Telework Eligible
Yes
Major Duties
Performs work involving ensuring the confidentiality, integrity, and availability of systems and applications through proper Segregation of Duties (SoD) risk analysis, principle of least privilege, and control of excessive authorization across all account types.
Designs, configures, monitors, tunes, and troubleshoots security tasks in the DLA Identity, Credential, and Access Management (ICAM) environment, adhering to Change Management policies and procedures.
Provides advice on System Applications and Products (SAP), Saviynt (governance and provisioning), or Okta (single sign-on) to improve operational performance, management, and strategy.
Offers policy interpretation and development support related to cybersecurity functional requirements.
Ensures security and compliance to maintain data confidentiality, integrity, and system availability.
Guides the acquisition, design, programming, testing, integration, and deployment of ICAM programs.
Develops and maintains Zero Trust Identity as a Service based on customer requirements, including single sign-on, identity federation, enterprise directory architecture, and resource provisioning.
Acts as a principal advisor to the Program Management Office (PMO), managing projects related to new technologies and information systems.
Conducts analyses to implement policies and procedures that secure DLA systems.
Participates in security and audit reviews to ensure safeguards' effectiveness and adequacy.
Provides guidance for audit readiness, legal and regulatory interpretation, and policy development.
Serves as the FISMA Point of Contact (POC) and Subject Matter Expert (SME) for various audits.
Performs enterprise-level security risk assessments and audit compliance activities.
Qualification Summary
To qualify as an IT Specialist (INFOSEC), your resume must demonstrate:
- One year of specialized experience related to cybersecurity, risk management, and security policy development.
- For GS-13, one year of experience equivalent to GS-12 or higher.
- Experience with federal cybersecurity guidelines, project management, and security assessments.
- Ability to collaborate with technical and management teams to resolve security and compliance issues.
- Volunteer work and unpaid experience can be considered if relevant.
#J-18808-Ljbffr