IT Specialist (INFOSEC)

Equal Employment Opportunity Commission · Washington, District of Columbia

$144k–$187kPosted pay
On-siteWorkplace
1w agoPosted · Sep 16
USAJOBSSource
$117kit support specialist median
Experience1+ years

Skills in this posting

The posting

Advises leadership on federal information security (INFOSEC) laws, regulations, standards, and emerging requirements, and contributes to the development and implementation of agency-level IT security policies and directives.

Monitors and reports on cybersecurity threats, vulnerabilities, and mitigation efforts, including reviewing and updating Plans of Action and Milestones (POA and M) and briefing the Chief Information Security Officer (CISO) on risk status.

Develops, reviews, and maintains key security authorization documentation, including System Security Plans (SSP), Contingency Plans (CP), Risk Assessments (RA), and other materials required to obtain or maintain an Authorization to Operate (ATO).

Conducts technology assessments, trend analyses, feasibility studies, and acquisition support activities, including drafting specifications, reviewing contract deliverables, and recommending courses of action to support cybersecurity objectives.

Provides operational support by resolving assigned incidents, responding to staff inquiries, tracking fulfillment requests, coordinating with technical teams, and ensuring all activities are documented in agency management tools.

IT-related experience; experience may be demonstrated by paid or unpaid experience and/or completion of specific, intensive training (for example, IT certification), as appropriate. Experience must have demonstrated each of the four competencies listed below.

Attention to Detail - Is thorough when performing work and conscientious about attending to detail.

Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services.

Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately.

Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. For the GS-14: You must have one year of specialized experience equivalent to the GS-13 level in federal service.

Specialized experience must include demonstrable experience: Guides secure cloud operations and sustainment by ensuring consistent approaches for cloud services, identifying and mitigating technical threat vectors and APT activity, and implementing practical remediation to reduce attack surface.

Enhances cybersecurity operations through improved SOC, SIEM, and SOAR processes, strengthening continuous monitoring (CONMON), maturing operational procedures, and sustaining a hardened security posture.

Advances DEVSECOPS maturity by implementing automated and manual AppSec testing (SAST, DAST, IAST, SCA, container scanning), implementing and enforcing secure coding including hardened deployment standards, and continuously monitoring environments for cybersecurity events.

Applies deep technical expertise in major cloud platforms, scripting/automation (Python, Bash, Golang), and cybersecurity frameworks (NIST, OWASP, CIS), including hands-on execution of Zero Trust pillars and secure AI practices.

Leads major INFOSEC initiatives-balancing workload across projects and incidents, keeping leadership dutifully informed while facilitating, executing and directing efforts in GRC, SOC operations, FedRAMP activities, and promotion of varying degrees of role-based enterprise level guidance, in concert with adversarial (blue/red/purple team) exercises.

Oversees federal security compliance by interpreting information security (INFOSEC) laws and FISMA regulations; managing POA&Ms and vulnerability remediation; developing or assessing ATO documentation (SSPs, RAs, CPs); and evaluating controls, baselines, cybersecurity-supply chain risk management (C-SCRM) and compliance across systems to strengthen EEOC's INFOSEC posture.

Applicants must meet all eligibility requirements (e.g., time-in-grade and qualification requirements) within 30 days of the closing date specified in the vacancy announcement.

Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic; religious; spiritual; community, student, social).

Volunteer work helps build critical competencies, knowledge, and skills and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.

The PivotHop read

Where these skills also reach

More it support specialist roles

Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.

© 2026 PivotHopReal data, real career moves