Jobs › Multiple Locations › IT Cybersecurity Specialist (Direct Hire)
IT Cybersecurity Specialist (Direct Hire)
Headquarters, NASA is hiring for the job of IT Cybersecurity Specialist (Direct Hire), Multiple Locations (On-site). This is a Cybersecurity job in the governance, risk, and compliance field, with a posted range of $89508 - $172980 Per Year. Review the full details below and apply directly with Headquarters, NASA.
This position is located in the Cybersecurity and Privacy Division (CSPD) of the Office of the Chief Information Officer (OCIO). As a Cybersecurity Risk Manager (CSRM), you will guide stakeholders as they implement assessment and authorization policies and procedures, cybersecurity continuous monitoring, and risk management activities. You will collaborate with other CSRMs to provide support for stakeholders in identifying, communicating, and managing cybersecurity risks.
Qualifications: Specialized experience is experience that has equipped you with the particular ability, skill, and knowledge to successfully perform the duties of this position and is typically in or related to this line of work. To qualify for GS-12, you must have one year of directly related specialized experience equivalent to the GS-11 level. Providing technical security oversight for information systems and balance the demands of multiple customers; Applying Risk Management Framework (RMF) process and principles, methods and/or practices against specified requirements/controls (e.g., National Institute of Standards and Technology (NIST) Special Publications 800-37, 800-53, and 800-60); Collaborating with customers and/or business partners to help manage compliance with requirements. To qualify for GS-13, you must have one year of directly related specialized experience equivalent to the GS-12 level. Providing technical security oversight for information systems and balance the demands of multiple customers while formulating and driving Agency security priorities; Applying Risk Management Framework (RMF) process and principles, methods and practices against specified requirements/controls (e.g., National Institute of Standards and Technology (NIST) Special Publications 800-37, 800-53, and 800-60) to develop security plans and continuously monitor the cybersecurity posture of networks and information systems; Collaborating with customers and/or business partners to perform oversight and manage compliance with requirements to ensure an organization's cybersecurity posture in a risk-based manner that minimizes operational impact. AND IF you are qualifying based on experience, you MUST also have IT-related experience demonstrating each of the nine competencies listed below: Attention to Detail - Is thorough when performing work and conscientious about attending to detail. Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. Decision Making - Makes sound, well-informed, and objective decisions; perceives the impact and implications of decisions; commits to action, even in uncertain situations, to accomplish organizational goals; causes change. Information Management - Identifies a need for and knows where or how to gather information; organizes and maintains information or information management systems. Interpersonal Skills - Treats others with courtesy, sensitivity, and respect. Considers and responds appropriately to the needs and feelings of different people in different situations. Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. Teamwork - Works well with others in a team environment to achieve goals; helps engender team spirit and commitment by encouraging, modeling, and/or facilitating cooperation, pride, trust, and a sense of group identity among team members. Technical Competence - Uses knowledge that is acquired through formal training or extensive on-the-job experience to perform one's job; works with, understands, and evaluates technical information related to the job; advises others on technical issues. Your resume must include a clear and detailed narrative description, in your own words, of how you meet the required specialized experience. Experience statements copied from a position description, vacancy announcement or other reference material constitutes plagiarism and may result in disqualification and losing consideration for the job. Please visit https://www.nasa.gov/careers/how-to-apply/#Artificial-Intelligence to review NASA's guidance on the use of artificial intelligent (AI) or AI-assisted tools during the application process.
Location and market context
This job is based in Multiple Locations on-site. Local candidates benefit from being close to Headquarters, NASA's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About cybersecurity governance jobs
Cybersecurity governance connects security control frameworks to business and regulatory risk, covering policy, risk assessment, and control assurance rather than hands-on operations. Jobs like this one are typically evaluated against frameworks such as NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices.
How to position yourself for this cybersecurity governance job
Strong candidates emphasize security control frameworks, risk assessment, policy and standards, and translating technical security posture into governance and board-level reporting. In your resume and outreach, tie your experience to how Headquarters, NASA would apply NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
- IT Cybersecurity Specialist (NETWORK/INFOSEC) · Defense Information Systems Agency · Multiple Locations
- SUPV IT CYBERSECURITY SPECIALIST (SYSADMIN/INFOSEC) · Defense Information Systems Agency · Multiple Locations
- SUPERVISORY IT CYBERSECURITY SPECIALIST (INFOSEC) · Defense Information Systems Agency · Multiple Locations
- IT Cybersecurity Specialist INFOSEC · Cybersecurity and Infrastructure Security Agency · Multiple Locations
- IT Cybersecurity Specialist · Western Area Power Administration · Multiple Locations
- Computer Engineer (Cybersecurity) · Bureau of the Fiscal Service · Multiple Locations
- Program analyst (Cyber Operations) · United States Space Force · Multiple Locations
- Program Analyst (Cyber Operations) · Air Force Materiel Command · Multiple Locations
More GRC jobs in Multiple Locations
- Senior Program Evaluation and Risk Analyst · Internal Revenue Service · IRS Nationwide Locations
- AI Auditor · GRC Careers · Remote
- Recent Graduate - Auditor · Office of Inspector General · Multiple Locations
- Supervisory Auditor · Office of Inspector General · Location Negotiable After Selection
- Performance Auditor · Office of the Inspector General for Tax Administration · Location Negotiable After Selection
- Investigative Support Auditor · Defense Contract Audit Agency · Multiple Locations
Hiring for Cybersecurity?
Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Want to be next in a job like this?
Jobs like IT Cybersecurity Specialist (Direct Hire) in Multiple Locations open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.