IT Cybersecurity Specialist (Security)

Centers for Medicare & Medicaid ServicesWoodlawn, Maryland, Dallas, Texasusajobsveröffentlicht 10.09.2026
Muss:CloudSecuritySenior

This position is located in the Department of Health & Human Services (HHS), Centers for Medicare & Medicaid Services (CMS), Office of Information Technology (OIT), Information Security and Privacy Group (ISPG), Division of Security and Privacy Compliance (DSPC). As a IT Cybersecurity Specialist (Security), GS-2210-13, you will secure Software-as-a-Service (SaaS) platforms and cloud-hosted business applications utilized throughout CMS.

Major duties

  • Plan, develop, and implement enterprise-wide SaaS security governance frameworks, policies, standards, and baselines to ensure the secure acquisition, adoption, operation, and continuous monitoring of cloud-hosted applications across CMS.
  • Design and implement automated security workflows, scripts, and integration pipelines connecting SaaS security tools to enterprise monitoring and ticketing systems to streamline detection, tracking, remediation, and validation of security findings.
  • Provide technical consultation, recommendations, and briefings to CMS senior leadership, application owners, cybersecurity personnel, vendors, and Federal partners on SaaS security risks, compliance posture, and remediation strategies.
  • Conduct security posture, vulnerability, and configuration assessments of SaaS platforms, prioritize findings by risk; and coordinate remediation with application owners, security teams, and vendors.
  • Evaluate SaaS platforms, third-party providers, and application integrations against Federal cybersecurity requirements.

Qualifications

ALL QUALIFICATION REQUIREMENTS MUST BE MET BY THE CLOSING DATE OF THIS ANNOUNCEMENT. Your resume (limited to no more than 2 pages) must include detailed information as it relates to the responsibilities and specialized experience for this position. Evidence of copying and pasting directly from the vacancy announcement without clearly documenting supplemental information to describe your experience will result in an ineligible rating. This will prevent you from being considered further. There is a Basic Requirement and Minimum Qualification Requirement for this position. You must meet both requirements. Basic Requirement: You must have IT related experience, demonstrated by paid or unpaid experience obtained in either the private or public sector, and/or completion of specific, intensive training that demonstrates that I possess each of the following four competencies: (1) Attention to Detail - Is thorough when performing work and conscientious about attending to detail. (2) Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. (3) Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. (4) Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. AND In order to qualify for the GS-13, you must meet the following: You must demonstrate in your resume at least one year (52 weeks) of qualifying specialized experience equivalent to the GS-12 grade level in the Federal government, obtained in either the private or public sector, to include: 1) Securing SaaS platforms and cloud-hosted applications (e.g., Microsoft 365, Salesforce, ServiceNow) using SaaS Security Posture Management (SSPM) or Cloud Access Security Broker (CASB) technologies to identify issues - such as misconfigurations, policy violations, and security risks; AND 2) Applying federal cybersecurity frameworks - such as Federal Information Security Modernization Act (FISMA), Federal Risk and Authorization Management Program (FedRAMP), or National Institute of Standards and Technology Risk Management Framework (NIST RMF) - to assess and monitor the compliance posture of cloud environments; AND 3) Developing and integrating automated workflows, scripts, or security tools to manage security findings across a cloud or SaaS environment. Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional, philanthropic, religious, spiritual, community, student, social). Volunteer work helps build critical competencies, knowledge, and skills, and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.

Education

This job does not have an education qualification requirement.