USA remote
IT Specialist (INFOSEC)
About this role
IT-related experience; experience may be demonstrated by paid or unpaid experience and/or completion of specific, intensive training (for example, IT certification), as appropriate. Experience must have demonstrated each of the four competencies listed below. Attention to Detail - Is thorough when performing work and conscientious about attending to detail. Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services.
Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations.
For the GS-14: You must have one year of specialized experience equivalent to the GS-13 level in federal service. Specialized experience must include demonstrable experience: Guides secure cloud operations and sustainment by ensuring consistent approaches for cloud services, identifying and mitigating technical threat vectors and APT activity, and implementing practical remediation to reduce attack surface. Enhances cybersecurity operations through improved SOC, SIEM, and SOAR processes, strengthening continuous monitoring (CONMON), maturing operational procedures, and sustaining a hardened security posture.
Advances DEVSECOPS maturity by implementing automated and manual AppSec testing (SAST, DAST, IAST, SCA, container scanning), implementing and enforcing secure coding including hardened deployment standards, and continuously monitoring environments for cybersecurity events. Applies deep technical expertise in major cloud platforms, scripting/automation (Python, Bash, Golang), and cybersecurity frameworks (NIST, OWASP, CIS), including hands-on execution of Zero Trust pillars and secure AI practices.