Apply with hirly
Chief Information Security Officer
Federal Emergency Management Agency · Washington, District of Columbia, United States
Upload your resume to see how well you match this job — free, in seconds, no account needed.
Your resume is used only to score it against this job. If you don't create an account, it is deleted within 24 hours.
Summary This Senior Executive Service position is in the Department of Homeland Security (DHS), Federal Emergency Management Agency (FEMA), Office of the Chief Information Officer, located in Washington, D.C. The Chief Information Security Officer is responsible for the information security requirements of the Agency by ensuring confidentiality, integrity, and availability of systems, networks, and data. Duties The Chief Information Security Officer (CISO) is responsible for performing and supervising work that involves applying analytical processes to the planning, design, and implementation of new and improved information systems to meet the mission requirements of the Agency's lines of business and administrative programs and safeguards systems from cyber threats in accordance with federal laws and regulations. This role executes the planning and delivery of secure, high-quality enterprise application services for FEMA personnel and stakeholders. In addition, the CISO, provides the security architectural planning and delivery of information technology (IT) services across the enterprise and in support of FEMA program offices and regions. FEMA operates extensive IT capabilities (day-to-day, emergency, fixed, and mobile) including its own switched telecommunications and data networks, satellite systems, wireless systems, and complex automated applications integral to FEMA program missions. FEMA's IT capabilities are intra/inter-agency and inter-governmental in scope but are managed under the leadership of the CIO. Primary Duties: Serves as the Senior Advisor to the CIO regarding development, publication, and implementation of Agency cybersecurity (information security) policies, standards, and guidance, as well as coordination, integration, training, and enforcement of all aspects of the Agency's cybersecurity program, consistent with guidance and direction from the U.S. Department of Homeland Security and in compliance with applicable laws, regulations, directives, and standards. Leads the Agency's implementation of all applicable regulatory requirements including the Computer Security Act, Federal Information Technology Acquisition Reform ACT (FITARA), Federal Information Security Management Act (FISMA), the Clinger-Cohen Act, relevant Office of Management and Budget (OMB) circulars and memoranda, Executive Orders, and Presidential Directives, as well as Congressional direction. Demonstrates leadership in guiding FEMA's cybersecurity program and informing Agency-wide information technology acquisitions. The incumbent provides daily management and oversight of the Office of the Chief Information Security Officer and its Division(s). Responsible for planning and implementing the Agency-wide cybersecurity enhancement initiatives, following all applicable laws, directives, policies, and directed actions and providing methodologies, tools, guidance, and subject-matter expertise to help ensure FEMA's cybersecurity programs can meet federal compliance and reporting requirements. The incumbent is also responsible for a balanced, robust, and secure information environment for FEMA systems. Responsible for planning and implementing the Agency-wide cybersecurity enhancement initiatives, following all applicable laws, directives, policies, and directed actions and providing methodologies, tools, guidance, and subject-matter expertise to help ensure FEMA's cybersecurity programs can meet federal compliance and reporting requirements. The incumbent is also responsible for a balanced, robust, and secure information environment for FEMA systems. Effectively develops and communicates the cybersecurity strategy throughout the Agency and drives the implementation of the Agency's strategic information security management plan, including coordination with stakeholders in FEMA directorates, offices, and regions. Utilizes a full range of strategic management and leadership skills and understands, explains, and presents complex technical ideas to both technical and non-technical audiences at all levels up to the highest in a persuasive and convincing manner. Exercises broad and deep IT knowledge coupled with equivalent knowledge of the activities of those organizations that use and exploit IT. Communicates the potential impact of emerging security technologies on organizations as well as individuals and analyzes the risks of using or not using such technologies. Assesses the impact of legislation and actively promotes cybersecurity compliance. Takes the initiative to keep both his/her own and subordinates' skills current and maintains an awareness of developments in cybersecurity and other IT-related disciplines. Responsible for program management, organizational change, coordination, communication, policy, and oversight. Provides planning guidance for cybersecurity priorities within the Agency to all designated IT personnel, including System Owners, Information System Security Officers, and Information System Security Managers throughout the Agency, to ensure a common, comprehensive approach to securing information and IT systems and applications used to support FEMA goals and objectives. Qualifications Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution. Candidates will not be hired based on their race, sex, color, religion, or national origin. To meet the minimum qualification requirements for this position, you must show that you possess the Executive Core Qualifications (ECQ) and Technical Qualifications (TQ) related to this position within your resume -
Not to Exceed
2 PAGES. Resumes over the 2-page limit, will not be reviewed beyond page 2 or may be disqualified. Your resume should include examples of experience, education, and accomplishments applicable to the qualification(s). If your resume does not reflect demonstrated evidence of these qualifications, you may not receive consideration for the position.
Technical Qualifications
(TQs): Your resume should demonstrate accomplishments that would satisfy the technical qualifications. TQ 1: Enterprise Cybersecurity Strategy and Risk Management: Demonstrated experience developing, implementing, and leading an enterprise cybersecurity strategy and risk management program within a large, complex, or federated organization. This includes establishing cybersecurity governance, policies, standards, performance measures, and risk management processes; aligning security initiatives and investments with mission priorities and federal mandates; modernizing enterprise cybersecurity through approaches such as Zero Trust, secure cloud adoption, dynamic testing for continuous monitoring and assessment, and risk-based vulnerability management; overseeing system authorization; managing significant cybersecurity budgets, programs, contracts, and workforce requirements; and advising senior executives on cyber risk, resource tradeoffs, and enterprise security posture. TQ 2: Cyber Operations, Incident Response, and Resilience: Extensive experience leading cybersecurity operations in large, complex environments, including management or oversight of a security operations center; incident detection, analysis, response, recovery, and reporting; coordination of response and mitigation activities during significant cyber incidents and emerging threats; and integration of technical, operational, and executive stakeholders to strengthen operational resilience, continuity of operations, and organizational readiness.
Executive Core Qualifications
(ECQs): In addition to the Technical Qualification Requirements listed above, all new entrants into the Senior Executive Service (SES) under a career appointment will be assessed for executive competency against the following five mandatory ECQs. If your 2-page resume does not reflect demonstrated evidence of the ECQs and TQs, you ma