IT Cybersecurity Specialist (INFOSEC)
Job Description
The U.S. Department of Labor Office of the Chief Information Officer (OCIO) is seeking an IT Cybersecurity Specialist (INFOSEC) to support the Directorate of Cybersecurity under the Department’s Chief Information Security Officer (CISO). This onsite role in Salt Lake City, UT focuses on enterprise-wide risk management, security and privacy plan work, assessment activities, and administration of security training and awareness for unclassified and classified environments.
Role Overview
Working under the CISO, the Directorate of Cybersecurity manages enterprise-wide organizational risk for the operation of unclassified and classified information systems. The role contributes to governance, authorization-related work, security training and awareness program administration, and continuous improvement of secure system operations in response to evolving threats.
At the GS-14 level, major duties are similar to GS-13, but performed under less supervision.
Key Responsibilities
- Review and evaluate security control assessment findings to determine risk significance, recommend responses, and align remediation actions with organizational risk tolerance and priorities.
- Consult with authorizing officials by advising whether findings represent significant risk and require immediate remediation.
- Develop recommendations for initiating immediate remediation when findings can be easily corrected.
- Update assessment reports with results from reassessments while preserving the original findings.
- Revise and maintain security and privacy plans to reflect the current state of implemented controls, including updates from corrective actions by system owners or common control providers.
- Verify that system security and privacy documentation accurately describes all implemented controls, including compensating controls used to meet security requirements.
- Create comprehensive Plans of Action and Milestones (POA&Ms) including timelines, deadlines, methods, Measures of Effectiveness, and Measures of Success to track remediation progress.
- Administer the Agency Computer Security Awareness Training Program, ensuring mandatory compliance and providing specialized cybersecurity training tailored to workforce needs.
- Design, maintain, and implement the Department’s IT Security Training and Awareness Program in collaboration with departmental IT leaders and security professionals.
- Support secure system operations by proactively addressing security issues identified through continuous monitoring, control assessments, and incident response activities.
Location and Employment Details
- Location: Salt Lake City, UT (onsite)
- Salary: USD 106,437 to 197,200 per year
- Experience level: Minimum 1 year
- Direct Hire Authority: This position is filled under Direct Hire Authority.
- Telework: Not a remote position; the selectee reports to an assigned DOL office location regularly and may be eligible for telework as determined by management in accordance with DOL policy.
Basic and Required Qualifications
- Must be at least 16 years old.
- Must be a U.S. Citizen.
- Required to obtain and maintain the necessary security/investigation level.
- Education may not be substituted for experience at this level.
- Candidate must meet probationary period requirements if the requirement has not been met.
- Subject to pre-employment and random drug tests.
- IT-related experience demonstrating each competency: Attention to Detail, Customer Service, Decision Making, Information Management, Interpersonal Skills, Oral Communication, Problem Solving, Teamwork, Technical Competence.
Federal Service requirement: Applicants must have 52 weeks of specialized experience equivalent to at least the next lower grade level.
Specialized Experience (Qualification Criteria)
Applicants must meet 3 of the 4 statements below to be found qualified for the applicable grade:
- GS-13: Experience independently managing, implementing, and maintaining enterprise cloud services and cloud applications within a defined program area, ensuring reliability, availability, and compliance with organizational standards.
- GS-13: Experience applying expert-level knowledge of FISMA, the NIST Risk Management Framework (RMF), and related cybersecurity policies to assigned systems.
- GS-13: Experience conducting detailed analysis of vulnerability scan results, collaborating with system owners and technical teams to coordinate remediation, and verifying secure deployment of IT applications and systems.
- GS-13: Experience supporting the development, review, and implementation of agency security policies, procedures, and standards, ensuring program-level compliance with governance and regulatory mandates.
- GS-14: Experience with leading the management, implementation, and optimization of enterprise cloud services and cloud applications across multiple programs.
- GS-14: Experience serving as a technical authority on FISMA, NIST RMF, and federal cybersecurity policies; interpreting requirements for senior leadership, shaping organizational risk decisions, and developing enterprise-level compliance strategies.
- GS-14: Experience coordinating remediation efforts across cross-functional teams and ensuring secure deployment practices are integrated into enterprise processes.
- GS-14: Experience developing, implementing, and evaluating agency-wide security governance frameworks, and advising executives on security posture, compliance risks, and mitigation strategies.
Benefits
A comprehensive benefits package is available; eligibility depends on the type of position and whether full-time, part-time, or intermittent.
Who Can Apply
- Open to U.S. Citizens, Nationals, or individuals who owe allegiance to the U.S.
- Open to federal employees whose job, agency, or department was eliminated and who are eligible for priority under applicable programs.
- Also open to all U.S. Citizens and ICTAP/CTAP eligibles in the local commuting area.
Application, Screening, and Assessment Information
- Traditional rating and ranking of applications does not apply.
- Veterans’ preference does not apply; however, veterans are encouraged to apply.
- All personnel must undergo a background investigation for access to DOL facilities, systems, information, and/or classified materials before entering on duty.
- Candidates tentatively selected must submit to screening for illegal drug use prior to appointment.
- Fair Chance Act: agencies may not request criminal history information before a conditional offer of employment.
- USA Hire Assessments: applicants must meet or exceed the cut score for critical competencies and complete assessments if a URL is provided.
- Reasonable Accommodation (RA): requests may be made if a disability would interfere with completing USA Hire Competency Based Assessments.
Required Documents
- Resume: Required. Submit via USAJOBS or upload from your profile.
- To receive full consideration, list month/year and number of work hours for relevant and specialized experience on the resume.
- Veterans documents (if applicable): Submit DD214 (and related proof) for any claimed 5-point or 10-point preference.
- Displaced Employee Placement documents: Required only if requesting priority consideration under CTAP or ICTAP.
- Cover letter: Not mandatory and not used to verify experience (may be submitted).
- Do not upload password-protected documents.