TSA Cybersecurity Jobs: 2210 and 1801 Career Paths Explained
TSA cybersecurity work spans more than one occupation. Some employees protect and support TSA information systems. Others analyze cyber risk across transportation sectors, support regulatory or compliance programs, or coordinate protective initiatives with transportation operators.
That distinction affects the occupational series, qualification standard and resume evidence expected from an applicant.
Two important pathways are:
- 2210 Information Technology Management, commonly used for IT Specialist and cybersecurity-focused IT positions; and
- 1801 General Inspection, Investigation, Enforcement and Compliance, used for some Transportation Security Specialist cyber-analysis or cybersecurity positions.
The vacancy announcement—not the word “cybersecurity” alone—determines the actual work.
This guide discusses authorized defensive, analytical, compliance and protective work. It does not provide instructions for exploiting systems, bypassing controls, disrupting transportation infrastructure or accessing networks without permission.
TSA Cybersecurity Careers at a Glance
| Topic | General current information |
|---|---|
| Main occupational series | 2210 and 1801 |
| Common 2210 title | Information Technology Specialist |
| Common 1801 titles | Transportation Security Specialist, Cyber Analyst or supervisory variants |
| Main 2210 focus | IT systems, services, security engineering, operations and risk management |
| Main 1801 focus | Transportation-security cyber analysis, compliance, coordination or program work |
| Degree requirement | Vacancy and qualification route specific |
| Specialized experience | Commonly required |
| Skills-based assessment | Possible, especially under current 2210 standards |
| Certifications | Helpful or required only when the vacancy says so |
| Background process | Required |
| Clearance or sensitivity | Position specific; common in higher-risk work |
| Drug testing | Position specific |
| Telework | Vacancy specific |
| Remote work | Not implied by telework eligibility |
| Law-enforcement authority | Not created by a cyber title |
The Two Main Cyber Pathways
2210 Information Technology Management
A 2210 position is centered on information technology. Cybersecurity can be the primary specialty or one component of a broader IT role.
Work can include:
- information-system security;
- security architecture;
- identity and access management;
- vulnerability management;
- security operations;
- incident coordination;
- risk management;
- cloud security;
- network defense;
- system authorization support;
- policy implementation;
- configuration management;
- security-control assessment;
- continuity and recovery planning;
- application security; and
- technical advice to system owners.
TSA publicly describes 2210 employees as managing, supervising, leading, administering, developing, delivering and supporting IT systems and services.
1801 Cyber or Transportation-Security Work
An 1801 position may be less focused on operating TSA’s internal IT environment and more focused on transportation-security programs.
Work can involve:
- analyzing transportation-sector cyber risk;
- supporting cybersecurity directives or requirements;
- coordinating with surface transportation operators;
- reviewing security programs;
- evaluating compliance information;
- developing protective initiatives;
- supporting inspections or assessments;
- preparing briefings and policy material;
- tracking remediation or program actions; and
- collaborating with government and industry partners.
Some TSA public materials identify Transportation Security Specialist cyber roles in series 1801.
An 1801 Cyber Analyst is not automatically a network administrator, penetration tester or criminal investigator.
Internal IT Security Versus Transportation-Sector Cybersecurity
| Internal TSA IT security | Transportation-sector cyber work |
|---|---|
| Protects TSA systems and services | Supports security across transportation organizations or programs |
| Often classified in 2210 | Can be classified in 1801 or another series |
| Technical controls and system risk are central | Analysis, compliance, policy and stakeholder coordination may be central |
| Works with system owners, engineers and IT operations | Works with transportation operators, regulators and security partners |
| Technical depth can be a primary qualification | Security-program and transportation knowledge can be equally important |
A candidate should not submit the same resume to both pathways without changing the evidence and terminology.
The Current 2210 Qualification Framework
OPM issued a competency-based qualification standard for series 2210 in April 2026.
The updated framework emphasizes demonstrated competencies and job-related assessment rather than relying only on a fixed education-versus-experience checklist.
Depending on grade and job analysis, competencies can include:
- attention to detail;
- customer service;
- interpersonal skills;
- reasoning;
- problem solving;
- teamwork;
- decision-making;
- information management;
- oral communication;
- technical competence; and
- additional cyber competencies established for the position.
