IT Spec (Infosec), GS-2210-14, FPL 14 (DH) (Open-Continuous)
Federal Student Aid
District of Columbia, District of ColumbiaDepartment of Education$144K – $187K
Posted 3 weeks ago · via Usajobs
Job Description
Summary
This position is in the U.S. Department of Education (ED), Federal Student Aid (FSA). FSA is modernizing the systems that serve over 17 million students and power more than $120 billion in financial aid each year. We are building a team of IT professionals to strengthen the technical foundation of one of the federal government's highest-impact digital ecosystems.Duties
- This is an open continuous announcement to fill current and future vacancies, until 07/30/2026. This is an open continuous announcement with cutoff dates. Applications will be referred based on receipt of application and established cutoff dates as follows: 1st cutoff date: 07/10/2026 2nd cutoff date: 07/20/2026 Last cutoff date: 07/24/2026 We encourage you to read this entire vacancy announcement prior to submitting your application. As a IT Spec (INFOSEC), GS-2210-14, you will be responsible for: • Leading enterprise cybersecurity program oversight across the Federal Student Aid (FSA) environment with in‐depth knowledge of the Federal Information Security Modernization Act (FISMA), Federal Risk and Authorization Management Program (FedRAMP), Department of Homeland Security Binding Operational Directives (DHS BODs), and related federal directives; ensure stakeholder security requirements are implemented across Zero Trust, segmented, and cloud architectures; and advise senior leadership on emerging threats and overall enterprise security posture. • Managing enterprise safeguards and compliance programs with expert knowledge of Internal Revenue Service (IRS) Publication 1075, Gramm Leach Bliley Act (GLBA) Safeguards Rule, NIST Special Publication (SP) 800 53, and NIST SP 800 171; oversee implementation and continuous monitoring of required controls across systems processing Federal Tax Information (FTI) and Controlled Unclassified information (CUI); and lead the full NIST SP 800 171 compliance lifecycle for Institutions of Higher Education (IHE). • Directing and leading Authority to Operate (ATO) and Operational Security Assessment (OSA) processes; perform Risk Management Framework (RMF)-aligned risk assessments, impact analyses, control evaluations, and continuous monitoring; serve as the technical authority for enterprise risk posture with strong skill in ATO, Enterprise Risk Management (ERM), continuous monitoring, and enterprise risk analysis; and provide authoritative recommendations supported by strong written and oral communication and leadership. • Overseeing incident response & compliance case management: triage, investigation, documentation, corrective action tracking, and regulatory reporting; provide senior advisory support during high risk events affecting significant data/systems. • Driving enterprise risk management artifacts (risk register, dashboards), committee support (Enterprise Cyber Risk Committee (ECRC), Chief Technology Officer (CTO) Risk Committee), training, and cybersecurity communications; manage Enterprise Risk Management (ERM) tool and user support.