IT SPECIALIST (INFOSEC)

Naval Facilities Engineering Systems CommandBroadway Complex, San Diego, California, Naval Base, Norfolk, Virginia, Port Hueneme, California, Washington Navy Yard, District of Columbiausajobspublished 10/09/2026
Must-have:DevOpsAgileSeniorLead

You will serve as an IT Specialist/Functional Security Control Assessor (FSCA) Liaison in the Command Information Office (CIO) of NAVFAC OSF.

Major duties

  • You will develop specifications to ensure risk, compliance, and assurance efforts conform to security, resilience, and dependability requirements at the software application, system, and network/enclave environment level.
  • You will monitor and evaluate a system's compliance with IT security, resilience, and dependability requirements.
  • You will provide an accurate technical evaluation of the software application, system, or network/enclave documenting the security posture, capabilities, and vulnerabilities against relevant cybersecurity compliance.
  • You will develop security assessment reports associated with authorization and deployment of new/existing OT using newly discovered threats to enable businesses and agencies to assess the resources needed to respond effectively.
  • You will conduct systems security evaluations, audits, and reviews.
  • You will ensure the rigorous application of information security/information assurance policies, principles, and practices in the delivery of all IT services.
  • You will recommend new or revised security measures and countermeasures based on the results of accreditation reviews.

Qualifications

Your resume must demonstrate the following four competencies, as defined: Attention to Detail - Is thorough when performing work and conscientious about attending to detail. IT-related experience demonstrating this competency includes: Developing methods to monitor and measure risk, compliance, and assurance efforts. Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. IT-related experience demonstrating this competency includes: Ensuring coordination and/or collaboration on security activities. Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. IT-related experience demonstrating this competency includes: Recommending new or revised security measures and countermeasures based on the results of accreditation reviews. Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. IT-related experience demonstrating this competency includes: Verifying that application software/network/system security postures are implemented as stated, document deviations, and recommending required actions to correct those deviations. In addition to experience demonstrating the four competencies above, your resume must also demonstrate one year of specialized experience equivalent to the next lower grade level (GS-13) or pay band in the federal service or equivalent experience in the private or public sector performing duties such as: Applying Risk Management Framework (RMF) and Security Assessment & Authorization (A&A) processes to assess authorization packages, maintain security artifacts, and develop comprehensive assessment reports. Conducting risk and vulnerability assessments, system security evaluations, and independent validation audits using cyber defense tools and vulnerability scans to verify security posture and compliance. Analyzing cyber threats, network security architectures, and cryptographic controls to recommend risk mitigations, implement compensating controls, and strengthen system resilience. Integrating cybersecurity policies into system development, migration, and operations while planning security accreditation reviews and monitoring ongoing risk and compliance. and Evaluating emerging threats and security requirements to support continuous risk management, compliance, and mission assurance. Additional qualification information can be found from the following Office of Personnel Management website: https://www.opm.gov/policy-data-oversight/classification-qualifications/general-schedule-qualification-standards/2200/information-technology-it-management-series-2210-alternative-a/ Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., professional, philanthropic, religious, spiritual, community, student, social). Volunteer work helps build critical competencies, knowledge, and skills and can provide valuable training and experience that translates directly to paid employment.