Jobs › Maryland › Washington, DC › Chief Information Security Officer
Chief Information Security Officer
Federal Emergency Management Agency is hiring for the job of Chief Information Security Officer, Washington, District of Columbia (On-site). This is a Cybersecurity job in the governance, risk, and compliance field, with a posted range of $151661 - $228000 Per Year. Review the full details below and apply directly with Federal Emergency Management Agency.
This Senior Executive Service position is in the Department of Homeland Security (DHS), Federal Emergency Management Agency (FEMA), Office of the Chief Information Officer, located in Washington, D.C. The Chief Information Security Officer is responsible for the information security requirements of the Agency by ensuring confidentiality, integrity, and availability of systems, networks, and data.
Qualifications: Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution. Candidates will not be hired based on their race, sex, color, religion, or national origin. To meet the minimum qualification requirements for this position, you must show that you possess the Executive Core Qualifications (ECQ) and Technical Qualifications (TQ) related to this position within your resume - NOT TO EXCEED 2 PAGES. Resumes over the 2-page limit, will not be reviewed beyond page 2 or may be disqualified. Your resume should include examples of experience, education, and accomplishments applicable to the qualification(s). If your resume does not reflect demonstrated evidence of these qualifications, you may not receive consideration for the position. TECHNICAL QUALIFICATIONS (TQs): Your resume should demonstrate accomplishments that would satisfy the technical qualifications. TQ 1: Enterprise Cybersecurity Strategy and Risk Management: Demonstrated experience developing, implementing, and leading an enterprise cybersecurity strategy and risk management program within a large, complex, or federated organization. This includes establishing cybersecurity governance, policies, standards, performance measures, and risk management processes; aligning security initiatives and investments with mission priorities and federal mandates; modernizing enterprise cybersecurity through approaches such as Zero Trust, secure cloud adoption, dynamic testing for continuous monitoring and assessment, and risk-based vulnerability management; overseeing system authorization; managing significant cybersecurity budgets, programs, contracts, and workforce requirements; and advising senior executives on cyber risk, resource tradeoffs, and enterprise security posture. TQ 2: Cyber Operations, Incident Response, and Resilience: Extensive experience leading cybersecurity operations in large, complex environments, including management or oversight of a security operations center; incident detection, analysis, response, recovery, and reporting; coordination of response and mitigation activities during significant cyber incidents and emerging threats; and integration of technical, operational, and executive stakeholders to strengthen operational resilience, continuity of operations, and organizational readiness. EXECUTIVE CORE QUALIFICATIONS (ECQs): In addition to the Technical Qualification Requirements listed above, all new entrants into the Senior Executive Service (SES) under a career appointment will be assessed for executive competency against the following five mandatory ECQs. If your 2-page resume does not reflect demonstrated evidence of the ECQs and TQs, you may not receive further consideration for the position. There are five ECQs: ECQ 1: Commitment to the Rule of Law and the Principles of the American Founding - This core qualification requires a demonstrated knowledge of the American system of government, commitment to uphold the Constitution and the rule of law, and commitment to serve the American people. ECQ 2: Driving Efficiency - This core qualification involves the demonstrated ability to strategically and efficiently manage resources, budget effectively, cut wasteful spending, and pursue efficiency through process and technological upgrades. ECQ 3: Merit and Competence - This core qualification involves the demonstrated knowledge, ability and technical competence to effectively and reliably produce work that is of exceptional quality. ECQ 4: Leading People - This core qualification involves the demonstrated ability to lead and inspire a group toward meeting the organization's vision, mission, and goals, and to drive a high-performance, high-accountability culture. This includes, when necessary, the ability to lead people through change and to hold individuals accountable. ECQ 5: Achieving Results - This core qualification involves the demonstrated ability to achieve both individual and organizational results, and to align results to stated goals from superiors. Note: If you are a member of the SES or have been certified through successful participation in an OPM approved SES Candidate Development Program (SESCDP), or have SES reinstatement eligibility, you do not need to address the (5) ECQs in your resume. In lieu of, you MUST attach proof (e.g., SF-50, Certification by OPM's SES Qualifications Review Board (QRB)) of your eligibility for noncompetitive appointment to the SES.
Location and market context
This job is based in Washington on-site. Local candidates benefit from being close to Federal Emergency Management Agency's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About cybersecurity governance jobs
Cybersecurity governance connects security control frameworks to business and regulatory risk, covering policy, risk assessment, and control assurance rather than hands-on operations. Jobs like this one are typically evaluated against frameworks such as NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices.
How to position yourself for this cybersecurity governance job
Strong candidates emphasize security control frameworks, risk assessment, policy and standards, and translating technical security posture into governance and board-level reporting. In your resume and outreach, tie your experience to how Federal Emergency Management Agency would apply NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
- IT Cybersecurity Specialist (Applications Software/SYSADMIN) · U.S. Coast Guard · Washington, District of Columbia
- Computer Engineer (Cybersecurity) · Bureau of Industry and Security · Washington, District of Columbia
- IT CYBERSECURITY SPECIALIST (INFOSEC) · Department of the Air Force Headquarters · Lackland AFB, Texas
- Deputy Chief Information Security Officer · Office of the Secretary of Defense · Pentagon, Arlington, Virginia
- Chief Information Security Officer · Office of the Secretary of the Interior · Multiple Locations
- Lead IT Cybersecurity Specialist · Centers for Disease Control and Prevention · Atlanta, Georgia
- Cybersecurity Specialist · Railroad Retirement Board · Chicago, Illinois
- IT CYBERSECURITY SPECIALIST (INFOSEC) · Defense Information Systems Agency · Arlington, Virginia
More GRC jobs in Washington
- Information Technology Specialist, (Information Technology Security and Audit Compliance) · Bureau of Prisons/Federal Prison System · Washington, District of Columbia
- Governance, Risk & Compliance (GRC) Lead, Federal · Peregrine Technologies · Washington, D.C.
- SAP Data Governance Manager · Accenture Federal Services · Washington, DC
- Internal Controls Auditor · Consumer Product Safety Commission · Washington, District of Columbia
- Records and Information Management Specialist · Commodity Futures Trading Commission · Washington, District of Columbia
- Auditor (Pathways Recent Graduate) · National Labor Relations Board · Washington, District of Columbia
Hiring for Cybersecurity?
Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Want to be next in a job like this?
Jobs like Chief Information Security Officer in Washington, District of Columbia open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.