GRC Careers: Governance, Risk and Compliance JobsGovernance · Risk · Compliance Careers

Jobs › Multiple Locations › IT Spec (INFOSEC) 'Information System Security Officer (ISSO)', GS-2210-13 FPL GS-13 (DH)

IT Spec (INFOSEC) 'Information System Security Officer (ISSO)', GS-2210-13 FPL GS-13 (DH)

Department of Education Headquarters
CybersecurityOn-siteFull-timeMultiple Locations$106437 - $172980 Per Year

Department of Education Headquarters is hiring for the job of IT Spec (INFOSEC) 'Information System Security Officer (ISSO)', GS-2210-13 FPL GS-13 (DH), Multiple Locations (On-site). This is a Cybersecurity job in the governance, risk, and compliance field, with a posted range of $106437 - $172980 Per Year. Review the full details below and apply directly with Department of Education Headquarters.

Organization: Department of Education HeadquartersLocation: Multiple LocationsWorkplace: On-siteFocus: CybersecuritySalary: $106437 - $172980 Per YearPosted: Oct 9, 2026
Department of Education Headquarters is hiring for this Cybersecurity job in Multiple Locations, one of the metros GRC Careers tracks for governance, risk, and compliance hiring.

This position is in the U.S. Department of Education (ED), Federal Student Aid (FSA), Chief Technology Division, Security Services Division as an Information System Security Officer (ISSO). FSA manages the administrative and oversight functions supporting programs authorized under Title I and Title IV of the Higher Education Act of 1965.

Qualifications: You must meet all qualification requirements within 30 days of the closing date of this vacancy announcement. If you are a current federal employee, you must meet all time-in-grade and time-after competitive appointment qualifications within 30 days of the closing date of this vacancy announcement. To verify that you meet these requirements, we will review your responses to the core eligibility questions on the occupational questionnaire, as well as your submitted resume and required documents. To make an accurate determination, you will need to include on your resume your federal position title, pay plan, occupational series, grade level, agency, dates for which you held the grade level (stated as MM/YYYY to MM/YYYY, OR MM/YYYY to PRESENT), and total hours worked per week. Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic; religious; spiritual; community, student, social). Minimum Qualification Requirements You may meet the minimum qualifications for the GS-13, if you possess the specialize experience, education, or a combination of the two. Specialized Experience for the GS-13 One year of experience in either federal or non-federal service that is equivalent to at least a GS-12 performing two (2) out of three (3) of the following duties or work assignments: 1. Experience conducting cybersecurity risk assessments and supporting Security Assessment and Authorization process efforts. 2. Experience in ensuring vulnerabilities and Plans of Actions and Milestones (POA&Ms) are processed in a timely manner and remediation plans are in place for identified vulnerabilities. 3. Experience supporting successful implementation and functionality of security requirements and information technology (IT) policies and procedures consistent with the organization's mission and goal Basic Experience Requirements Example (IT Specialist GS-12 and Above GS or Equivalent): For positions at the GS-12, GS-13, GS-14, or GS-15 grade levels, applicants may qualify by meeting or exceeding the minimum proficiency level established for each of the required competencies, in addition to meeting the specialized experience requirement as demonstrated through the assessment of skills. You must possess IT-related experience (paid or unpaid experience and/or completion of specific, intensive training (e.g., IT certification), as appropriate) demonstrating each of the nine competencies listed below. Attention to Detail - Is thorough when performing work and conscientious about attending to detail. 2. Customer Service - Works with clients and customers (i.e., any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. 3. Decision Making - Makes sound, well-informed, and objective decisions; perceives the impact and implications of decisions; commits to action, even in uncertain situations, to accomplish organizational goals; causes change. 4. Information Management - Identifies a need for and knows where or how to gather information; organizes and maintains information or information management systems. 5. Interpersonal Skills- Shows understanding, friendliness, courtesy, tact, empathy, concern, and politeness to others; develops and maintains effective relationships with others; may include effectively dealing with individuals who are difficult, hostile, or distressed; relates well to people from varied backgrounds and different situations. 6. Oral Communication- Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. 7. Problem Solving- Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. 8. Teamwork- Encourages and facilitates cooperation, pride, trust, and group identity; fosters commitment and team spirit; works with others to achieve goals. 9. Technical Competence- Uses knowledge that is acquired through formal training or on-the-job experience to perform one's job; works with, understands, and evaluates technical information related to the job; advises others on technical issues Knowledge, Skills, and Abilities (KSAs) The quality of your experience will be measured by the extent to which you possess the following knowledge, skills and abilities (KSAs). You do not need to provide separate narrative responses to these KSAs, as they will be measured by your responses to the occupational questionnaire (you may preview the occupational questionnaire by clicking the link at the end of the Evaluations section of this vacancy announcement). 1. Knowledge of cybersecurity risk management processes (e.g., methods for assessing and mitigating cybersecurity risks). 2. Knowledge of cybersecurity and privacy principles; vulnerabilities; impacts of cybersecurity lapses; and applicable business processes of operations of customer organization. 3. Knowledge of vulnerability information dissemination sources

Location and market context

This job is based in Multiple Locations on-site. Local candidates benefit from being close to Department of Education Headquarters's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.

About cybersecurity governance jobs

Cybersecurity governance connects security control frameworks to business and regulatory risk, covering policy, risk assessment, and control assurance rather than hands-on operations. Jobs like this one are typically evaluated against frameworks such as NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices.

How to position yourself for this cybersecurity governance job

Strong candidates emphasize security control frameworks, risk assessment, policy and standards, and translating technical security posture into governance and board-level reporting. In your resume and outreach, tie your experience to how Department of Education Headquarters would apply NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices, and lead with concrete outcomes rather than duties.

Similar GRC jobs

More jobs at Department of Education Headquarters

More GRC jobs in Multiple Locations

Hiring for Cybersecurity?

Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.

Post a job  Pricing from $99 · About GRC Careers · Hiring toolkit

Want to be next in a job like this?

Jobs like IT Spec (INFOSEC) 'Information System Security Officer (ISSO)', GS-2210-13 FPL GS-13 (DH) in Multiple Locations open regularly. Be first to know, privately. No current employer ever sees you looking.

New Cybersecurity jobs, the moment they post.

One click unsubscribe.
Know your GRC? Take the 2-minute AI Governance Challenge. No signup needed.
Play now →

Employer, or see something wrong with this posting? Report this posting and we will review it promptly.