Agency-added technical competencies can include areas such as:
- information systems and network security;
- computer network defense;
- risk management;
- security incident management;
- requirements analysis;
- security-control implementation; and
- vulnerability remediation.
The announcement explains how TSA is applying the standard to the vacancy.
Skills-based assessment
Under a competency-based approach, an applicant may be evaluated through:
- structured questionnaires;
- technical interviews;
- work samples;
- job-knowledge assessments;
- writing exercises;
- situational judgment exercises;
- technical scenarios; or
- another validated assessment.
A certification list alone does not demonstrate proficiency.
Qualifications for 1801 Cyber Roles
Series 1801 covers broad inspection, investigation, enforcement and compliance work for which another more specific series is not controlling.
A TSA cyber vacancy in 1801 can require specialized experience involving:
- transportation cybersecurity;
- security-policy analysis;
- compliance programs;
- risk assessments;
- stakeholder coordination;
- regulatory implementation;
- protective-security programs;
- incident analysis;
- program evaluation; or
- executive briefing.
Do not assume that an 1801 vacancy uses the 2210 qualification standard.
Cybersecurity Certifications
Certifications can strengthen an application when they match the job.
Examples can include credentials related to:
- information security;
- cloud security;
- network security;
- audit and controls;
- incident response;
- risk management;
- governance;
- digital forensics; or
- project management.
However:
- no single certification qualifies every TSA cyber applicant;
- a certification does not replace specialized experience when the vacancy requires it;
- an expired credential should not be described as current;
- entry-level certificates do not prove senior architecture capability; and
- offensive-security credentials do not authorize access to systems.
List the issuing organization, credential status and relevant dates.
Education
Education requirements vary by series, level and qualification route.
Relevant fields can include:
- cybersecurity;
- computer science;
- information technology;
- information systems;
- software engineering;
- computer engineering;
- mathematics;
- statistics;
- operations research;
- public policy;
- homeland security; and
- transportation or infrastructure security.
A degree can support qualification, but many experienced positions require direct specialized experience. Conversely, experience using ordinary office software does not establish cybersecurity competence.
Submit transcripts when the announcement requires them.
Federal Resume Evidence
A strong cyber resume should show authorized work, personal responsibility and measurable outcomes.
For 2210 roles, evidence can include:
- systems or environments secured;
- security controls implemented;
- risk assessments completed;
- vulnerabilities prioritized and remediated;
- incidents coordinated;
- authorizations supported;
- policies developed;
- architecture reviewed;
- audit findings resolved;
- cloud or network environments supported;
- technical teams advised; and
- service or risk improvements achieved.
For 1801 roles, evidence can include:
- transportation sectors supported;
- security programs evaluated;
- regulatory or compliance work performed;
- risk information analyzed;
- stakeholders coordinated;
- reports and briefings produced;
- corrective actions tracked;
- policy implementation supported; and
- program outcomes improved.
Include:
- employer;
- job title;
- dates;
- hours worked per week;
- scope;
- tools or frameworks where appropriate;
- level of independence;
- results; and
- federal series, grade or TSA band when applicable.
Protect Sensitive Information in the Resume
Do not include:
- exploitable vulnerabilities;
- IP addresses;
- network diagrams;
- credentials;
- authentication details;
- protected incident timelines;
- sensitive transportation-system configurations;
- classified information;
- Sensitive Security Information;
- procurement-sensitive architecture; or
- names of individuals without a legitimate reason.
Describe the problem, your authorized role, the method at an appropriate level and the result.
Interview Preparation
Prepare examples involving:
- prioritizing vulnerabilities with limited resources;
- explaining risk to a nontechnical executive;
- responding to a suspected incident;
- resolving disagreement over a security control;
- balancing mission availability and security;
- correcting a weak access-control process;
- evaluating compliance evidence;
- coordinating across organizations;
- writing a defensible recommendation;
- handling incomplete information;
- learning an unfamiliar technology; and
- identifying an error in your own analysis.
