USA remote
IT SPECIALIST (INFOSEC)
About this role
DS-04: Your resume must also demonstrate at least one year of specialized experience at or equivalent to the GS-09 grade level or DS-03 pay band in the Federal service or equivalent experience in the private or public sector. Specialized experience must demonstrate the following: Risk Management Framework (RMF): Assisting in the preparation, documentation, and review of Assessment and Authorization (A&A) packages across system life cycles; Security Controls & STIGs: Applying and validating Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) on operating systems, network devices, or applications; Vulnerability & Incident Management: Utilizing automated scanning tools (e.g., ACAS/Tenable Nessus) to evaluate vulnerabilities, track POA&Ms (Plan of Action and Milestones), and support incident response; Access & Compliance Monitoring: Performing routine audit log reviews, user access verification, and ensuring adherence to DoD information security instructions and directives.
DS-05: Your resume must also demonstrate at least one year of specialized experience at or equivalent to the GS-11 grade level or DS-04 pay band in the Federal service or equivalent experience in the private or public sector. Specialized experience must demonstrate the following: A&A Leadership & RMF Lifecycle: Leading, developing, and final-reviewing comprehensive Assessment & Authorization (A&A) packages through all steps of the Risk Management Framework (RMF) to achieve and sustain an Authority to Operate (ATO); Cybersecurity Policy & Governance: Authoring, interpreting, and enforcing DoD-wide and command-level INFOSEC policies, procedures, and system security plans (SSPs); Vulnerability & Risk Mitigation: Directing remediation efforts for complex vulnerabilities, analyzing STIG non-compliance impacts, and managing high-priority Plans of Action and Milestones (POA&Ms); Technical Oversight & Coordination: Providing senior advisory support to the Information System Security Manager (ISSM) and Authorizing Official (AO), while mentoring and guiding junior/journey-level ISSOs and technical teams.
Additional qualification information can be found from the following Office of Personnel Management website: https://www.opm.gov/policy-data-oversight/classification-qualifications/competency-based-policy/general-schedule/2200/2210-competency-based-policy/competency-based-qualification-standard/ https://www.opm.gov/policy-data-oversight/classification-qualifications/general-schedule-qualification-standards/2200/information-technology-it-management-series-2210-alternative-a/ Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., professional, philanthropic, religious, spiritual, community, student, social).