IT Specialist (INFOSEC)
Job Description
The EEOC IT Specialist (INFOSEC) role supports the agency’s information security program within the Cybersecurity and Risk Management Division (CRMD). In this position, you will advise leadership on federal INFOSEC requirements, help manage cyber risk, and develop and maintain authorization documentation needed to support an Authorization to Operate (ATO). This onsite role is located in Washington, DC, with a salary range of USD 143,913 to 187,093 per year (GS-2210-14).
What you’ll do
- Advise leadership on federal information security laws, regulations, standards, and emerging requirements, and contribute to the development and implementation of agency-level IT security policies and directives.
- Monitor and report on cybersecurity threats, vulnerabilities, and mitigation efforts, including reviewing and updating Plans of Action and Milestones (POA and M) and briefing the Chief Information Security Officer (CISO) on risk status.
- Develop, review, and maintain security authorization documentation, including System Security Plans (SSP), Contingency Plans (CP), Risk Assessments (RA), and other materials required to obtain or maintain an ATO.
- Perform technology assessments, trend analyses, feasibility studies, and acquisition support activities such as drafting specifications, reviewing contract deliverables, and recommending courses of action to support cybersecurity objectives.
- Provide operational support by resolving assigned incidents, responding to staff inquiries, tracking fulfillment requests, coordinating with technical teams, and ensuring work is documented in agency management tools.
Security and engineering focus
You will apply technical expertise and cybersecurity frameworks aligned to major INFOSEC initiatives, including work related to secure cloud operations and sustainment, SOC/SIEM/SOAR improvements for continuous monitoring (CONMON), and DevSecOps maturity through AppSec testing and continuous event monitoring.
- Guide secure cloud operations by identifying and mitigating technical threat vectors and APT activity, and implementing remediation to reduce attack surface.
- Enhance cybersecurity operations through improved SOC processes, SIEM and SOAR process maturity, and sustaining a hardened security posture.
- Advance DEVSECOPS maturity by implementing automated and manual AppSec testing (SAST, DAST, IAST, SCA, container scanning) and supporting secure coding and hardened deployment standards.
- Use scripting and automation (Python, Bash, Golang) and cybersecurity frameworks (NIST, OWASP, CIS) to support secure execution practices.
- Lead INFOSEC initiatives balancing workload across projects and incidents, including efforts in GRC, SOC operations, FedRAMP activities, and role-based enterprise guidance alongside blue/red/purple team exercises.
- Oversee federal security compliance by interpreting INFOSEC laws and FISMA regulations, managing POA&Ms and vulnerability remediation, and evaluating controls and cybersecurity supply chain risk management (C-SCRM) across systems.
Required qualifications
- U.S. Citizen or National.
- Selective Service registration: Males born after 12-31-59 must be registered (or exempt).
- Suitable for federal employment, determined by a background investigation.
- May be required to successfully complete a probationary period.
- IT-related experience, which may be demonstrated by paid or unpaid experience and/or completion of specific, intensive training (for example, IT certification), as appropriate.
- Demonstrated each of the four competencies: Attention to Detail, Customer Service, Oral Communication, and Problem Solving.
- For GS-14: one year of specialized experience equivalent to the GS-13 level in federal service.
Education
This position does not have an education qualification requirement. A combination of academic education and industry-recognized certifications, such as CISSP, CCSP, and/or SANS certification or higher, is preferred but not required.
Additional information
- Relocation expenses will not be paid.
- You will be expected to report to the duty station listed on this announcement.
- This announcement may be used to fill additional similar vacancies across EEOC.
- This job opportunity announcement uses the OPM Federal Wide Direct Hire Authority to recruit and appoint qualified candidates to certain positions in the competitive service.
- All federal employees are subject to conflict of interest statutes and the Standards of Ethical Conduct; this position may require a confidential financial disclosure report within 30 days of appointment.
- Personnel vetting is required, including a background investigation and enrollment in Continuous Vetting. The EEOC will also enroll the successful candidate into FBI Rap Back service for notification of criminal matters.
How you’ll be evaluated
You will be evaluated based on how well you meet the qualifications above. Competitive rating, ranking, and veterans’ preference procedures do not apply under the Direct Hire Authority.
Required documents
- Resume (NOT TO EXCEED 2 pages) showing work schedule, hours worked per week, dates of employment, and duties performed.
- Other supporting documents: CTAP/ICTAP documentation (if applicable) and/or current or former political appointee documentation (if applicable).
Failure to submit required documents may result in loss of consideration.