IT Specialist (Security)

Centers-For-Medicare-and-Medicaid-Services

Woodlawn (MD)

On-site

USD 108,000 - 154,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

The Centers for Medicare & Medicaid Services (CMS) within the Department of Health and Human Services seeks an IT Specialist (Security) at the GS-2210-13 level to review, analyze, develop, publish, promote, and implement enterprise-wide IT security policies and SDLC standards.

This role requires applying security policies and frameworks, integrating security controls into DevSecOps pipelines, and coordinating third-party security deliverables.

Qualifications

  • IT-related experience at GS-12 level in federal government.
  • Applying security policies, standards, and risk management frameworks (e.g., NIST SP 800-53, FISMA, FedRAMP).
  • Experience with DevSecOps pipelines and compliance-as-code.
  • Managing third-party security deliverables and remediation tracking.
  • Contributing to incident response activities and system security documentation.

Responsibilities

  • Review, analyze, develop, publish, promote, and implement enterprise-wide IT security policies and SDLC standards.
  • Provide guidance on security governance and risk management across systems.
  • Lead or support incident response and security control assessments.
  • Develop or maintain system security documentation (SSPs, Contingency Plans, Risk Assessments).

Skills

Attention to Detail
Customer Service
Oral Communication
Problem Solving

Job description

This position is located in the Department of Health & Human Services (HHS), Centers for Medicare & Medicaid Services (CMS), Office of Communications(OC), Web & Emerging Technologies Group (WETG), Division of Website Operations (DWO).

As a IT Specialist (Security), GS-2210-13, you will review, analyze, develop, publish, promote, and implement awareness of enterprise-wide HHS information technology (IT) security and/or system development life cycle (SDLC) policies and standards.

ALL QUALIFICATION REQUIREMENTS MUST BE MET BY THE CLOSING DATE OF THIS ANNOUNCEMENT.

Your resume (limited to no more than 2 pages) must include detailed information as it relates to the responsibilities and specialized experience for this position. Evidence of copying and pasting directly from the vacancy announcement without clearly documenting supplemental information to describe your experience will result in an ineligible rating. This will prevent you from being considered further.

There is a BASIC REQUIREMENT AND MINIMUM QUALIFICATION REQUIREMENT for this position. You must meet both requirements.

BASIC REQUIREMENT: You must have IT-related experience, at the GS-12 grade level in the federal government, demonstrating each of the four competencies listed:

  • (1) Attention to Detail - Is thorough when performing work and conscientious about attending to detail.
  • (2) Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services.
  • (3) Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately.
  • (4) Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations.

AND

MINIMUM QUALIFICATION: In order to qualify for the GS-13, you must meet the following: You must demonstrate in your resume at least one year (52 weeks) of qualifying specialized experience equivalent to the GS-12 grade level in the Federal government, obtained in either the private or public sector, to include: 1) Applying security policies, standards, and risk management frameworks (such as NIST SP 800-53, FISMA, FedRAMP, or equivalent industry frameworks like ISO 27001 or SOC 2) to assess, authorize, and continuously monitor the security posture of information systems; 2) Overseeing or advising on the integration of security controls into a DevSecOps pipeline, including compliance-as-code, automated vulnerability scanning, and automated generation of security control evidence; 3) Managing or coordinating third-party contractor or vendor security deliverables, including reviewing security assessment reports, tracking remediation of findings, and enforcing compliance with security requirements and timelines; AND 4) Leading or contributing to incident response activities, security control assessments, and the development or maintenance of system security documentation (such as System Security Plans, Contingency Plans, or Risk Assessment Reports).

Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional, philanthropic, religious, spiritual, community, student, social). Volunteer work helps build critical competencies, knowledge, and skills, and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Specialist (INFOSEC)
IT Specialist (INFOSEC)

Towson • Rockville (MD), Northern (KY)

On-site
USD 120,000 - 150,000
Foreign Investment Risk Compliance Monitoring Program Lead
Foreign Investment Risk Compliance Monitoring Program Lead

US Cybersecurity and Infrastructure Security Agency • Arlington (VA)

On-site
USD 110,000 - 140,000
IT Program Manager (Data Management)
IT Program Manager (Data Management)

Centers-For-Medicare-and-Medicaid-Services • Woodlawn (MD)

On-site
USD 90,000 - 120,000
Cybersecurity Technical Writer
Cybersecurity Technical Writer

US Cybersecurity and Infrastructure Security Agency • Arlington (VA)

On-site
USD 90,000 - 120,000
Supervisory IT Specialist (INFOSEC)
Supervisory IT Specialist (INFOSEC)

US Office of Inspector General • San Francisco (CA)

On-site
USD 120,000 - 150,000
IT Specialist (INFOSEC)
IT Specialist (INFOSEC)

US Arlington National Cemetery • Arlington (VA)

On-site
USD 120,000 - 160,000
IT CYBERSECURITY SPECIALIST (INFOSEC) - 887210000
IT CYBERSECURITY SPECIALIST (INFOSEC) - 887210000

Caecommunity • Fort Lee (NJ), Northern (KY)

Hybrid
USD 90,000 - 120,000
IT CYBERSECURITY SPECIALIST (INFOSEC) (DIRECT HIRE)
IT CYBERSECURITY SPECIALIST (INFOSEC) (DIRECT HIRE)

GRC Careers, LLC • United States

On-site
USD 110,000 - 140,000
IT CYBERSECURITY SPECIALIST (INFOSEC)
IT CYBERSECURITY SPECIALIST (INFOSEC)

Defense Contract Management Agency International • United States

On-site
USD 80,000 - 110,000
Supervisory IT Specialist (Policy/Planning)
Supervisory IT Specialist (Policy/Planning)

US Deputy Assistant Secretary for Information and Technology • Austin (TX)

On-site
USD 90,000 - 120,000