IT Cybersecurity Specialist (Security)

Centers for Medicare & Medicaid Services

United States

On-site

USD 100,000 - 140,000

Full time

9 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Centers for Medicare & Medicaid Services (CMS) seeks an IT Cybersecurity Specialist (Security) at GS-2210-13 to secure SaaS platforms and cloud-hosted business applications used across CMS.

The role requires applying FISMA/NIST RMF, developing automated workflows for security findings, and implementing SSPM/CASB technologies. This position emphasizes attention to detail, customer service, oral communication, and problem solving to protect CMS information assets.

Qualifications

  • Experience securing SaaS platforms and cloud-hosted applications using SSPM or CASB to identify misconfigurations, policy violations, and security risks.
  • Experience applying FISMA, FedRAMP, or NIST RMF to assess and monitor cloud environments.
  • Developing and integrating automated workflows, scripts, or security tools to manage security findings across cloud or SaaS environments.
  • Demonstrated ability to meet broad competencies: attention to detail, customer service, oral communication, and problem solving.

Responsibilities

  • Secure SaaS platforms and cloud-hosted business applications used across CMS.
  • Apply federal cybersecurity frameworks to assess compliance posture of cloud environments.
  • Develop and integrate automated workflows to manage security findings across cloud environments.

Skills

SaaS security
CASB
SSPM
NIST RMF
Automation scripts
Cloud security
FedRAMP
Attention to Detail
Customer Service
Oral Communication
Problem Solving

Tools

Microsoft 365
Salesforce
ServiceNow

Job description

This position is located in the Department of Health & Human Services (HHS), Centers for Medicare & Medicaid Services (CMS), Office of Information Technology (OIT), Information Security and Privacy Group (ISPG), Division of Security and Privacy Compliance (DSPC). As a IT Cybersecurity Specialist (Security), GS-2210-13, you will secure Software-as-a-Service (SaaS) platforms and cloud-hosted business applications utilized throughout CMS.

Qualifications: ALL QUALIFICATION REQUIREMENTS MUST BE MET BY THE CLOSING DATE OF THIS ANNOUNCEMENT. Your resume (limited to no more than 2 pages) must include detailed information as it relates to the responsibilities and specialized experience for this position. Evidence of copying and pasting directly from the vacancy announcement without clearly documenting supplemental information to describe your experience will result in an ineligible rating. This will prevent you from being considered further. There is a Basic Requirement and Minimum Qualification Requirement for this position. You must meet both requirements. Basic Requirement: You must have IT related experience, demonstrated by paid or unpaid experience obtained in either the private or public sector, and/or completion of specific, intensive training that demonstrates that I possess each of the following four competencies: (1) Attention to Detail - Is thorough when performing work and conscientious about attending to detail. (2) Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. (3) Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. (4) Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. AND In order to qualify for the GS-13, you must meet the following: You must demonstrate in your resume at least one year (52 weeks) of qualifying specialized experience equivalent to the GS-12 grade level in the Federal government, obtained in either the private or public sector, to include: 1) Securing SaaS platforms and cloud-hosted applications (e.g., Microsoft 365, Salesforce, ServiceNow) using SaaS Security Posture Management (SSPM) or Cloud Access Security Broker (CASB) technologies to identify issues - such as misconfigurations, policy violations, and security risks; AND 2) Applying federal cybersecurity frameworks - such as Federal Information Security Modernization Act (FISMA), Federal Risk and Authorization Management Program (FedRAMP), or National Institute of Standards and Technology Risk Management Framework (NIST RMF) - to assess and monitor the compliance posture of cloud environments; AND 3) Developing and integrating automated workflows, scripts, or security tools to manage security findings across a cloud or SaaS environment. Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional, philanthropic, religious, spiritual, community, student, social). Volunteer work helps build critical competencies, knowledge, and skills, and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Cybersecurity Specialist (Security)
IT Cybersecurity Specialist (Security)

U.S. Department of Health and Human Services • Woodlawn (MD)

On-site
USD 110,000 - 140,000
IT Specialist (INFOSEC)
IT Specialist (INFOSEC)

Southern Arkansas University • Rockville (MD), Northern (KY)

Hybrid
USD 110,000 - 140,000
IT Specialist (INFOSEC)
IT Specialist (INFOSEC)

Towson • Rockville (MD), Northern (KY)

Hybrid
USD 120,000 - 150,000
IT Cybersecurity Specialist (Security)
IT Cybersecurity Specialist (Security)

Centers for Medicare & Medicaid Services • Maryland

Hybrid
USD 116,000 - 158,000
IT Cybersecurity Specialist (PLCYPN-INFOSEC)
IT Cybersecurity Specialist (PLCYPN-INFOSEC)

U.S. Coast Guard • Kearneysville (WV)

On-site
USD 120,000 - 160,000
Cloud SaaS Security Specialist
Cloud SaaS Security Specialist

Centers for Medicare & Medicaid Services • United States

On-site
USD 100,000 - 140,000
Chief Architect for Cyber Services
Chief Architect for Cyber Services

US Cybersecurity and Infrastructure Security Agency • Arlington (VA)

On-site
USD 140,000 - 190,000
SaaS Cloud Security & Compliance Specialist
SaaS Cloud Security & Compliance Specialist

U.S. Department of Health and Human Services • Woodlawn (MD)

On-site
USD 110,000 - 140,000
SUPV IT CYBERSECURITY SPECIALIST (PLCYPLN/INFOSEC)
SUPV IT CYBERSECURITY SPECIALIST (PLCYPLN/INFOSEC)

Defense Information Systems Agency • Fort Meade (MD)

On-site
USD 110,000 - 140,000
Lead IT Cybersecurity Specialist
Lead IT Cybersecurity Specialist

Centers for Disease Control and Prevention • Atlanta (GA)

On-site
USD 120,000 - 144,000