GRC Careers: AI Governance, Risk and Compliance JobsConnecting Talent and Trust. Post a Job Log in

JobsMarylandWashington, DCChief Information Security Officer

Chief Information Security Officer

Federal Emergency Management Agency
CybersecurityOn-siteFull-timeWashington, District of Columbia$151661 - $228000 Per Year

Federal Emergency Management Agency is hiring for the job of Chief Information Security Officer, Washington, District of Columbia (On-site). This is a Cybersecurity job in the governance, risk, and compliance field, with a posted range of $151661 - $228000 Per Year. Review the full details below and apply directly with Federal Emergency Management Agency.

Organization: Federal Emergency Management AgencyLocation: Washington, District of ColumbiaWorkplace: On-siteFocus: CybersecuritySalary: $151661 - $228000 Per YearPosted: Sep 21, 2026
Federal Emergency Management Agency is hiring for this Cybersecurity job in Washington, one of the metros GRC Careers tracks for governance, risk, and compliance hiring. See other GRC jobs in Washington →

This Senior Executive Service position is in the Department of Homeland Security (DHS), Federal Emergency Management Agency (FEMA), Office of the Chief Information Officer, located in Washington, D.C. The Chief Information Security Officer is responsible for the information security requirements of the Agency by ensuring confidentiality, integrity, and availability of systems, networks, and data.

Qualifications: Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution. Candidates will not be hired based on their race, sex, color, religion, or national origin. To meet the minimum qualification requirements for this position, you must show that you possess the Executive Core Qualifications (ECQ) and Technical Qualifications (TQ) related to this position within your resume - NOT TO EXCEED 2 PAGES. Resumes over the 2-page limit, will not be reviewed beyond page 2 or may be disqualified. Your resume should include examples of experience, education, and accomplishments applicable to the qualification(s). If your resume does not reflect demonstrated evidence of these qualifications, you may not receive consideration for the position. TECHNICAL QUALIFICATIONS (TQs): Your resume should demonstrate accomplishments that would satisfy the technical qualifications. TQ 1: Enterprise Cybersecurity Strategy and Risk Management: Demonstrated experience developing, implementing, and leading an enterprise cybersecurity strategy and risk management program within a large, complex, or federated organization. This includes establishing cybersecurity governance, policies, standards, performance measures, and risk management processes; aligning security initiatives and investments with mission priorities and federal mandates; modernizing enterprise cybersecurity through approaches such as Zero Trust, secure cloud adoption, dynamic testing for continuous monitoring and assessment, and risk-based vulnerability management; overseeing system authorization; managing significant cybersecurity budgets, programs, contracts, and workforce requirements; and advising senior executives on cyber risk, resource tradeoffs, and enterprise security posture. TQ 2: Cyber Operations, Incident Response, and Resilience: Extensive experience leading cybersecurity operations in large, complex environments, including management or oversight of a security operations center; incident detection, analysis, response, recovery, and reporting; coordination of response and mitigation activities during significant cyber incidents and emerging threats; and integration of technical, operational, and executive stakeholders to strengthen operational resilience, continuity of operations, and organizational readiness. EXECUTIVE CORE QUALIFICATIONS (ECQs): In addition to the Technical Qualification Requirements listed above, all new entrants into the Senior Executive Service (SES) under a career appointment will be assessed for executive competency against the following five mandatory ECQs. If your 2-page resume does not reflect demonstrated evidence of the ECQs and TQs, you may not receive further consideration for the position. There are five ECQs: ECQ 1: Commitment to the Rule of Law and the Principles of the American Founding - This core qualification requires a demonstrated knowledge of the American system of government, commitment to uphold the Constitution and the rule of law, and commitment to serve the American people. ECQ 2: Driving Efficiency - This core qualification involves the demonstrated ability to strategically and efficiently manage resources, budget effectively, cut wasteful spending, and pursue efficiency through process and technological upgrades. ECQ 3: Merit and Competence - This core qualification involves the demonstrated knowledge, ability and technical competence to effectively and reliably produce work that is of exceptional quality. ECQ 4: Leading People - This core qualification involves the demonstrated ability to lead and inspire a group toward meeting the organization's vision, mission, and goals, and to drive a high-performance, high-accountability culture. This includes, when necessary, the ability to lead people through change and to hold individuals accountable. ECQ 5: Achieving Results - This core qualification involves the demonstrated ability to achieve both individual and organizational results, and to align results to stated goals from superiors. Note: If you are a member of the SES or have been certified through successful participation in an OPM approved SES Candidate Development Program (SESCDP), or have SES reinstatement eligibility, you do not need to address the (5) ECQs in your resume. In lieu of, you MUST attach proof (e.g., SF-50, Certification by OPM's SES Qualifications Review Board (QRB)) of your eligibility for noncompetitive appointment to the SES.

Location and market context

This job is based in Washington on-site. Local candidates benefit from being close to Federal Emergency Management Agency's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.

About cybersecurity governance jobs

Cybersecurity governance connects security control frameworks to business and regulatory risk, covering policy, risk assessment, and control assurance rather than hands-on operations. Jobs like this one are typically evaluated against frameworks such as NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices.

How to position yourself for this cybersecurity governance job

Strong candidates emphasize security control frameworks, risk assessment, policy and standards, and translating technical security posture into governance and board-level reporting. In your resume and outreach, tie your experience to how Federal Emergency Management Agency would apply NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices, and lead with concrete outcomes rather than duties.

Similar GRC jobs

More GRC jobs in Washington

Hiring for Cybersecurity?

Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.

Post a job  Pricing from $99 · About GRC Careers · Hiring toolkit

Want to be next in a job like this?

Jobs like Chief Information Security Officer in Washington, District of Columbia open regularly. Be first to know, privately. No current employer ever sees you looking.

New Cybersecurity jobs, the moment they post.

One click unsubscribe.
Know your GRC? Take the 2-minute AI Governance Challenge. No signup needed.
Play now →

Employer, or see something wrong with this posting? Report this posting and we will review it promptly.