IT Security Specialist — DevSecOps & Risk Lead

Centers-For-Medicare-and-Medicaid-Services

Woodlawn (MD)

On-site

USD 108,000 - 154,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

The Centers for Medicare & Medicaid Services (CMS) within the Department of Health and Human Services seeks an IT Specialist (Security) at the GS-2210-13 level to review, analyze, develop, publish, promote, and implement enterprise-wide IT security policies and SDLC standards.

This role requires applying security policies and frameworks, integrating security controls into DevSecOps pipelines, and coordinating third-party security deliverables.

Qualifications

  • IT-related experience at GS-12 level in federal government.
  • Applying security policies, standards, and risk management frameworks (e.g., NIST SP 800-53, FISMA, FedRAMP).
  • Experience with DevSecOps pipelines and compliance-as-code.
  • Managing third-party security deliverables and remediation tracking.
  • Contributing to incident response activities and system security documentation.

Responsibilities

  • Review, analyze, develop, publish, promote, and implement enterprise-wide IT security policies and SDLC standards.
  • Provide guidance on security governance and risk management across systems.
  • Lead or support incident response and security control assessments.
  • Develop or maintain system security documentation (SSPs, Contingency Plans, Risk Assessments).

Skills

Attention to Detail
Customer Service
Oral Communication
Problem Solving

Job description

The Centers for Medicare & Medicaid Services (CMS) within the Department of Health and Human Services seeks an IT Specialist (Security) at the GS-2210-13 level to review, analyze, develop, publish, promote, and implement enterprise-wide IT security policies and SDLC standards.

This role requires applying security policies and frameworks, integrating security controls into DevSecOps pipelines, and coordinating third-party security deliverables.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SaaS Cloud Security Specialist | FedRAMP & NIST Telework
SaaS Cloud Security Specialist | FedRAMP & NIST Telework

Centers for Medicare & Medicaid Services • Maryland

Hybrid
USD 116,000 - 158,000
IT Cybersecurity Specialist (Security)
IT Cybersecurity Specialist (Security)

Centers for Medicare & Medicaid Services • Maryland

On-site
USD 116,000 - 158,000
IT Specialist (Security)
IT Specialist (Security)

Centers-For-Medicare-and-Medicaid-Services • Woodlawn (MD)

On-site
USD 108,000 - 154,000
IT Security Governance Officer
IT Security Governance Officer

Commence, LLC • Virginia Beach (VA)

On-site
USD 120,000 - 180,000
IT Specialist (INFOSEC)
IT Specialist (INFOSEC)

Towson • Rockville (MD), Northern (KY)

On-site
USD 120,000 - 150,000
Senior InfoSec Specialist: Policy, Risk and Compliance
Senior InfoSec Specialist: Policy, Risk and Compliance

Southern Arkansas University • Rockville (MD), Northern (KY)

Hybrid
USD 110,000 - 140,000
Senior IT Security & Governance Supervisor
Senior IT Security & Governance Supervisor

US Office of Inspector General • San Francisco (CA)

On-site
USD 120,000 - 150,000
Data Management IT Program Manager
Data Management IT Program Manager

Centers-For-Medicare-and-Medicaid-Services • Woodlawn (MD)

On-site
USD 90,000 - 120,000
Cloud Security Operations Specialist
Cloud Security Operations Specialist

Provider Resources, LLC • Erie

On-site
USD 110,000 - 140,000
Medical Insurance
Dental Insurance
Vision Insurance
+2
Healthcare IT Security Governance Leader
Healthcare IT Security Governance Leader

Commence, LLC • Virginia Beach (VA)

On-site
USD 120,000 - 180,000