Jobs › Multiple Locations › Supvy IT Spec (SEC) 'Cyber Ops Branch Chief', GS-2210-15 FPL GS-15 (DH)
Supvy IT Spec (SEC) 'Cyber Ops Branch Chief', GS-2210-15 FPL GS-15 (DH)
Department of Education Headquarters is hiring for the job of Supvy IT Spec (SEC) 'Cyber Ops Branch Chief', GS-2210-15 FPL GS-15 (DH), Multiple Locations (On-site). This is a Cybersecurity job in the governance, risk, and compliance field, with a posted range of $147945 - $197200 Per Year. Review the full details below and apply directly with Department of Education Headquarters.
This position is in the U.S. Department of Education (ED), Federal Student Aid (FSA), Chief Technology Office. FSA manages the administrative and oversight functions supporting programs authorized under Title I and Title IV of the Higher Education Act of 1965, as amended (HEA) and the Health Education Assistance Loan (HEAL) program transferred to the U.S.
Qualifications: Minimum Qualification Requirements You may meet the minimum qualifications for the GS-15, if you possess the specialize experience, education, or a combination of the two. Specialized Experience for the GS-15 One year of experience in either federal or non-federal service that is equivalent to at least a GS-14 performing two (2) out of three (3) of the following duties or work assignments: 1.Experienced in leading both the Security Operations Center (SOC) and Security Engineering teams in a large enterprise, overseeing 24/7 threat monitoring, threat hunting, and incident response while directing the design, implementation, and lifecycle management of enterprise-wide security engineering solutions such as SIEM and SOAR to ensure resilient, scalable, and continuously visible defensive architectures. 2. Experience as the senior technical authority for around the clock SOC operations by establishing Standard Operating Procedures (SOPs) for threat detection and triage, leading major incident response efforts, and integrating threat intelligence into vulnerability management to prioritize remediation and ensure all activities align with security standards such as FISMA, NIST, or other cyber security industry standards. 3. Experience extensively in developing and enforcing technical security standards, ensuring NIST aligned compliance, and conducting vulnerability audits across U.S. Federal or private sector environments, with deep expertise in cybersecurity policies and directives in line with cyber security federal or industry standards. Basic Experience Requirements Example (Supervisory IT Positions ):Applicants may qualify by meeting or exceeding the minimum proficiency level established for each of the required competencies, in addition to meeting the specialized experience requirement as demonstrated through the assessment of skills. You must possess IT-related experience (paid or unpaid experience and/or completion of specific, intensive training (e.g., IT certification), as appropriate) demonstrating each of the ten competencies listed below. Accountability-Holds self and others accountable for measurable high-quality, timely, and cost-effective results. Determines objectives, sets priorities, and delegates work. Accepts responsibility for mistakes. Complies with established control systems and rules. 2. Customer Service- Anticipates and meets the needs of both internal and external customers. Delivers high-quality products and services; is committed to continuous improvement. 3. Decisiveness- Makes well-informed, effective, and timely decisions, even when data are limited or solutions produce unpleasant consequences; perceives the impact and implications of decisions. 4. Flexibility- Is open to change and new information; rapidly adapts to new information, changing conditions, or unexpected obstacles. 5. Integrity/Honesty- Behaves in an honest, fair, and ethical manner. Shows consistency in words and actions. Models high standards of ethics. 6. Interpersonal Skills- Treats others with courtesy, sensitivity, and respect. Considers and responds appropriately to the needs and feelings of different people in different situations. 7. Oral Communication- Makes clear and convincing oral presentations. Listens effectively; clarifies information as needed. 8. Problem Solving- Identifies and analyzes problems; weighs relevance and accuracy of information; generates and evaluates alternative solutions; makes recommendations. 9. Resilience- Deals effectively with pressure; remains optimistic and persistent, even under adversity. Recovers quickly from setbacks. 