IT Cybersecurity Specialist
What you'd do
The Office of the Chief Information Officer (OCIO) serves as the IT hub of the U.S. Department of Labor. We develop, maintain and protect IT solutions and data across our 27 agencies to enable mission outcomes through technology and service. OCIO continually enhances federal IT and digital capability with a focus on cybersecurity and customer experience to serve America's wage earners, job seekers and retirees.
Major duties
The Department of Labor may use certain incentives and hiring flexibilities, currently offered by the Federal government to attract highly qualified candidates. Relocation Expenses, Recruitment Incentives, Superior Qualifications and Special Needs Pay-Setting Authority may be negotiable. Click here for Additional Information. The position may be located at any of the DOL office locations, if available. The advertised salary range reflects the minimum and maximum pay for all locations. Final salary will be determined based on the selectee's assigned duty station in accordance with applicable locality pay tables. The role supports the Chief Information Officer (OCIO) and its Directorate of Cybersecurity, which consists of the following divisions: Cybersecurity Governance, Cybersecurity Authorization, and Security Operations Center. Under the direction of the Department's Chief Information Security Officer(CISO), the Directorate manages the enterprise-wide organizational risk associated with the operation of unclassified and classified information systems through a distribution model that provides resiliency in the face of evolving threats. Major duties include, but are not limited to: Independently plan, execute, and complete complex cybersecurity assignments, applying advanced knowledge of information security principles, federal requirements, and enterprise IT environments. Implement and validate compliance with FISMA, NIST SP 800-53, and the Risk Management Framework (RMF) by assessing controls, documenting artifacts, and recommending corrective actions. Conduct formal security assessments, audits, and reviews, including evaluating controls, collecting evidence, and making risk determinations to ensure regulatory and departmental compliance. Monitor enterprise systems to ensure cybersecurity controls remain effective and aligned with federal requirements. Work collaboratively across IT, development, operations, and business units to identify, analyze, and resolve cybersecurity risks. Ensure security requirements are integrated into new and modernized systems, cloud solutions, and emerging technologies. Suggest and implement practical security solutions to meet compliance and operational requirements. Evaluate existing methods and procedures and recommends improvements for enhanced security and operational efficiency. Partner with IT teams to identify, mitigate, and remediate vulnerabilities and ensure security measures are fully integrated. Maintain accurate and complete information in CSAM and prepares standard or recurring cybersecurity reporting. Participate in security awareness initiatives and stays current with evolving data privacy and cybersecurity trends to strengthen organizational security practices.
What you need to qualify
You must meet the Basic Requirements and the Specialized Experience to qualify for the IT Cybersecurity Specialist, as described below. Basic Qualifications: Applicants must have IT-related experience demonstrating each of the following competencies listed below: Attention to Detail - Is thorough when performing work and conscientious about attending to detail. Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. Decision Making - Makes sound, well-informed, and objective decisions; perceives the impact and implications of decisions; commits to action, even in uncertain situations, to accomplish organizational goals; causes change. Information Management - Identifies a need for and knows where or how to gather information; organizes and maintains information or information management systems. Interpersonal Skills - Shows understanding, friendliness, courtesy, tact, empathy, concern, and politeness to others; develops and maintains effective relationships with others; may include effectively dealing with individuals who are difficult, hostile, or distressed; relates well to people from varied backgrounds and different situations Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. Teamwork - Encourages and facilitates cooperation, pride, trust, and group identity; fosters commitment and team spirit; works with others to achieve goals. Technical Competence - Uses knowledge that is acquired through formal training or on-the-job experience to perform one's job; works with, understands, and evaluates technical information related to the job; advises others on technical issues. AND Applicants must have 52 weeks of specialized experience equivalent to at least the next lower grade level, in the Federal Service. For GS-12 : Applicants must have 52 weeks of specialized experience equivalent to at least the next lower grade level GS-11 in the Federal Service. Specialized Experience is the experience that equipped the applicant with the particular knowledge, skills, and abilities (KSA's) to perform the duties of the position successfully, and that is typically in or related to the position to be filled. To be creditable, specialized experience must have been equivalent to at least the next lower grade level. Applicants must meet ALL of the statements below to be found qualified. Qualifying specialized experience for GS-12 includes: Experience applying FISMA, NIST, and RMF frameworks to evaluate and implement security and privacy controls. Experience interpreting federal cybersecurity requirements and advising leadership on compliance and risk-reduction strategies. Experience conducting enterprise security reviews and risk assessments to ensure adherence to federal cybersecurity policies. Experience briefing leadership and helping shape organizational cybersecurity policies and processes.
Before you apply
Federal applications are different: your resume should be 3–5 pages and mirror the language of this announcement. Read our federal resume guide first — it's the #1 reason qualified people get screened out.
Don't miss the next one.
Get an email the moment a similar federal job opens — postings can close in as little as 5 days.