Chief Information Security Officer

National Institutes of Health

$150K — $200K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Executive-level leadership in a large cybersecurity program
  • Expertise in regulatory compliance and strategic alignment
  • Experience advising senior executives on security matters
  • Proven ability to build coalitions and represent cybersecurity programs
  • Understanding of U.S. laws and principles governing security and privacy

Responsibilities

  • Lead NIH-wide cybersecurity infrastructure and strategies
  • Serve as technical advisor to senior NIH officials
  • Ensure cybersecurity programs align with business needs and long-term goals
  • Oversee continuous threat monitoring and vulnerability management
  • Direct and manage the cybersecurity program and policies
  • Represent NIH in discussions with government officials and industry leaders
  • Collaborate with partners to enhance information security practices

Benefits

  • Comprehensive federal benefits package
  • Vacation, sick leave, and holidays
  • Life insurance and health benefits
  • Participation in the Federal Employees Retirement System
  • Opportunities for volunteer assignments in critical situations
Full Job Description
Summary

The Office of the Director, in the NIH, is seeking exceptional candidates for the position of Director of Cybersecurity/Chief Information Security Officer. This is a career Federal position in the Senior Executive Service. See "Duties" section for a list of the major responsibilities.

Duties

  • Provides executive level leadership, direction, and oversight for planning, coordination, and control of NIH-wide cybersecurity infrastructure and technology functions.
  • Serves as the principal technical advisor to the Chief Information Officer (CIO), the Deputy Chief Information Officer, and other senior NIH officials on cybersecurity infrastructure and technology across the 27 institutes and centers.
  • Ensures the cybersecurity programs are consistent with the current security and business needs and long-term goals of NIH.
  • Manages continuous monitoring and remediation of potential and actual threats and vulnerabilities to NIH's systems and data.
  • Provides strategic planning, integration and support for NIH cybersecurity and counter-intelligence initiatives and physical security through collaboration with executives, research scientists, and technical internal and external groups.
  • Assesses risks and improve the NIH information security.
  • Directs and manages a cybersecurity program to protect NIH information and its assets, cybersecurity policy, and related functions (e.g., vulnerability management, intrusion detection and incident response, and continuous monitoring, etc.).
  • Represents the CIO and Deputy CIO in meetings with NIH and HHS officials, OMB, representatives of business and industry, Congressional committees and staff, and other matters involving plans, programs, policies, and objectives of the OCIO and NIH.
  • Works with organizational units and partners to implement practices that meet agreed-on policies and standards for information security and privacy.
  • Ensures that NIH cybersecurity infrastructure and technology meet all requirements in compliance with Federal laws, regulations, and best practices.
  • Manages an annual budget of approximately $77M and directs a staff of approximately 50 federal employees and 150 contractors.


Requirements

Conditions of employment

  • U.S. Citizenship requirement or proof of being a U.S. National must be met by closing date.
  • Employment is subject to the successful completion of the pre-appointment process (i.e., background investigation, verification of qualifications and job requirements, completion of onboarding forms, submission of required documents, etc.).
  • Applicants must meet all qualifications requirements by the closing date of this announcement.
  • This position requires completion of a public financial disclosure report.
  • This position is a Testing Designated Position, which requires the incumbent to submit to random testing of urine and illegal drugs or substances.
  • The selectee must be eligible to obtain and maintain a Top Secret/SCI security clearance.
  • A one-year probationary period must be served by the individual selected if not currently or previously in the career Senior Executive Service.


Qualifications

BASIC QUALIFICATIONS:

Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution. Candidates will not be hired based on their race, sex, color, religion, or national origin.

To meet the minimum qualification requirements for this position, you must show that you possess the Executive Core Qualifications (ECQ) and Technical Qualifications (TQ) related to this position within your resume - NOT TO EXCEED 2 PAGES. Resumes over the 2-page limit, will not be reviewed beyond page 2 or may be disqualified. Your resume must include examples of experience, education, and accomplishments applicable to the qualification(s). If your resume does not reflect demonstrated evidence of these qualifications, you may not receive consideration for the position.

There is NO requirement to prepare a narrative statement specifically addressing the Executive Core Qualifications (ECQs) or the Technical Qualifications (TQs).

TECHNICAL QUALIFICATIONS (TQs): Your resume must demonstrate accomplishments that would satisfy the technical qualifications.

TQ 1: Demonstrated ability providing executive-level leadership for a large, comprehensive cybersecurity program that ensures regulatory compliance and leads infrastructure and technology initiatives consistent with information security, business needs, change management, and long-term organizational goals to protect government information, operations, and assets.

TQ 2: Demonstrated ability to build coalitions by advising and representing senior level executives inside and outside the agency regarding cybersecurity programs, systems policy, and technical matters, while demonstrating senior-level expertise in managing agency-wide cybersecurity infrastructure to deliver secure, result-oriented outcomes.

EXECUTIVE CORE QUALIFICATIONS (ECQs): In addition to the Technical Qualification requirements listed above, all new entrants into the Senior Executive Service (SES) under a career appointment will be assessed for executive competency against the following five mandatory ECQs. If your 2-page resume does not reflect demonstrated evidence of the ECQs and TQs, you may not receive further consideration for the position.

There are five ECQs:

ECQ 1: Commitment to the Rule of Law and the Principles of the American Founding - This core qualification requires a demonstrated knowledge of the American system of government, commitment to uphold the Constitution and the rule of law, and commitment to serve the American people.

