Cybersecurity Specialist (Investigation)
What you'd do
EBSA plays a vital role in protecting the retirement, health, and other job-based benefits of America's workers, retirees, and their families. We issue effective regulations, offer comprehensive education and assistance to workers, plan sponsors, fiduciaries, and service providers, and rigorously enforce the law. We serve workers, families, and the broader employee benefits community by protecting the security and integrity of the nation's benefit systems.
Major duties
The Cybersecurity Specialist (Investigation) in EBSA's Office of Enforcement conducts investigations of cybersecurity protections and practices of employee benefit plans and their service providers. The specialist uses advanced technical skills to assess network security, identify vulnerabilities, analyze digital evidence, and evaluate compliance with cybersecurity standards and the requirements of the Employee Retirement Income Security Act of 1974 (ERISA). This work directly supports ERISA investigations and helps protect pension and welfare benefit plans from cyber threats and data breaches.
What you need to qualify
Qualification requirements include meeting minimum proficiency levels for required competencies, demonstrating one year of specialized experience equivalent to at least the next lower grade level, i.e. GS-13, in the Federal Service, and satisfying selective factor certification requirements. Competencies Attention to Detail - is thorough when performing work and conscientious about attending to detail. (Advanced-level proficiency or higher). Customer Service - works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. (Advanced-level proficiency or higher). Decision Making - makes sound, well-informed, and objective decisions; perceives the impact and implications of decisions; commits to action, even in uncertain situations, to accomplish organizational goals; causes change. (Intermediate-level proficiency or higher). Information Management - identifies a need for and knows where or how to gather information; organizes and maintains information or information management systems. (Advanced-level proficiency or higher). Interpersonal Skills - shows understanding, friendliness, courtesy, tact, empathy, concern, and politeness to others; develops and maintains effective relationships with others; may include effectively dealing with individuals who are difficult, hostile, or distressed; relates well to people from varied backgrounds and different situations. (Advanced-level proficiency or higher). Oral Communication - expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. (Intermediate-level proficiency or higher). Problem Solving - identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. (Advanced-level proficiency or higher). Teamwork - encourages and facilitates cooperation, pride, trust, and group identity; fosters commitment and team spirit; works with others to achieve goals. (Advanced-level proficiency or higher). Technical Competence - uses knowledge that is acquired through formal training or on-the-job experience to perform one's job; works with, understands, and evaluates technical information related to the job; advises others on technical issues. (Advanced-level proficiency or higher). Specialized Experience Specialized experience serves as evidence that an applicant possesses the knowledge, skills, and abilities/competencies required for successful performance in the position. For this position, specialized experience is defined as one year of experience performing both of the following: 1. Demonstrated experience leading cybersecurity investigations using diverse methods for evidence identification, collection, analysis, and reporting. Key experience indicators may include: Leading investigations to resolve security incidents ensuring evidence is properly collected, preserved, and analyzed Analyzing digital evidence to uncover root causes, inform remediation, and support risk mitigation strategies Developing and implementing procedures for identifying, acquiring, and documenting digital evidence across multiple systems Presenting investigation findings to leadership and recommending actions based on cybersecurity investigative results 2. Demonstrated experience coordinating the collection and analysis of data to support cybersecurity investigations. Key experience indicators may include: Collaborating with cross-functional teams to establish information needs and oversee cybersecurity data collection and analysis Planning and performing cybersecurity reviews of network systems to identify weaknesses and ensure practices meet industry standards Analyzing cyber threat indicators and attacker tactics to provide actionable insights for decision-makers Recommending improvements to data collection and analysis processes to strengthen cybersecurity capabilities Selective Factor Applicants must possess a valid Certified Information Systems Security Professional (CISSP) certification.
Before you apply
Federal applications are different: your resume should be 3–5 pages and mirror the language of this announcement. Read our federal resume guide first — it's the #1 reason qualified people get screened out.
Don't miss the next one.
Get an email the moment a similar federal job opens — postings can close in as little as 5 days.