What are the responsibilities and job description for the IT Specialist (INFOSEC) position at Equal Employment Opportunity Commission?
As an IT Specialist (INFOSEC) at the GS-2210-14, you will be part of the Cybersecurity and Risk Management Division (CRMD), Office of the Chief Information Officer, U.S. Equal Employment Opportunity Commission (EEOC). If selected, you will serve as an Information Technology (IT) Specialist, Information Security Officer (ISO), in support of the agency's information security (INFOSEC) programs.
Specialized experience must include demonstrable experience:
Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic; religious; spiritual; community, student, social). Volunteer work helps build critical competencies, knowledge, and skills and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.
Qualifications:
IT-related experience; experience may be demonstrated by paid or unpaid experience and/or completion of specific, intensive training (for example, IT certification), as appropriate. Experience must have demonstrated each of the four competencies listed below.
- Attention to Detail - Is thorough when performing work and conscientious about attending to detail.
- Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services.
- Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately.
- Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations.
Specialized experience must include demonstrable experience:
- Guides secure cloud operations and sustainment by ensuring consistent approaches for cloud services, identifying and mitigating technical threat vectors and APT activity, and implementing practical remediation to reduce attack surface.
- Enhances cybersecurity operations through improved SOC, SIEM, and SOAR processes, strengthening continuous monitoring (CONMON), maturing operational procedures, and sustaining a hardened security posture.
- Advances DEVSECOPS maturity by implementing automated and manual AppSec testing (SAST, DAST, IAST, SCA, container scanning), implementing and enforcing secure coding including hardened deployment standards, and continuously monitoring environments for cybersecurity events.
- Applies deep technical expertise in major cloud platforms, scripting/automation (Python, Bash, Golang), and cybersecurity frameworks (NIST, OWASP, CIS), including hands-on execution of Zero Trust pillars and secure AI practices.
- Leads major INFOSEC initiatives-balancing workload across projects and incidents, keeping leadership dutifully informed while facilitating, executing and directing efforts in GRC, SOC operations, FedRAMP activities, and promotion of varying degrees of role-based enterprise level guidance, in concert with adversarial (blue/red/purple team) exercises.
- Oversees federal security compliance by interpreting information security (INFOSEC) laws and FISMA regulations; managing POA&Ms and vulnerability remediation; developing or assessing ATO documentation (SSPs, RAs, CPs); and evaluating controls, baselines, cybersecurity-supply chain risk management (C-SCRM) and compliance across systems to strengthen EEOC's INFOSEC posture.
Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic; religious; spiritual; community, student, social). Volunteer work helps build critical competencies, knowledge, and skills and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.
Salary : $143,913