A strong response explains:
- the authorized mission context;
- the risk or requirement;
- your individual role;
- the analysis performed;
- the decision or recommendation;
- how sensitive information was protected; and
- the measurable result.
Clearance, Suitability and Sensitive Positions
Cyber positions can involve access to sensitive systems, security information or regulated-industry data.
The announcement can require:
- a background investigation;
- suitability or fitness review;
- eligibility for a security clearance;
- access to classified information;
- drug testing;
- financial disclosure; or
- continued reporting obligations.
A “clearance required” field should not be replaced with assumptions based on the job title. Some cyber positions are sensitive without requiring the same clearance level as another vacancy.
Read the TSA security-clearance guide.
Cybersecurity Versus General IT
Not every 2210 position is a cybersecurity job.
General IT work can focus on:
- systems administration;
- applications;
- enterprise architecture;
- data management;
- customer support;
- telecommunications;
- program management;
- policy and planning; or
- IT acquisition.
Cybersecurity focuses more directly on confidentiality, integrity, availability, risk and protection against unauthorized activity.
Read the TSA Information Technology Specialist guide for the broader 2210 occupation.
Cybersecurity Versus Intelligence Analysis
A cyber intelligence role can analyze threat information, but Intelligence Analyst is a separate occupational pathway.
Cybersecurity work can include technical or compliance action. Intelligence work focuses on collecting, evaluating and communicating intelligence within authorized frameworks.
Do not claim intelligence-community experience merely because you reviewed security alerts.
Cybersecurity Versus Physical Security
Cybersecurity protects information systems, networks, data and operational technology. Physical Security Specialist work protects facilities, people and physical assets.
The two can overlap in converged-security programs, but they remain distinct disciplines.
Can a TSO Move Into Cybersecurity?
Yes, after developing relevant technical or program qualifications.
Useful steps can include:
- formal coursework;
- a degree or certificate program;
- authorized IT support experience;
- cybersecurity labs using legal training environments;
- federal developmental programs;
- security-policy assignments;
- risk or compliance work;
- technical writing;
- project experience; and
- certifications matched to the target role.
Checkpoint experience provides TSA mission context, but it does not by itself prove 2210 or cyber-focused 1801 competence.
Pay, Location and Telework
Pay depends on:
- occupational series;
- TSA band;
- locality;
- duty station;
- technical depth;
- supervisory responsibility;
- clearance requirements; and
- the final offer.
Cyber work can be located at headquarters, technical offices or field locations. Some positions can be telework eligible. Protected systems, operational coordination, classified work and incident response can require onsite attendance.
Telework eligibility does not mean fully remote.
Common Application Mistakes
Applicants often:
- treat every cyber job as 2210;
- ignore an 1801 qualification standard;
- use one generic resume for internal IT and transportation-sector roles;
- list tools without explaining outcomes;
- rely on certifications alone;
- describe unauthorized access as experience;
- reveal vulnerabilities or protected architecture;
- claim a clearance they do not hold;
- copy the vacancy;
- omit hours worked per week;
- assume all cyber positions are remote; or
- confuse cyber, intelligence, physical security and law enforcement.
Frequently Asked Questions
What series are TSA cybersecurity jobs?
Common pathways include 2210 Information Technology Management and 1801 transportation-security cyber roles.
Did the 2210 qualification standard change?
Yes. OPM issued a competency-based 2210 qualification standard in April 2026. The vacancy explains how it is applied.
Is a cybersecurity degree required?
Not universally. Qualification depends on the series, grade, competencies and announcement.
Are certifications required?
Only when the vacancy or agency requirement says so. Relevant certifications can still strengthen an application.
Is a clearance always required?
No. Clearance and sensitivity requirements are position specific.
Can offensive-security experience qualify?
Authorized testing can be relevant. Unauthorized access should never be presented as legitimate experience.
Can a TSO move into cybersecurity?
Yes, after developing the technical or cyber-program qualifications required by the vacancy.
Next steps in your TSA search
Compare Security careers, Mission Support careers and law-enforcement careers. TSO candidates should read the TSA test-prep hub and optional JobTestPrep TSA PrepPack.