Chief Information Security Officer AD-2210-00 (Senior Manager) FPL AD-00
Apply
Position ID:
FSA-26-13067489
City:
Multiple Locations
Date Posted:
2026-09-28
Expiration Time:
2026-10-13
Job Type:
Job Category:
Information Technology Management
Salary:
179436 - 209600 PA
Job Summary
This position is in the U.S. Department of Education (ED), Federal Student Aid (FSA), Technology Operations Division (TOD). The Technology Operations Division provides information technology operations services for all FSA systems, promoting the effective and secure use of technology to achieve FSA's strategic objectives through sound planning, investments, integrated technology architectures and standards, effective systems development, production support, and cybersecurity services.
Job Description
Minimum Qualification Requirements You may meet the minimum qualifications for the AD-00 (Senior Manager), if you possess the specialize experience, education, or a combination of the two. Specialized Experience for the AD-00-(GS-15 equivalent) One year of experience in either federal or non-federal service that is equivalent to at least a AD-00 (GS-14 equivalent) performing two (2) out of three (3) of the following duties or work assignments: 1. Experience leading enterprise-wide information security programs, including strategic planning, policy development, and advising on security risks, resources, and mission requirements aligned with Federal or industry standards and mandates (e.g., FISMA, OMB A-130, NIST). 2.Experience directing and advising on enterprise risk management, security authorizations, and secure IT acquisitions compliance with security regulations, including applying RMF and SCRM to assess and mitigate risks across various IT, cloud, and vendor environments. 3. Experience providing strategic leadership and oversight of enterprise SOC and incident management programs containing critical cyber threats, including develop critical threat response, mitigation, incident response, and required reporting procedures. Basic Experience Requirements Example (Supervisory IT Positions ): Applicants may qualify by meeting or exceeding the minimum proficiency level established for each of the required competencies, in addition to meeting the specialized experience requirement as demonstrated through the assessment of skills. You must possess IT-related experience (paid or unpaid experience and/or completion of specific, intensive training (e.g., IT certification), as appropriate) demonstrating each of the ten competencies listed below. Accountability-Holds self and others accountable for measurable high-quality, timely, and cost-effective results. Determines objectives, sets priorities, and delegates work. Accepts responsibility for mistakes. Complies with established control systems and rules. 2. Customer Service- Anticipates and meets the needs of both internal and external customers. Delivers high-quality products and services; is committed to continuous improvement. 3. Decisiveness- Makes well-informed, effective, and timely decisions, even when data are limited or solutions produce unpleasant consequences; perceives the impact and implications of decisions. 4. Flexibility- Is open to change and new information; rapidly adapts to new information, changing conditions, or unexpected obstacles. 5. Integrity/Honesty- Behaves in an honest, fair, and ethical manner. Shows consistency in words and actions. Models high standards of ethics. 6. Interpersonal Skills- Treats others with courtesy, sensitivity, and respect. Considers and responds appropriately to the needs and feelings of different people in different situations. 7. Oral Communication- Makes clear and convincing oral presentations. Listens effectively; clarifies information as needed. 8. Problem Solving- Identifies and analyzes problems; weighs relevance and accuracy of information; generates and evaluates alternative solutions; makes recommendations. 9. Resilience- Deals effectively with pressure; remains optimistic and persistent, even under adversity. Recovers quickly from setbacks. 10. Written Communication- Writes in a clear, concise, organized, and convincing manner for the intended audience. Applicants may qualify by meeting or exceeding the minimum proficiency level established for each of the required competencies, in addition to meeting the specialized experience requirement as demonstrated through the assessment of skills. You must possess IT-related experience (paid or unpaid experience and/or completion of specific, intensive training (e.g., IT certification), as appropriate) demonstrating each of the seventeen competencies listed below. Knowledge, Skills, and Abilities (KSAs) The quality of your experience will be measured by the extent to which you possess the following knowledge, skills and abilities (KSAs). You do not need to provide separate narrative responses to these KSAs, as they will be measured by your responses to the occupational questionnaire (you may preview the occupational questionnaire by clicking the link at the end of the Evaluations section of this vacancy announcement). 1. Knowledge of cybersecurity laws, regulations, and standards-including the Federal Information Security Modernization Act (FISMA), NIST Risk Management Framework (RMF), OMB mandates, and Authorizing Official (AO) responsibilities-to manage enterprise cyber risk and maintain Authority to Operate (ATO) across mission-critical systems. 2. Skill in directing operational cybersecurity functions, Security Operations Center (SOC) technologies (such as SIEM, network forensics, and packet capture), and incident response frameworks to detect advanced threats, mitigate vulnerabilities, and protect Personally Identifiable Information (PII) and High-Value Assets (HVAs). 3. Ability to oversee Continuous Diagnostics and Mitigation (CDM) and Information Security Continuous Monitoring (ISCM) programs, integrate security across system development lifecycles (SDLC/LMM), and enforce strict cybersecurity requirements across large-scale contractor, cloud hosting, and external partner ecosystems. 4. Skill in leading multidisciplinary technical teams, managing contractor deliverables and IT security budgets, and building strategic partnerships with executives, external oversight authorities, and audit entities (e.g., OIG, DHS, FISMA auditors) to remediate findings and achieve organizational goals.