An application made for this job — a tailored resume and cover letter that speak straight to the posting.
The Centers for Medicare & Medicaid Services (CMS) within the Department of Health and Human Services seeks an IT Specialist (Security) at the GS-2210-13 level to review, analyze, develop, publish, promote, and implement enterprise-wide IT security policies and SDLC standards.
This role requires applying security policies and frameworks, integrating security controls into DevSecOps pipelines, and coordinating third-party security deliverables.
This position is located in the Department of Health & Human Services (HHS), Centers for Medicare & Medicaid Services (CMS), Office of Communications(OC), Web & Emerging Technologies Group (WETG), Division of Website Operations (DWO).
As a IT Specialist (Security), GS-2210-13, you will review, analyze, develop, publish, promote, and implement awareness of enterprise-wide HHS information technology (IT) security and/or system development life cycle (SDLC) policies and standards.
ALL QUALIFICATION REQUIREMENTS MUST BE MET BY THE CLOSING DATE OF THIS ANNOUNCEMENT.
Your resume (limited to no more than 2 pages) must include detailed information as it relates to the responsibilities and specialized experience for this position. Evidence of copying and pasting directly from the vacancy announcement without clearly documenting supplemental information to describe your experience will result in an ineligible rating. This will prevent you from being considered further.
There is a BASIC REQUIREMENT AND MINIMUM QUALIFICATION REQUIREMENT for this position. You must meet both requirements.
BASIC REQUIREMENT: You must have IT-related experience, at the GS-12 grade level in the federal government, demonstrating each of the four competencies listed:
AND
MINIMUM QUALIFICATION: In order to qualify for the GS-13, you must meet the following: You must demonstrate in your resume at least one year (52 weeks) of qualifying specialized experience equivalent to the GS-12 grade level in the Federal government, obtained in either the private or public sector, to include: 1) Applying security policies, standards, and risk management frameworks (such as NIST SP 800-53, FISMA, FedRAMP, or equivalent industry frameworks like ISO 27001 or SOC 2) to assess, authorize, and continuously monitor the security posture of information systems; 2) Overseeing or advising on the integration of security controls into a DevSecOps pipeline, including compliance-as-code, automated vulnerability scanning, and automated generation of security control evidence; 3) Managing or coordinating third-party contractor or vendor security deliverables, including reviewing security assessment reports, tracking remediation of findings, and enforcing compliance with security requirements and timelines; AND 4) Leading or contributing to incident response activities, security control assessments, and the development or maintenance of system security documentation (such as System Security Plans, Contingency Plans, or Risk Assessment Reports).
Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional, philanthropic, religious, spiritual, community, student, social). Volunteer work helps build critical competencies, knowledge, and skills, and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.