Apply with hirly
IT Specialist (Security)
Centers for Medicare & Medicaid Services · Woodlawn, Maryland, United States
Upload your resume to see how well you match this job — free, in seconds, no account needed.
Your resume is used only to score it against this job. If you don't create an account, it is deleted within 24 hours.
Already have an account? Sign in to see your saved application
Summary This position is located in the Department of Health & Human Services (HHS), Centers for Medicare & Medicaid Services (CMS), Office of Communications(OC), Web & Emerging Technologies Group (WETG), Division of Website Operations (DWO). As a IT Specialist (Security), GS-2210-13, you will review, analyze, develop, publish, promote, and implement awareness of enterprise-wide HHS information technology (IT) security and/or system development life cycle (SDLC) policies and standards. Duties
- Acts as ISSO for assigned WETG systems, ensuring ADOs and contractors meet security and risk framework requirements (NIST 800-53, FISMA, FedRAMP) across the authorization lifecycle, including control testing, risk decisions, and threat modeling.
- Direct integration of security controls into the DevSecOps pipeline, guiding contractors on compliance-as-code (e.g., InSpec), automated vulnerability scanning, and evidence generation, while verifying automated results truly reflect compliance.
- Oversee contractor and vendor security performance by assessing security impacts of changes, reviewing assessment reports, tracking POA-Ms to closure, enforcing CMS testing standards, and holding ADOs accountable to contract security commitments.
- Drive incident response and continuous monitoring, reporting security incidents per CMS Incident Handling Guidelines, partnering with CMS security operations, and ensuring 24x7x365 monitoring coverage for assigned systems.
- Keep security documentation current, including System Security Plans, Risk Assessment Reports, and Contingency Plans, and coordinates annual assessments and penetration testing to support Authority to Operate (ATO) decisions. Qualifications
All Qualification Requirements Must Be Met by the Closing Date
Of This Announcement.
Your resume (limited to no more than 2 pages) must include detailed information as it relates to the responsibilities and specialized experience for this position. Evidence of copying and pasting directly from the vacancy announcement without clearly documenting supplemental information to describe your experience will result in an ineligible rating. This will prevent you from being considered further. There is a
Basic Requirement and Minimum Qualification Requirement
for this position. You must meet both requirements. BASIC REQUIREMENT: You must have IT-related experience, at the GS-12 grade level in the federal government, demonstrating each of the four competencies listed: I have IT-related experience, demonstrated by paid or unpaid experience obtained in either the private or public sector and/or completion of specific, intensive training that demonstrates that I possess each of the following four competencies: (1) Attention to Detail
- Is thorough when performing work and conscientious about attending to detail. (2) Customer Service
- Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. (3) Oral Communication
- Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. (4) Problem Solving
- Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations.
And Minimum
QUALIFICATION: In order to qualify for the GS-13, you must meet the following: You must demonstrate in your resume at least one year (52 weeks) of qualifying specialized experience equivalent to the GS-12 grade level in the Federal government, obtained in either the private or public sector, to include: 1) Applying security policies, standards, and risk management frameworks (such as
Nist Sp
800-53, FISMA, FedRAMP, or equivalent industry frameworks like ISO 27001 or SOC 2) to assess, authorize, and continuously monitor the security posture of information systems; 2) Overseeing or advising on the integration of security controls into a DevSecOps pipeline, including compliance-as-code, automated vulnerability scanning, and automated generation of security control evidence; 3) Managing or coordinating third-party contractor or vendor security deliverables, including reviewing security assessment reports, tracking remediation of findings, and enforcing compliance with security requirements and timelines; AND 4) Leading or contributing to incident response activities, security control assessments, and the development or maintenance of system security documentation (such as System Security Plans, Contingency Plans, or Risk Assessment Reports). Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional, philanthropic, religious, spiritual, community, student, social). Volunteer work helps build critical competencies, knowledge, and skills, and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.