Independent job-search site. Not affiliated with the U.S. government. Applications happen on the official USAJOBS.gov. Learn more
Home/Jobs/Chief Information Security Officer (Cybersecurity)
Announcement #880328600

Chief Information Security Officer (Cybersecurity)

Government Accountability Office · Washington, District of Columbia
InternalTelework eligible

What you'd do

This position is located in the Government Accountability Office. As a Chief Information Security Officer (CISO) you will be responsible for the planning, governance, and coordination of all cybersecurity initiatives across GAO. The incumbent represents GAO in external forums to ensure a clear vision and message on GAO Initiatives and federal programs to help identify and address priority needs for cybersecurity risk management.

Major duties

As a Chief Information Security Officer , ES, 2210, 00, your typical work assignments may include the following: Provides executive oversight and strategic direction on Information Security and makes GAO aware of risks and vulnerabilities not yet enumerated by GAO during the normal course of operating its systems and enables the agency to enhance its security posture. The CISO is a senior leadership position that is responsible for integration of all internal agency information security activities. Identifies, creates, implements and evaluates all GAO programs to ensure concurrence with federal Cybersecurity laws and regulations to include being the strategic and tactical leader for data, policy, and technology products. Provides subject matter expertise to GAO Executive Committee and mission teams on cyber related matters and manages IT incident response procedures. Oversees and recommends a comprehensive, state-of-the-art program to assess whether GAO has implemented an adequate and effective cybersecurity program and partnerships have been established to protect agency information technology (IT) systems and critical infrastructure from cyber threats and vulnerabilities. Oversees timely, impactful, and innovative cybersecurity and IT audits of data and systems maintained by or on behalf of GAO and its Operating Divisions. Analyzes and facilitates the sharing of timely, reliable, and actionable information regarding cybersecurity threats, vulnerabilities, incidents, and responses with a view toward protecting against those risks, mitigating damage from incidents, and limiting contagion across systems, and networks. Develops and mentors staff through onboarding, open communication, training and development opportunities and performance management processes. Builds and maintains a highly motivated, responsive, and proactive workforce possessing required competencies. Fosters a diverse and inclusive workplace.

What you need to qualify

Minimum Qualifications: The Senior Executive Service (SES) appointments require one year (52 weeks) of specialized experience at the next lower band/grade at the GS-14/GS-15 level, PE band level III, PT band levels III and IV, MS band levels I and II, Senior Executive Service, Senior Level (SL), or equivalent in the Federal Service, or comparable private/public sector. Executive Core Qualifications (ECQs): The ECQs assess executive experience and potential. They measure whether you have the executive skills needed to succeed in a variety of Senior Executive Service positions. ECQs can be submitted outside of the resume as additional documentation. Please address the following ECQs listed below. *NOTE*: For current SES applicants or applicants who have previously held an SES appointment, ECQs can be resume based. For applicants who has not held a previous SES appointment ECQ's are required (essay-based) responses for each ECQ is required to submitted as additional documentation outside of the resume. Leading Change: This core qualification involves the ability to bring about strategic change, both within and outside the organization, to meet organizational goals. Inherent to this ECQ is the ability to establish an organizational vision and to implement it in a continuously changing environment. Leading People: This core qualification involves the ability to lead people toward meeting the organizations vision, mission, and goals. Inherent to this ECQ is the ability to provide an inclusive workplace that fosters the development of others, facilitates cooperation and teamwork, and supports constructive resolution of conflicts. Results Driven: This core qualification involves the ability to meet organizational goals and customer expectations. Inherent to this ECQ is the ability to make decisions that produce high quality results by applying technical knowledge, analyzing problems, and calculating risks. Business Acumen: This core qualification involves the ability to manage human, financial, and information resources strategically. Building Coalitions: This core qualification involves the ability to build coalitions internally and with other federal agencies, state and local governments, nonprofit and private sector organizations, foreign governments, or international organizations to achieve common goals. Technical Qualifications: All applicants must meet the Technical Qualifications and Executive Core Qualification requirements listed above to be eligible for consideration. Eligibility will be based on a clear demonstration that the applicants training, and experience are of the scope, quality, and level of responsibility sufficient to successfully perform the duties and responsibilities of this executive position. TQ-1 Knowledge of IT security theories and concepts, practices, and emerging issues; and IT Security and concepts sufficient to oversee the efficient and effective lifecycle management of agency-wide enterprise information security services and solutions while ensuring value in transforming, re-engineering, and/or supporting mission operations and service delivery. TQ-2 Ability to secure the cooperation of others at all levels to accomplish requirements in the face of frequently conflicting and often controversial program goals. Successful performance requires an executive with the highest talent, supervisory ability, organizational skills and depth and breadth in IT Infrastructure operations management. TQ-3 Ability in the management and utilization of the personnel within the Office and to integrate the management of GAO and operating contractors in directing programs or isolating problems affecting progress and coordination of IT programs, and for arriving at workable solutions to a variety of complex and interrelated problems. TQ-4 Ability to interpret broad and complex IT policy and procedures, both to and from higher authority and to succinctly present requirements, orally and in writing. TQ-5 Knowledge of related regulations, laws, and orders (e.g. Clinger-Cohen Act, Performance and Results Act, IT related Presidential Directive/Executive Orders, and the Federal Information Security Management Act). Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic; religious; spiritual; community, student, social). Volunteer work helps build critical competencies, knowledge, and skills and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.

Before you apply

Federal applications are different: your resume should be 3–5 pages and mirror the language of this announcement. Read our federal resume guide first — it's the #1 reason qualified people get screened out.

Don't miss the next one.

Get an email the moment a similar federal job opens — postings can close in as little as 5 days.

Free forever. One click to unsubscribe.