F

Chief Information Security Officer

Federal Emergency Management Agency · Washington, District of Columbia

$152k–$228kPosted pay
On-siteWorkplace
1d agoPosted · Sep 21
USAJOBSSource
$146ksecurity engineer median

Skills in this posting

The posting

The Chief Information Security Officer (CISO) is responsible for performing and supervising work that involves applying analytical processes to the planning, design, and implementation of new and improved information systems to meet the mission requirements of the Agency's lines of business and administrative programs and safeguards systems from cyber threats in accordance with federal laws and regulations.

This role executes the planning and delivery of secure, high-quality enterprise application services for FEMA personnel and stakeholders. In addition, the CISO, provides the security architectural planning and delivery of information technology (IT) services across the enterprise and in support of FEMA program offices and regions.

FEMA operates extensive IT capabilities (day-to-day, emergency, fixed, and mobile) including its own switched telecommunications and data networks, satellite systems, wireless systems, and complex automated applications integral to FEMA program missions.

FEMA's IT capabilities are intra/inter-agency and inter-governmental in scope but are managed under the leadership of the CIO.

Primary Duties: Serves as the Senior Advisor to the CIO regarding development, publication, and implementation of Agency cybersecurity (information security) policies, standards, and guidance, as well as coordination, integration, training, and enforcement of all aspects of the Agency's cybersecurity program, consistent with guidance and direction from the U.S.

Department of Homeland Security and in compliance with applicable laws, regulations, directives, and standards.

Leads the Agency's implementation of all applicable regulatory requirements including the Computer Security Act, Federal Information Technology Acquisition Reform ACT (FITARA), Federal Information Security Management Act (FISMA), the Clinger-Cohen Act, relevant Office of Management and Budget (OMB) circulars and memoranda, Executive Orders, and Presidential Directives, as well as Congressional direction.

Demonstrates leadership in guiding FEMA's cybersecurity program and informing Agency-wide information technology acquisitions. The incumbent provides daily management and oversight of the Office of the Chief Information Security Officer and its Division(s).

Responsible for planning and implementing the Agency-wide cybersecurity enhancement initiatives, following all applicable laws, directives, policies, and directed actions and providing methodologies, tools, guidance, and subject-matter expertise to help ensure FEMA's cybersecurity programs can meet federal compliance and reporting requirements.

The incumbent is also responsible for a balanced, robust, and secure information environment for FEMA systems.

Responsible for planning and implementing the Agency-wide cybersecurity enhancement initiatives, following all applicable laws, directives, policies, and directed actions and providing methodologies, tools, guidance, and subject-matter expertise to help ensure FEMA's cybersecurity programs can meet federal compliance and reporting requirements.

The incumbent is also responsible for a balanced, robust, and secure information environment for FEMA systems.

Effectively develops and communicates the cybersecurity strategy throughout the Agency and drives the implementation of the Agency's strategic information security management plan, including coordination with stakeholders in FEMA directorates, offices, and regions.

Utilizes a full range of strategic management and leadership skills and understands, explains, and presents complex technical ideas to both technical and non-technical audiences at all levels up to the highest in a persuasive and convincing manner.

Exercises broad and deep IT knowledge coupled with equivalent knowledge of the activities of those organizations that use and exploit IT. Communicates the potential impact of emerging security technologies on organizations as well as individuals and analyzes the risks of using or not using such technologies.

Assesses the impact of legislation and actively promotes cybersecurity compliance. Takes the initiative to keep both his/her own and subordinates' skills current and maintains an awareness of developments in cybersecurity and other IT-related disciplines.

Responsible for program management, organizational change, coordination, communication, policy, and oversight.

Provides planning guidance for cybersecurity priorities within the Agency to all designated IT personnel, including System Owners, Information System Security Officers, and Information System Security Managers throughout the Agency, to ensure a common, comprehensive approach to securing information and IT systems and applications used to support FEMA goals and objectives.

Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution. Candidates will not be hired based on their race, sex, color, religion, or national origin.

To meet the minimum qualification requirements for this position, you must show that you possess the Executive Core Qualifications (ECQ) and Technical Qualifications (TQ) related to this position within your resume - NOT TO EXCEED 2 PAGES. Resumes over the 2-page limit, will not be reviewed beyond page 2 or may be disqualified.

Your resume should include examples of experience, education, and accomplishments applicable to the qualification(s). If your resume does not reflect demonstrated evidence of these qualifications, you may not receive consideration for the position.

TECHNICAL QUALIFICATIONS (TQs): Your resume should demonstrate accomplishments that would satisfy the technical qualifications.

TQ 1: Enterprise Cybersecurity Strategy and Risk Management: Demonstrated experience developing, implementing, and leading an enterprise cybersecurity strategy and risk management program within a large, complex, or federated organization.

This includes establishing cybersecurity governance, policies, standards, performance measures, and risk management processes; aligning security initiatives and investments with mission priorities and federal mandates; modernizing enterprise cybersecurity through approaches such as Zero Trust, secure cloud adoption, dynamic testing for continuous monitoring and assessment, and risk-based vulnerability management; overseeing system authorization; managing significant cybersecurity budgets, programs, contracts, and workforce requirements; and advising senior executives on cyber risk, resource tradeoffs, and enterprise security posture.

TQ 2: Cyber Operations, Incident Response, and Resilience: Extensive experience leading cybersecurity operations in large, complex environments, including management or oversight of a security operations center; incident detection, analysis, response, recovery, and reporting; coordination of response and mitigation activities during significant cyber incidents and emerging threats; and integration of technical, operational, and executive stakeholders to strengthen operational resilience, continuity of operations, and organizational readiness.

EXECUTIVE CORE QUALIFICATIONS (ECQs): In addition to the Technical Qualification Requirements listed above, all new entrants into the Senior Executive Service (SES) under a career appointment will be assessed for executive competency against the following five mandatory ECQs.

If your 2-page resume does not reflect demonstrated evidence of the ECQs and TQs, you may not receive further consideration for the position.

There are five ECQs: ECQ 1: Commitment to the Rule of Law and the Principles of the American Founding - This core qualification requires a demonstrated knowledge of the American system of government, commitment to uphold the Constitution and the rule of law, and commitment to serve the American people.

ECQ 2: Driving Efficiency - This core qualification involves the demonstrated ability to strategically and efficiently manage resources, budget effectively, cut wasteful spending, and pursue efficiency through process and technological upgrades.

ECQ 3: Merit and Competence - This core qualification involves the demonstrated knowledge, ability and technical competence to effectively and reliably produce work that is of exceptional quality.

ECQ 4: Leading People - This core qualification involves the demonstrated ability to lead and inspire a group toward meeting the organization's vision, mission, and goals, and to drive a high-performance, high-accountability culture. This includes, when necessary, the ability to lead people through change and to hold individuals accountable.

ECQ 5: Achieving Results - This core qualification involves the demonstrated ability to achieve both individual and organizational results, and to align results to stated goals from superiors.

Note: If you are a member of the SES or have been certified through successful participation in an OPM approved SES Candidate Development Program (SESCDP), or have SES reinstatement eligibility, you do not need to address the (5) ECQs in your resume.

In lieu of, you MUST attach proof (e.g., SF-50, Certification by OPM's SES Qualifications Review Board (QRB)) of your eligibility for noncompetitive appointment to the SES.

The PivotHop read

Where these skills also reach

More security engineer roles

Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.

© 2026 PivotHopReal data, real career moves