GRC Careers: AI Governance, Risk and Compliance JobsConnecting Talent and Trust. Post a Job Log in

JobsMultiple LocationsIT Cybersecurity Specialist

IT Cybersecurity Specialist

Western Area Power Administration
CybersecurityOn-siteFull-timeMultiple Locations$106437 - $154280 Per Year

Western Area Power Administration is hiring for the job of IT Cybersecurity Specialist, Multiple Locations (On-site). This is a Cybersecurity job in the governance, risk, and compliance field, with a posted range of $106437 - $154280 Per Year. Review the full details below and apply directly with Western Area Power Administration.

Organization: Western Area Power AdministrationLocation: Multiple LocationsWorkplace: On-siteFocus: CybersecuritySalary: $106437 - $154280 Per YearPosted: Aug 25, 2026
Western Area Power Administration is hiring for this Cybersecurity job in Multiple Locations, one of the metros GRC Careers tracks for governance, risk, and compliance hiring.

As an IT Cybersecurity Specialist (INFOSEC), you will provide technical expertise and guidance to WAPA functional and project teams regarding cybersecurity technical issues, risk analyses, mitigation plans and continuity of operations planning. **This is NOT A REMOTE POSITION. The selectee will be required to be physically present at one of the duty location(s) identified.**

Qualifications: QUALIFICATION REQUIRMENTS: To qualify for this position, you must meet the minimum qualification requirements as well as the specialized experience requirements outlined below: MINIMUM REQUIREMENTS FOR GRADE 12 and Above (GS or Equivalent): The competencies listed in the "How You Will Be Evaluated" section will be used to evaluate whether or not you meet the minimum proficiency level established for the 2210 series SPECIALIZED EXPERIENCE for Cybersecurity Infrastructure and Architecture (IA): A qualified candidate's online application and resume must demonstrate at least one (1) year of specialized experience equivalent in difficulty and responsibility to the next lower grade level GS-12 in the Federal service (obtained in either the public or private sectors). Specialized experience for this position is defined as having at least two (2) of the following: Test, analyze, and/or implement existing and future systems to complement existing cybersecurity architectures; often leading Authority to Operate (ATO) job functions such as control testing and validation, Plan of Actions & Milestones (POAM) tracking or Risk Acceptance (RA). Analyze security events, including threat model development and resulting security risk analysis of systems. Design and develop security architecture to execute a company's cybersecurity program to meet Federal Information Security Modernization Act (FISMA), North American Electric Reliability (NERC), Critical Information Protection (CIP), or NIST 800-53 Controls. Perform vulnerability management to include scans, assessments, and remediation in conjunction with other IT business units to reduce company-wide risk. -OR- SPECIALIZED EXPERIENCE for Cybersecurity Operations (Ops): A qualified candidate's online application and resume must demonstrate at least one (1) year of specialized experience equivalent in difficulty and responsibility to the next lower grade level GS-12 in the Federal service (obtained in either the public or private sectors). Specialized experience for this position is defined as having at least two (2) of the following: Configure and manage and/or manage the lifecycle of at least 1 (one) of the following cybersecurity systems: Axonius, Carbon Black App Control, Carbon Black Endpoint Detection and Response (EDR), Corelight, Forescout, Splunk, and Tenable. Apply the Risk Management Framework (RMF) and assess cybersecurity systems against federal and industry compliance standards, such as NIST SP 800-53, FISMA, or NERC CIP. Conduct incident response activities, vulnerability assessments, and/or digital forensics, including analyzing security events to understand and mitigate active potential cybersecurity threats.

Location and market context

This job is based in Multiple Locations on-site. Local candidates benefit from being close to Western Area Power Administration's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.

About cybersecurity governance jobs

Cybersecurity governance connects security control frameworks to business and regulatory risk, covering policy, risk assessment, and control assurance rather than hands-on operations. Jobs like this one are typically evaluated against frameworks such as NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices.

How to position yourself for this cybersecurity governance job

Strong candidates emphasize security control frameworks, risk assessment, policy and standards, and translating technical security posture into governance and board-level reporting. In your resume and outreach, tie your experience to how Western Area Power Administration would apply NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices, and lead with concrete outcomes rather than duties.

Similar GRC jobs

More GRC jobs in Multiple Locations

Want to be next in a job like this?

Jobs like IT Cybersecurity Specialist in Multiple Locations open regularly. Be first to know, privately. No current employer ever sees you looking.

New Cybersecurity jobs, the moment they post.

One click unsubscribe.
Know your GRC? Take the 2-minute AI Governance Challenge. No signup needed.
Play now →

Employer, or see something wrong with this posting? Report this posting and we will review it promptly.