ECQ 2: Driving Efficiency - This core qualification involves the demonstrated ability to strategically and efficiently manage resources, budget effectively, cut wasteful spending, and pursue efficiency through process and technological upgrades.

ECQ 3: Merit and Competence - This core qualification involves the demonstrated knowledge, ability and technical competence to effectively and reliably produce work that is of exceptional quality.

ECQ 4: Leading People - This core qualification involves the demonstrated ability to lead and inspire a group toward meeting the organization's vision, mission, and goals, and to drive a high-performance, high-accountability culture. This includes, when necessary, the ability to lead people through change and to hold individuals accountable.

ECQ 5: Achieving Results - This core qualification involves the demonstrated ability to achieve both individual and organizational results, and to align results to stated goals from superiors.

Note: If you are a member of the SES or have been certified through successful participation in an OPM approved SES Candidate Development Program (SESCDP), or have SES reinstatement eligibility, you do not need to respond to the ECQs. Instead, you should attach proof (e.g., SF-50, Certification by OPM's SES Qualifications Review Board (QRB)) of your eligibility for noncompetitive appointment to the SES.

Please DO NOT submit separate documents addressing the ECQs or TQs.

BASIC QUALIFICATIONS:

The Office of the Director, NIH seeks candidates who have a commitment to excellence and the energy, enthusiasm, and innovative thinking necessary to lead a dynamic organization.

All competitive candidates for SES positions with the Federal Government must demonstrate leadership experience indicative of senior executive level management capability. The Director of Cybersecurity/Chief Information Security Officer (CISO) position resides within the Office of Chief Information Officer (OCIO) in the Office of the Director, NIH, and reports directly to the NIH Chief Information Officer.

Applicants must meet the requirements for the GS-2210 series as defined by the U.S. Office of Personnel Management Qualifications Standards Manual for General Schedule Positions which is available at: OPM Qualifications Standards GS-2210 Website and demonstrate in your two (2) page resume that you possess the Technical Qualifications (TQs) listed above. It is recommended that your resume emphasize levels of responsibility, scope and complexity of programs managed, and program accomplishments and results.

Candidates must possess experience at the senior level (GS-14/15 level or equivalent) in the job-specific Technical Qualifications (TQs). The TQs measure the technical expertise required by this position and must be addressed within your 2-page resume. It is recommended that corresponding TQs be annotated in parenthesis within your 2-page resume.

Political, Schedule C, Non-career SES Appointee*:
In the last five years, based on the closing date of this announcement, have you been or are you currently an employee in the Executive Branch serving on a political, Schedule C, or Non-career SES appointment? If yes, and you are selected through this vacancy announcement, you may be required to obtain approval by the Office of Personnel Management (OPM) prior to beginning employment. (Please confirm whether or not you have this experience within your 2-page resume)

*A political appointee is an appointment made by the President without confirmation by the Senate (5 CFR [redacted](c)) OR an Assistant position to a top-level Federal official if filled by a person designated by the President as a White House Fellow (5 CFR [redacted](z)). A Non-career SES appointee is approved by the White House and serves at the pleasure of the appointing official without time limitations. A Schedule C appointee occupies a position excepted from the competitive service by the President, or by the Director, OPM, because of the confidential or policy-determining nature of the position duties.

NOTE: IF SELECTED, a Structured Interview will be used to certify the candidate by an OPM Qualifications Review Board (QRB). If you are currently serving in a career SES appointment, are eligible for reinstatement into the SES, or have successfully completed an SES Candidate Development Program approved by the Office of Personnel Management (OPM), you WILL NOT need to participate in a Structured Interview.

Additional information

NIH is located in Bethesda, MD; our campus is adjacent to downtown Bethesda, MD, at the Medical Center Metro station, and close to shops, walking trails, and restaurants.

Travel and Transportation expenses may be authorized in accordance with applicable Federal Travel Regulations governing the relocation of current Federal employees and new appointees.

HHS has a critical preparedness and response mission: HHS protects the American people from health threats, researches emerging diseases, and mobilizes public health programs with domestic and international partners. In support of this mission, HHS offers its employees the opportunity to volunteer to become Federal Civilian Detailees and contribute their unique skills through voluntary temporary assignments to humanitarian emergencies or Departmental priorities countering new and emerging health, safety, and security threats.

To promote efficiency in the hiring process, the resume and corresponding responses of successful candidates may be shared with other Institutes/Centers of NIH with similar vacancies. However, applicants are strongly encouraged to apply directly to the vacancy of interest and not rely on this possibility as a means of securing employment.

Standards of Conduct/Financial Disclosure: The National Institutes of Health inspires public confidence in our science by maintaining high ethical principles. NIH employees are subject to Federal government-wide regulations and statutes as well as agency-specific regulations described at the NIH Ethics website. We encourage you to review this information. The Ethics in Government Act, PL 95-521, also requires the applicant selected for this position to submit a Public Financial Disclosure Report, OGE-278, prior to assuming the SES position, annually, and upon termination of employment.

Benefits

Help

A career with the U.S. government provides employees with a comprehensive benefits package. As a federal employee, you and your family will have access to a range of benefits that are designed to make your federal career very rewarding. Opens in a new windowLearn more about federal benefits.

The federal government offers a comprehensive benefits package including vacation, sick leave, holidays, life insurance, health benefits, and participation in the Federal Employees Retirement System. For more information, check out New Employee Benefits at N

Similar Jobs

More Jobs at National Institutes of Health

More Information Technology Jobs

Find similar Chief Information Security Officer jobs: