IT Specialist (Security)

Centers for Medicare & Medicaid Services•Woodlawn, MD
•Onsite

About The Position

This position is located in the Department of Health & Human Services (HHS), Centers for Medicare & Medicaid Services (CMS), Office of Communications(OC), Web & Emerging Technologies Group (WETG), Division of Website Operations (DWO). As a IT Specialist (Security), GS-2210-13, you will review, analyze, develop, publish, promote, and implement awareness of enterprise-wide HHS information technology (IT) security and/or system development life cycle (SDLC) policies and standards.

Requirements

  • You must be a U.S. Citizen or National to apply for this position.
  • You will be subject to a background and suitability investigation.
  • Males born after December 31, 1959, must be registered or exempt from Selective Service.
  • One-year probationary period may be required.
  • If you are selected for this position, the documentation that you present for purposes of completing the Department of Homeland Security (DHS) Form I-9 will be verified through the DHS "E-Verify" System.
  • All Federal employees are required to have Federal salary payments made by direct deposit to a financial institution of their choice.
  • IT-related experience, at the GS-12 grade level in the federal government, demonstrating each of the four competencies: Attention to Detail, Customer Service, Oral Communication, and Problem Solving.
  • At least one year (52 weeks) of qualifying specialized experience equivalent to the GS-12 grade level in the Federal government, obtained in either the private or public sector, to include: Applying security policies, standards, and risk management frameworks (such as NIST SP 800-53, FISMA, FedRAMP, or equivalent industry frameworks like ISO 27001 or SOC 2) to assess, authorize, and continuously monitor the security posture of information systems.
  • Overseeing or advising on the integration of security controls into a DevSecOps pipeline, including compliance-as-code, automated vulnerability scanning, and automated generation of security control evidence.
  • Managing or coordinating third-party contractor or vendor security deliverables, including reviewing security assessment reports, tracking remediation of findings, and enforcing compliance with security requirements and timelines.
  • Leading or contributing to incident response activities, security control assessments, and the development or maintenance of system security documentation (such as System Security Plans, Contingency Plans, or Risk Assessment Reports).

Nice To Haves

  • Experience with NIST 800-53, FISMA, FedRAMP, ISO 27001, or SOC 2.
  • Experience with compliance-as-code tools like InSpec.
  • Experience with automated vulnerability scanning.
  • Experience with incident response and continuous monitoring.
  • Experience maintaining System Security Plans, Risk Assessment Reports, and Contingency Plans.

Responsibilities

  • Acts as ISSO for assigned WETG systems, ensuring ADOs and contractors meet security and risk framework requirements (NIST 800-53, FISMA, FedRAMP) across the authorization lifecycle, including control testing, risk decisions, and threat modeling.
  • Direct integration of security controls into the DevSecOps pipeline, guiding contractors on compliance-as-code (e.g., InSpec), automated vulnerability scanning, and evidence generation, while verifying automated results truly reflect compliance.
  • Oversee contractor and vendor security performance by assessing security impacts of changes, reviewing assessment reports, tracking POA-Ms to closure, enforcing CMS testing standards, and holding ADOs accountable to contract security commitments.
  • Drive incident response and continuous monitoring, reporting security incidents per CMS Incident Handling Guidelines, partnering with CMS security operations, and ensuring 24x7x365 monitoring coverage for assigned systems.
  • Keep security documentation current, including System Security Plans, Risk Assessment Reports, and Contingency Plans, and coordinates annual assessments and penetration testing to support Authority to Operate (ATO) decisions.

Benefits

  • Comprehensive benefits package
  • Access to a range of benefits designed to make your federal career very rewarding
  • Flexible working arrangements
  • Alternative work schedules at the manager's discretion
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service