IT Cybersecurity Specialist (Direct Hire)
Headquarters, NASASummary
This position is located in the Cybersecurity and Privacy Division (CSPD) of the Office of the Chief Information Officer (OCIO). As a Cybersecurity Risk Manager (CSRM), you will guide stakeholders as they implement assessment and authorization policies and procedures, cybersecurity continuous monitoring, and risk management activities. You will collaborate with other CSRMs to provide support for stakeholders in identifying, communicating, and managing cybersecurity risks.
- Duties described below are at the highest grade advertised. Duties assigned at lower grade levels will be of more limited scope, performed with less independence and limited complexity; duties will be commensurate with the grade of selected employee.
- Validate the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials).
- Validate that security controls are correctly implemented and remain effective throughout the system lifecycle. Design or advise on technical solutions to complex problems which require technical expertise and ingenuity.
- Leads information system stakeholders by ensuring their assessment readiness, effective continuous monitoring, and ongoing adherence to risk management activities, while providing technical oversight and cybersecurity consultation to stakeholders.
- Identify patterns of noncompliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program.
- Negotiate with program security, cybersecurity management, stakeholders, and other relevant parties to clarify requirements and resolve issues while balancing mission needs against compliance mandates.
- Perform security analysis, identify threats, and prioritize vulnerabilities to define and assess compliance with accepted government standards and regulations.
- Advise senior management, such as Authorizing Officials (AO), Chief Information Officer (CIO), and Chief Information Security Officer (CISO) on cybersecurity risk levels and security posture.
- Develop methods to monitor and measure risk, compliance, and assurance efforts. Ensure selected security controls operate as intended in every phase of the information system lifecycle.
- Provide leadership and direction to information technology (IT) personnel by ensuring that cybersecurity awareness, basics, literacy, and training are provided to operations personnel commensurate with their responsibilities.
Conditions of employment
- This position is open to U.S. citizens, nationals or those who owe allegiance to the U.S.
- This position may require a one-year probationary period. If selected, the requirement to serve such period will be determined by Title 5 of the Code of Federal Regulations, Part 11. **See Additional Information section**
- You must meet qualifications requirements by the closing date of this announcement.
- Position subject to pre-employment background investigation or higher-level clearance. Investigation/Clearance may differ and be required based on the duty location/NASA Center requirements.
- Financial Disclosure, Drug Testing, and/or the Travel Requirements for this position may differ and be required based on the duty location/NASA Center requirements.
Qualifications
Specialized experience is experience that has equipped you with the particular ability, skill, and knowledge to successfully perform the duties of this position and is typically in or related to this line of work.
To qualify for GS-12, you must have one year of directly related specialized experience equivalent to the GS-11 level.
- Providing technical security oversight for information systems and balance the demands of multiple customers;
- Applying Risk Management Framework (RMF) process and principles, methods and/or practices against specified requirements/controls (e.g., National Institute of Standards and Technology (NIST) Special Publications 800-37, 800-53, and 800-60);
- Collaborating with customers and/or business partners to help manage compliance with requirements.
- Providing technical security oversight for information systems and balance the demands of multiple customers while formulating and driving Agency security priorities;
- Applying Risk Management Framework (RMF) process and principles, methods and practices against specified requirements/controls (e.g., National Institute of Standards and Technology (NIST) Special Publications 800-37, 800-53, and 800-60) to develop security plans and continuously monitor the cybersecurity posture of networks and information systems;
- Collaborating with customers and/or business partners to perform oversight and manage compliance with requirements to ensure an organization's cybersecurity posture in a risk-based manner that minimizes operational impact.
IF you are qualifying based on experience, you MUST also have IT-related experience demonstrating each of the nine competencies listed below:
- Attention to Detail - Is thorough when performing work and conscientious about attending to detail.
- Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services.
- Decision Making - Makes sound, well-informed, and objective decisions; perceives the impact and implications of decisions; commits to action, even in uncertain situations, to accomplish organizational goals; causes change.
- Information Management - Identifies a need for and knows where or how to gather information; organizes and maintains information or information management systems.
- Interpersonal Skills - Treats others with courtesy, sensitivity, and respect. Considers and responds appropriately to the needs and feelings of different people in different situations.
- Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately.
- Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations.
- Teamwork - Works well with others in a team environment to achieve goals; helps engender team spirit and commitment by encouraging, modeling, and/or facilitating cooperation, pride, trust, and a sense of group identity among team members.
- Technical Competence - Uses knowledge that is acquired through formal training or extensive on-the-job experience to perform one's job; works with, understands, and evaluates technical information related to the job; advises others on technical issues.
Please visit https://www.nasa.gov/careers/how-to-apply/#Artificial-Intelligence to review NASA's guidance on the use of artificial intelligent (AI) or AI-assisted tools during the application process.
Education
This job does not have an education qualification requirement.
Additional information
Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution.
A career with the U.S. government provides employees with a comprehensive benefits package. As a federal employee, you and your family will have access to a range of benefits that are designed to make your federal career very rewarding. Opens in a new windowLearn more about federal benefits.
Eligibility for benefits depends on the type of position you hold and whether your position is full-time, part-time or intermittent. Contact the hiring agency for more information on the specific benefits offered.