@fdic.gov
Address
Federal Deposit Insurance Corporation
FDIC Human Resources Branch
3501 Fairfax Drive
HRB (PA-1730-5007)
Arlington, Virginia 22226
United States

Your session is about to expire!

Your USAJOBS session will expire due to inactivity in 8 minutes. Any unsaved data will be lost if you allow the session to expire. Click the button below to continue your session.