Information Security Manager (INFOSEC)
This position is located in Division of Risk Management Supervision (RMS) and serves as the primary subject matter and technical expert in information security, responsible for managing the development and implementation of RMS's information security and privacy programs. Additional selections may be made from this announcement to fill identical vacancies that arise later.
Major duties
Develops and implements RMS's security and privacy policies and procedures related to RMS systems and processes. Manages the day-to-day operations of RMS's IT projects with respect to security and privacy requirements and documentation. Oversees RMS's compliance with corporate directives related to information security and privacy protection, and internal security memoranda and practices related to bank supervision. Collaborates with all RMS staff, other FDIC divisions, and external agencies on system access, security, and privacy matters, including sensitive issues with Division-wide implications. Implements business-specific security and privacy practices as directed by OCISO management and maintains communication with OCISO to ensure a continuous feedback loop. Serves as the point of contact for divisional data-loss incidents and data breaches; tracks and reports suspected information security violations to the Security Response Team and coordinates corrective actions with OCISO and RMS staff. Assesses FDIC technology posture, broader IT industry trends, and legislative and oversight actions to recommend program changes or new initiatives within the Division. Develops and delivers presentations and guidance to improve user understanding of security and privacy requirements and promote adherence to corporate and Division policies.
Qualifications
Qualifying experience is credited from private and public sectors, including paid and unpaid service (e.g., Peace Corps, AmeriCorps). Volunteer service builds competencies that translate to paid work. You will receive credit for all qualifying experience. See OPM's General Schedule Qualification Standards for details. CG-14: Applicants must complete one year of specialized experience equivalent to the CG-13 level or above in Federal service. Specialized experience is defined as: Collaborating with cybersecurity leadership on enterprise level security strategy, impact assessments, and risk management activities; Contributes to the development, implementation, and maintenance of information security and privacy policies, procedures, and controls within an enterprise environment; AND Conducts day to day security operations for IT systems or projects, including system access oversight, documentation, incident reporting, and/or coordination with cross functional teams. Applicants must have met the qualification requirements within 30 calendar days of the closing date. Interagency Career Transition Assistance Program (ICTAP) eligible applicants must earn 85 or higher on the online assessment to be determined "well qualified." Resume Content Required for Qualification Determinations For each position on your resume, include: Employer name; Title; Series and grade (federal jobs only); Start and end dates (month/year); Hours per week; Relevant experience supporting your specialized experience responses. Important: If your resume is missing these details, your application may be marked incomplete, and you might not be considered for this job. Do not copy/paste duties or specialized experience from this announcement into your resume; that will not be considered a demonstration of your qualifications.
Education
There is no substitution of education for experience for this position.