IT Specialist; INFOSEC)
Listed on 2026-10-04
-
IT/Tech
Cybersecurity, Information Security & Data Protection
The EEOC IT Specialist (INFOSEC) role supports the agency’s information security program within the Cybersecurity and Risk Management Division (CRMD). In this position, you will advise leadership on federal INFOSEC requirements, help manage cyber risk, and develop and maintain authorization documentation needed to support an Authorization to Operate (ATO). This onsite role is located in Washington, DC
, with a salary range of USD 143,913 to 187,093 per year (GS-2210-14).
- Advise leadership on federal information security laws, regulations, standards, and emerging requirements
, and contribute to the development and implementation of agency-level IT security policies and directives. - Monitor and report on cybersecurity threats, vulnerabilities, and mitigation efforts
, including reviewing and updating Plans of Action and Milestones (POA and M) and briefing the Chief Information Security Officer (CISO) on risk status. - Develop, review, and maintain security authorization documentation, including System Security Plans (SSP),
Contingency Plans (CP),
Risk Assessments (RA), and other materials required to obtain or maintain an ATO
. - Perform technology assessments, trend analyses, feasibility studies, and acquisition support activities such as drafting specifications, reviewing contract deliverables, and recommending courses of action to support cybersecurity objectives.
- Provide operational support by resolving assigned incidents, responding to staff inquiries, tracking fulfillment requests, coordinating with technical teams, and ensuring work is documented in agency management tools.
You will apply technical expertise and cybersecurity frameworks aligned to major INFOSEC initiatives, including work related to secure cloud operations and sustainment, SOC/SIEM/SOAR improvements for continuous monitoring (CONMON), and Dev Sec Ops maturity through App Sec testing and continuous event monitoring.
- Guide secure cloud operations by identifying and mitigating technical threat vectors and APT activity, and implementing remediation to reduce attack surface.
- Enhance cybersecurity operations through improved SOC processes, SIEM and SOAR process maturity, and sustaining a hardened security posture.
- Advance DEVSECOPS maturity by implementing automated and manual App Sec testing (
SAST, DAST, IAST, SCA, container scanning
) and supporting secure coding and hardened deployment standards. - Use scripting and automation (
Python, Bash, Golang
) and cybersecurity frameworks (
NIST, OWASP, CIS
) to support secure execution practices. - Lead INFOSEC initiatives balancing workload across projects and incidents, including efforts in GRC, SOC operations, FedRAMP activities
, and role-based enterprise guidance alongside blue/red/purple team exercises. - Oversee federal security compliance by interpreting INFOSEC laws and FISMA regulations, managing POA&Ms and vulnerability remediation, and evaluating controls and cybersecurity supply chain risk management (C-SCRM) across systems.
- U.S. Citizen or National
. - Selective Service registration
:
Males born after 12-31-59 must be registered (or exempt). - Suitable for federal employment
, determined by a background investigation. - May be required to successfully complete a probationary period.
- IT-related experience
, which may be demonstrated by paid or unpaid experience and/or completion of specific, intensive training (for example, IT certification), as appropriate. - Demonstrated each of the four competencies:
Attention to Detail
, Customer Service
, Oral Communication
, and Problem Solving
. - For GS-14:
one year of specialized experience equivalent to the GS-13 level in federal service.
This position does not have an education qualification…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).