Centers for Medicare & Medicaid Services logo

IT Cybersecurity Specialist (Security)

Centers for Medicare & Medicaid Services

MULTIPLE LOCATIONSJob$116–150K/yrSeen 1 day agoSeen in employer's feed 1 day ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$116–150K/yr
Location
MULTIPLE LOCATIONS
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

The IT Cybersecurity Specialist secures SaaS platforms and cloud‑hosted applications for CMS, developing governance frameworks, automated workflows, and providing technical consultation to senior leadership while assessing security posture and compliance across.

Skills & qualifications

RequiredNice to have

Skills

SaaS Security Posture ManagementCloud Access Security BrokerMicrosoft 365SalesforceServiceNowFISMAFedRAMPNIST RMF

Qualifications

One Year of Qualifying Specialized ExperienceAttention to DetailCustomer ServiceOral CommunicationProblem Solving

Full job description

Summary This position is located in the Department of Health & Human Services (HHS), Centers for Medicare & Medicaid Services (CMS), Office of Information Technology (OIT), Information Security and Privacy Group (ISPG), Division of Security and Privacy Compliance (DSPC). As a IT Cybersecurity Specialist (Security), GS-2210-13, you will secure Software-as-a-Service (SaaS) platforms and cloud-hosted business applications utilized throughout CMS. Responsibilities Plan, develop, and implement enterprise-wide SaaS security governance frameworks, policies, standards, and baselines to ensure the secure acquisition, adoption, operation, and continuous monitoring of cloud-hosted applications across CMS. Design and implement automated security workflows, scripts, and integration pipelines connecting SaaS security tools to enterprise monitoring and ticketing systems to streamline detection, tracking, remediation, and validation of security findings. Provide technical consultation, recommendations, and briefings to CMS senior leadership, application owners, cybersecurity personnel, vendors, and Federal partners on SaaS security risks, compliance posture, and remediation strategies. Conduct security posture, vulnerability, and configuration assessments of SaaS platforms, prioritize findings by risk; and coordinate remediation with application owners, security teams, and vendors. Evaluate SaaS platforms, third-party providers, and application integrations against Federal cybersecurity requirements. Requirements Conditions of Employment Qualifications ALL QUALIFICATION REQUIREMENTS MUST BE MET BY THE CLOSING DATE OF THIS ANNOUNCEMENT. Your resume (limited to no more than 2 pages) must include detailed information as it relates to the responsibilities and specialized experience for this position. Evidence of copying and pasting directly from the vacancy announcement without clearly documenting supplemental information to describe your experience will result in an ineligible rating. This will prevent you from being considered further. There is a Basic Requirement and Minimum Qualification Requirement for this position. You must meet both requirements. Basic Requirement: You must have IT related experience, demonstrated by paid or unpaid experience obtained in either the private or public sector, and/or completion of specific, intensive training that demonstrates that I possess each of the following four competencies: (1) Attention to Detail - Is thorough when performing work and conscientious about attending to detail. (2) Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. (3) Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. (4) Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. AND In order to qualify for the GS-13, you must meet the following: You must demonstrate in your resume at least one year (52 weeks) of qualifying specialized experience equivalent to the GS-12 grade level in the Federal government, obtained in either the private or public sector, to include: 1) Securing SaaS platforms and cloud-hosted applications (e.g., Microsoft 365, Salesforce, ServiceNow) using SaaS Security Posture Management (SSPM) or Cloud Access Security Broker (CASB) technologies to identify issues - such as misconfigurations, policy violations, and security risks; AND 2) Applying federal cybersecurity frameworks - such as Federal Information Security Modernization Act (FISMA), Federal Risk and Authorization Management Program (FedRAMP), or National Institute of Standards and Technology Risk Management Framework (NIST RMF) - to assess and monitor the compliance posture of cloud environments; AND 3) Developing and integrating automated workflows, scripts, or security tools to manage security findings across a cloud or SaaS environment. Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional, philanthropic, religious, spiritual, community, student, social). Volunteer work helps build critical competencies, knowledge, and skills, and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience. Education This job does not have an education qualification requirement. Additional Information Bargaining Unit Position: Yes-American Federation of Government Employees, Local 1923 Tour of Duty: Flexible Recruitment Incentive: Not Authorized Relocation Incentive: Not Authorized Financial Disclosure: Not Required Additional Salary Information: Dallas, TX: $115,711 to $150,426 Woodlawn, MD: $121,785 to $158,322 Workplace Flexibility at CMS: This position has a regular and recurring reporting requirement to the CMS office listed in this announcement. CMS offers flexible working arrangements and allows employees the opportunity to participate in alternative work schedules at the manager's discretion. The Interagency Career Transition Assistance Plan (ICTAP) and Career Transition Assistance Plan (CTAP) provide eligible displaced federal employees with selection priority over other candidates for competitive service vacancies. To be qualified you must submit the required documentation and be rated well-qualified for this vacancy. Click here for a detailed description of the required supporting documents. A well-qualified applicant is one whose knowledge, skills and abilities clearly exceed the minimum qualification requirements of the position. Additional information about ICTAP and CTAP eligibility is on OPM's Career Transition Resources website at www.opm.gov/rif/employee_guides/career_transition.asp.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.