IT Cybersecurity Specialist (INFOSEC)
Summary
Implement and enforce cybersecurity policies for HHS systems, conduct risk assessments, and ensure compliance with federal standards.
This position is located in the Department of Health and Human Services, Office of the National Coordinator for Health Information Technology, headquartered in Washington, District of Columbia. This announcement will close at 11:59 PM, on the day that 75 applications have been received.
As an IT Cybersecurity Specialist (INFOSEC), you will: Develop, implement, and maintain cybersecurity policies, security controls, and secure SDLC processes to ensure information systems comply with Federal cybersecurity requirements, organizational security standards, and applicable laws, regulations, and guidance. Conduct cybersecurity risk assessments, security control assessments, and compliance reviews; analyzes vulnerabilities and recommends corrective actions to reduce risk and strengthen the organization's security posture. Coordinate cybersecurity projects and contractor activities by monitoring technical performance, deliverables, schedules, and contract compliance while preparing reports, metrics, and documentation to support enterprise cybersecurity operations. Perform cybersecurity risk management activities, including vulnerability assessments, security control evaluations, and remediation planning to improve the security and resilience of organizational information systems. Monitor and maintain the cybersecurity posture of department information systems through continuous assessment, security status reporting, vulnerability tracking, and ongoing maintenance activities.