
IT Cybersecurity Specialist (Security)
Centers for Medicare & Medicaid Services
Woodlawn, MDFull-time$116–158K/yrPosted today
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near Woodlawn, MD, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Job overview
The IT Cybersecurity Specialist (Security) will secure SaaS platforms and cloud‑hosted business applications for CMS, developing governance frameworks, automated workflows, and providing technical consultation on security risks and compliance.
Skills & qualifications
Skills
Qualifications
Full job description
Summary
This position is located in the Department of Health & Human Services (HHS), Centers for Medicare & Medicaid Services (CMS), Office of Information Technology (OIT), Information Security and Privacy Group (ISPG), Division of Security and Privacy Compliance (DSPC). As a IT Cybersecurity Specialist (Security), GS-2210-13, you will secure Software-as-a-Service (SaaS) platforms and cloud-hosted business applications utilized throughout CMS.
Duties
- Plan, develop, and implement enterprise-wide SaaS security governance frameworks, policies, standards, and baselines to ensure the secure acquisition, adoption, operation, and continuous monitoring of cloud-hosted applications across CMS.
- Design and implement automated security workflows, scripts, and integration pipelines connecting SaaS security tools to enterprise monitoring and ticketing systems to streamline detection, tracking, remediation, and validation of security findings.
- Provide technical consultation, recommendations, and briefings to CMS senior leadership, application owners, cybersecurity personnel, vendors, and Federal partners on SaaS security risks, compliance posture, and remediation strategies.
- Conduct security posture, vulnerability, and configuration assessments of SaaS platforms, prioritize findings by risk; and coordinate remediation with application owners, security teams, and vendors.
- Evaluate SaaS platforms, third-party providers, and application integrations against Federal cybersecurity requirements.
Qualifications
ALL QUALIFICATION REQUIREMENTS MUST BE MET BY THE CLOSING DATE OF THIS ANNOUNCEMENT. Your resume (limited to no more than 2 pages) must include detailed information as it relates to the responsibilities and specialized experience for this position. Evidence of copying and pasting directly from the vacancy announcement without clearly documenting supplemental information to describe your experience will result in an ineligible rating. This will prevent you from being considered further. There is a Basic Requirement and Minimum Qualification Requirement for this position. You must meet both requirements. Basic Requirement: You must have IT related experience, demonstrated by paid or unpaid experience obtained in either the private or public sector, and/or completion of specific, intensive training that demonstrates that I possess each of the following four competencies: (1) Attention to Detail - Is thorough when performing work and conscientious about attending to detail. (2) Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. (3) Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. (4) Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. AND In order to qualify for the GS-13, you must meet the following: You must demonstrate in your resume at least one year (52 weeks) of qualifying specialized experience equivalent to the GS-12 grade level in the Federal government, obtained in either the private or public sector, to include: 1) Securing SaaS platforms and cloud-hosted applications (e.g., Microsoft 365, Salesforce, ServiceNow) using SaaS Security Posture Management (SSPM) or Cloud Access Security Broker (CASB) technologies to identify issues - such as misconfigurations, policy violations, and security risks; AND 2) Applying federal cybersecurity frameworks - such as Federal Information Security Modernization Act (FISMA), Federal Risk and Authorization Management Program (FedRAMP), or National Institute of Standards and Technology Risk Management Framework (NIST RMF) - to assess and monitor the compliance posture of cloud environments; AND 3) Developing and integrating automated workflows, scripts, or security tools to manage security findings across a cloud or SaaS environment. Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional, philanthropic, religious, spiritual, community, student, social). Volunteer work helps build critical competencies, knowledge, and skills, and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.
Education
This job does not have an education qualification requirement. How You Will Be Evaluated
You will be evaluated based on how well you meet the qualifications listed in this vacancy announcement. Your qualifications will be evaluated based on your application materials (e.g., resume, supporting documents), the responses you provide in the application questionnaire, and the results of the online assessment(s) required for this position. A Subject Matter Expert will assist in the resume review process to help determine whether you meet the minimum job qualifications. Please follow all instructions carefully. Errors or omissions may affect your rating. You will be assessed on the following competencies (knowledge, skills, abilities, and other characteristics): Accountability Attention to Detail Customer Service Decision Making Flexibility Influencing/Negotiating Integrity/Honesty Interpersonal Skills Learning Reading Comprehension Reasoning Self-Management Stress Tolerance Teamwork In order to be considered for this position, you must complete all required steps in the process. In addition to the application and application questionnaire, this position requires an online assessment. The online assessment measures critical general competencies required to perform the job. The assessment includes a cut score based on the minimum level of required proficiency in these critical general competencies. You must meet or exceed the cut score to be considered. You will not be considered for the position if you score below the cut score or fail to complete the assessment. Overstating your qualifications and/or experience in your application materials or application questionnaire may result in your removal from consideration. Cheating on the online assessment may also result in your removal from consideration. RPL Applicants RPL applicants who are verified as registered for the same series, grade, and location as this vacancy announcement will be placed in one of the following categories based on category rating procedures: Best Qualified - significantly exceeds the evaluation criteria Well Qualified - excelsin the evaluation criteria Qualified - meets the minimum qualification requirements If you are found to be among the top-qualified candidates, you will be referred to the selecting official for employment consideration. The category rating process does not add veterans' preference points but protects the rights of veterans by placing them ahead of non-preference eligibles within each category. Veterans' preference eligibles who meet the minimum qualification requirements and who have a compensable service-connected disability of at least 10 percent will be listed in the highest quality category (except in the case of professional or scientific positions at the GS-09 level or higher). Other Information
Bargaining Unit Position: Yes-American Federation of Government Employees, Local 1923 Tour of Duty: Flexible Recruitment Incentive: Not Authorized Relocation Incentive: Not Authorized Financial Disclosure: Not Required Additional Salary Information: Dallas, TX: $115,711 to $150,426 Woodlawn, MD: $121,785 to $158,322 Workplace Flexibility at CMS: This position has a regular and recurring reporting requirement to the CMS office listed in this announcement. CMS offers flexible working arrangements and allows employees the opportunity to participate in alternative work schedules at the manager's discretion. The Interagency Career Transition Assistance Plan (ICTAP) and Career Transition Assistance Plan (CTAP) provide eligible displaced federal employees with selection priority over other candidates for competitive service vacancies. To be qualified you must submit the required documentation and be rated well-qualified for this vacancy. Click here for a detailed description of the required supporting documents. A well-qualified applicant is one whose knowledge, skills and abilities clearly exceed the minimum qualification requirements of the position. Additional information about ICTAP and CTAP eligibility is on OPM's Career Transition Resources website at www.opm.gov/rif/employee_guides/career_transition.asp.
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Security SpecialistSocial Security Administration · Washington, DC · $144–187K/yrPosted 1w agoPosted 1w ago
IT CYBERSECURITY SPECIALIST (NETWORK/INFOSEC)Defense Information Systems Agency · Fort Meade, MD · $122–158K/yrPosted 2 days agoPosted 2 days ago
SUPV IT CYBERSECURITY SPECIALIST (PLCYPLN/INFOSEC)Defense Information Systems Agency · Fort Meade, MD · $150–197K/yrPosted 2 days agoPosted 2 days ago
IT SPECIALIST (INFOSEC)DOD Cyber Crime Center · Linthicum Heights, MD · $144–187K/yrPosted 1w agoPosted 1w ago
IT CYBERSECURITY SPECIALIST (INFOSEC)Defense Information Systems Agency · Gunter AFB, AL · $101–169K/yrPosted todayPosted today
You've read the whole posting — now see how you match it.