GRC Careers: AI Governance, Risk and Compliance JobsGovernance · Risk · Compliance Careers

Jobs › Virginia › Washington, DC › Foreign Investment Risk Compliance Monitoring Program Lead

Foreign Investment Risk Compliance Monitoring Program Lead

Cybersecurity and Infrastructure Security Agency
RiskOn-siteFull-timeArlington, Virginia$121785 - $187093 Per Year

Cybersecurity and Infrastructure Security Agency is hiring for the job of Foreign Investment Risk Compliance Monitoring Program Lead, Arlington, Virginia (On-site). This is a Risk job in the governance, risk, and compliance field, with a posted range of $121785 - $187093 Per Year. Review the full details below and apply directly with Cybersecurity and Infrastructure Security Agency.

Organization: Cybersecurity and Infrastructure Security AgencyLocation: Arlington, VirginiaWorkplace: On-siteFocus: RiskSalary: $121785 - $187093 Per YearPosted: Oct 2, 2026
Cybersecurity and Infrastructure Security Agency is hiring for this Risk job in Arlington, one of the metros GRC Careers tracks for governance, risk, and compliance hiring. See other GRC jobs in Arlington →

This announcement is issued under the Direct Hire Authority (DHA) to recruit for positions for which there is a critical hiring need. Selectee(s) will receive a career or career-conditional appointment in the competitive service and may be required to serve a one year probationary period. The official title of this position is Information Technology Cybersecurity Specialist, GS-2210-13/14.

Qualifications: Do NOT copy and paste the duties, specialized experience, or occupational assessment questionnaire from this announcement into your resume as that will not be considered a demonstration of your qualifications for this position. Your resume must describe your work and experience, in your own words. To be considered minimally qualified for this position, you must demonstrate that you have the required proficiency level of competencies and experience for the respective grade level in which you are applying. COMPETENCY REQUIREMENT: Experience must be Information Technology (IT)-related; the experience may be demonstrated by paid or unpaid experience and/or completion of specific, intensive training (for example, IT certification), as appropriate. You must have IT-related experience demonstrating each of the required competencies listed below and must meet or exceed the minimum proficiency level established for each by grade level. For more information, see Competency-Based Qualification Standard for the Information Technology Management Series, 2210. You qualify at the GS-GS-13 and GS-14, if you have the following competencies: Attention to Detail - Is thorough when performing work and conscientious about attending to detail. (Minimum Proficiency Level: 4) Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. (Minimum Proficiency Level: 4) Decision Making - Makes sound, well-informed, and objective decisions; perceives the impact and implications of decisions; commits to action, even in uncertain situations, to accomplish organizational goals; causes change. (Minimum Proficiency Level: 3) Information Management - Identifies a need for and knows where or how to gather information; organizes and maintains information or information management systems.(Minimum Proficiency Level: 4) Interpersonal Skills - Shows understanding, friendliness, courtesy, tact, empathy, concern, and politeness to others; develops and maintains effective relationships with others; may include effectively dealing with individuals who are difficult, hostile, or distressed; relates well to people from varied backgrounds and different situations. (Minimum Proficiency Level: 4) Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. (Minimum Proficiency Level: 3) Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. (Minimum Proficiency Level: 4) Teamwork - Encourages and facilitates cooperation, pride, trust, and group identity; fosters commitment and team spirit; works with others to achieve goals. (Minimum Proficiency Level: 4) Technical Competence - Uses knowledge that is acquired through formal training or on-the-job experience to perform one's job; works with, understands, and evaluates technical information related to the job; advises others on technical issues. (Minimum Proficiency Level: 4) AND SPECIALIZED EXPERIENCE: In addition to meeting the competency requirement listed above, you must have at least one year of specialized experience at the next lower GS-grade level (or equivalent). Specialized experience is experience that has equipped you with the particular competencies/knowledge, skills, and abilities to successfully perform the duties of the position and is typically in or related to the work of the position to be filled. Such experience is typically gained in the IT field or through the performance of work where the primary concern is IT. You qualify at the GS-13 grade level, if you have: At least one (1) year of specialized experience at the GS-12 grade level (or equivalent) performing at least two of the following duties: Maintaining a current CompTIA Security+ or equivalent certification; Implementing cybersecurity controls within an information system; Evaluating technical vulnerabilities and cybersecurity audits to determine potential impact and mitigation; OR Conducting audits of cybersecurity practices and/or other compliance terms. You qualify at the GS-14 grade level, if you have: At least one (1) year of specialized experience at the GS-13 grade level (or equivalent) performing at least one of the following duties: Serving as a technical authority leading and coordinating cyber incident response and analysis; Leading systems security evaluations/audits/reviews and resolving security integration issues across systems and networks; Influencing leadership and stakeholders to adopt and implement cybersecurity findings and recommendations affecting telecommunications programs; OR Performing Information System Security Officer/Manager responsibilities for enterprise information system. Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., profess

Location and market context

This job is based in Arlington on-site. Local candidates benefit from being close to Cybersecurity and Infrastructure Security Agency's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.

About risk management jobs

Risk jobs own the methodology for identifying, assessing, and escalating enterprise, operational, and technology risk. Second-line teams set risk appetite and challenge the first line. Jobs like this one are typically evaluated against frameworks such as enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices.

How to position yourself for this risk management job

Strong candidates emphasize risk assessment methodology, appetite and escalation, cross-functional partnership, and clear reporting to senior leadership and the board. In your resume and outreach, tie your experience to how Cybersecurity and Infrastructure Security Agency would apply enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices, and lead with concrete outcomes rather than duties.

Similar GRC jobs

More jobs at Cybersecurity and Infrastructure Security Agency

More GRC jobs in Arlington

Hiring for Risk?

Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.

Post a job  Pricing from $99 · About GRC Careers · Hiring toolkit

Want to be next in a job like this?

Jobs like Foreign Investment Risk Compliance Monitoring Program Lead in Arlington, Virginia open regularly. Be first to know, privately. No current employer ever sees you looking.

New Risk jobs, the moment they post.

One click unsubscribe.
Know your GRC? Take the 2-minute AI Governance Challenge. No signup needed.
Play now →

Employer, or see something wrong with this posting? Report this posting and we will review it promptly.