10. Written Communication- Writes in a clear, concise, organized, and convincing manner for the intended audience. Knowledge, Skills, and Abilities (KSAs) The quality of your experience will be measured by the extent to which you possess the following knowledge, skills and abilities (KSAs). You do not need to provide separate narrative responses to these KSAs, as they will be measured by your responses to the occupational questionnaire (you may preview the occupational questionnaire by clicking the link at the end of the Evaluations section of this vacancy announcement). 1. Knowledge of the SOC lifecycle, 24/7 monitoring, incident response, threat hunting, and intelligence, with cybersecurity frameworks such as FSMA, NIST, General Data Protection Regulation (GPDR). Familiarity with Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), EDR, NDR, architecture and network security tools, along with awareness of technology consolidation, strategic planning, organizational risk posture, budgeting, and coordination across internal teams and external partners including SOC. 2. Knowledge of NIST SP 800-171, SP 800-53, FISMA, and security requirements for organization; understanding of vulnerability identification, assessment, prioritization, remediation, and documentation; proficiency in technical evaluations of systems, networks, and applications to determine security gaps; and thorough familiarity with the Risk Management Framework, including ATO documentation and POA&M processes. including SOC. 3. Skill in translating technical concepts into clear, non-technical language for senior leaders, FSA business units, and ISSOs; effective collaboration with ISOs, ISSOs, and Business Unit leaders to support cybersecurity awareness, risk- and attack-based security architecture, a secure culture, accurate security-tool inventory maintenance, deployment oversight, tool life-cycle management, and transition recommendations aligned to opera
Location and market context
This job is based in Multiple Locations on-site. Local candidates benefit from being close to Department of Education Headquarters's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About cybersecurity governance jobs
Cybersecurity governance connects security control frameworks to business and regulatory risk, covering policy, risk assessment, and control assurance rather than hands-on operations. Jobs like this one are typically evaluated against frameworks such as NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices.
How to position yourself for this cybersecurity governance job
Strong candidates emphasize security control frameworks, risk assessment, policy and standards, and translating technical security posture into governance and board-level reporting. In your resume and outreach, tie your experience to how Department of Education Headquarters would apply NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
- IT Cybersecurity Specialist (Security) · Centers for Medicare & Medicaid Services · Multiple Locations
- IT CYBERSECURITY SPECIALIST (SYSANALYSIS/INFOSEC) · Defense Information Systems Agency · Multiple Locations
- IT CYBERSECURITY SPECIALIST (APPSW/INFOSEC) · Defense Finance and Accounting Service · Multiple Locations
- Cyber Network Professional - Entry to Mid Level · National Security Agency/Central Security Service · Multiple Locations
- IT CYBERSECURITY SPECIALIST (INFOSEC) · Defense Finance and Accounting Service · Multiple Locations
- IT CYBERSECURITY SPECIALIST (NETWORK/INFOSEC) · Defense Information Systems Agency · Multiple Locations
- Cybersecurity State Coordinator · Cybersecurity and Infrastructure Security Agency · Multiple Locations
- Cybersecurity Risk Management and Compliance - Technical · DHS Headquarters · Multiple Locations
More jobs at Department of Education Headquarters
- Supervisory Auditor (Performance) · Department of Education Headquarters · Multiple Locations
More GRC jobs in Multiple Locations
- Compliance Innovation & AI Lead · GE Vernova · 2 Locations
- Global Head of Payroll, Tax & Risk Operations · GE Vernova · Remote
- Auditor (Performance) · Office of the Inspector General · Multiple Locations
- Government Information Specialist (Privacy Analyst) · Customs and Border Protection · Multiple Locations
- Senior Compliance Manager - Global FCC Investigations · OKX · EMEA
- Complaints Compliance & Prevention Manager - (Relocation to Madrid) · N26 · Berlin
Hiring for Cybersecurity?
Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Want to be next in a job like this?
Jobs like Supvy IT Spec (SEC) 'Cyber Ops Branch Chief', GS-2210-15 FPL GS-15 (DH) in Multiple Locations open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.