Sr. Cyber/Cloud Security Specialist
Job in
Washington, District of Columbia, 20022, USA
Listed on 2026-08-07
Listing for:
GovCIO
Full Time
position Listed on 2026-08-07
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, IT Project Manager
Job Description & How to Apply Below
Washington, Washington, DC
Suitability/Public Trust
Hybrid schedule
Cyber Security Services
OverviewGovCIO is currently hiring for a Sr. Cyber/Cloud Security Specialist to serve as Lead Information Technology Specialist (INFOSEC) and Cybersecurity Operations (SECOPS). This position will be hybrid, mostly remote with occasional onsite time as needed at EEOC HQ in Washington, DC.
Responsibilities- Serve as Lead Information Technology Specialist (INFOSEC), Cybersecurity Operations (SECOPS) responsible for contributing to the Agency’s IT Security Program, directs SECOPS, coordinates, and maintains inputs to EEOC's IT Security Program.
- Advise and support the Chief Information Security Officer (CISO) on developments in Cybersecurity, Information Security (INFOSEC) and IT Security emerging technical threat vectors, advanced persistent threats (APT), attack surface or weaknesses.
- Advise Agency-level technical implementation or introduction of policy and orders, proactively developing supporting documentation and drafts for implementation.
- Direct the Commission’s Cybersecurity Operations (SECOPS) cell, influencing a range of the EEOC’s operations that have a direct and corresponding impact to the mission of the EEOC and its critical infrastructure.
- Enable and administer incident handling (IH) and response (IR), security incident and event management (SIEM) dashboards, inputs, “playbooks” and metrics to achieve efficiency.
- Facilitate, coordinate, and administer EEOC's Cybersecurity Operations (SECOPS) in support of the Information Security (INFOSEC) Program, and aid Agency Information system security program officers. Ensure accurate and timely status reporting of SOC efficiency metrics and recommend necessary adjustments.
- Provide advising authority for threat, vulnerability, and configuration management; convey threat product recommendations to EEOC staff and customers; and provide expertise and insight to OIT for industry attack trends, mitigations, and active defenses.
Bachelor's degree in Cybersecurity, Information Assurance or Information Security with 12+ years (or commensurate experience)
Required Skills and Experience- Ability to guide discussions, support CISO decisions with or without team support and effectuate positive cybersecurity changes at varying levels—users, developers, system admins, Directors, Managers and Executives where necessary.
- Demonstrated experience as a SOC lead or Senior Team successfully engaging with managed security service providers (MSSP), Joint Cybersecurity external entities (e.g., CISA, CYBERCOM) on incident response (IR), weakness, incident handling (IH) and vulnerability management (VM), including mitigating actions to contain activity and facilitating forensics analysis.
- Documented applied theory as SOC Manager or Team lead conducting and guiding in-depth evaluations of current INFOSEC/IT Security/Cybersecurity tactics, techniques, and procedures, to include their effect on baseline configurations.
- Proficiency as a SOC manager or Senior Team lead providing cybersecurity hygiene and posture status, support debriefings and input in support of Governance, Risk, and Compliance (GRC) activities.
- Provide network subscribers with incident response support, including mitigating actions to contain activity and facilitating forensics analysis when necessary.
- Expertise conducting and guiding log-based and endpoint-based threat detection to detect and protect against threats from multiple sources.
- Security implementation techniques and strategies in web services.
- Solid understanding of securing web technology, Microsoft cloud (e.g., Azure, M365) security knowledge and demonstrable abilities.
- Skilled security evaluation of complex web portals (Java, APIs, Ruby, databases such as SQL, Oracle) using commercial or open-source tools such as SQLmap, mongoaudit.
- Expert knowledge of Web Application Attack and Audit Frameworks, including Security evaluation using NMAP, W3af.
- Execution of a continuous monitoring and remediation program using tools such as Azure Security Center, Defender for Cloud, NMAP, Wireshark, Qualys.
- Execution of an endpoint detection and response (EDR) remediation…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×