Posted August 12, 2026

IT Cybersecurity Specialist


Phoenix, AZOnsiteFull Time

Compensation: $106,437 to $154,280 Annually


This IT Cybersecurity Specialist position is with Western Area Power Administration (Department of Energy) in Phoenix, AZ. As an IT Cybersecurity Specialist (INFOSEC), you will provide technical expertise and guidance to WAPA functional and project teams regarding cybersecurity technical issues, risk analyses, mitigation plans and continuity of operations planning. **This is NOT A REMOTE POSITION. The selectee will be required to be physically present at one of the duty location(s) identified.** Key duties: • As a IT Cybersecurity Specialist, you will: Provide technical oversight of IT operating system security ensuring the confidentiality, integrity, and availability of systems, networks and data. Develop, review and evaluate information security policies for WAPA. Employ Defense in Depth principles and technology and other best practices in security engineering designs and implementation. Evaluate the quality of Federal Information Security Management Act (FISMA) and North American Electric Reliability Corporation (NERC) Critical Information Protection (CIP) evidence for the purposes of ensuring WAPA is meeting regulatory requirements and standards common in the industry (e.g. NERC and FERC guidelines). Create and maintain evidence in specific evidence repositories. Serve as one of WAPA's lead technical experts on systems, network, and cloud security to management and other technical specialists on critical IT issues. Analyze Information Assurance (IA) security events, including threat model development and resulting security risk analysis of systems. Qualifications: QUALIFICATION REQUIRMENTS: To qualify for this position, you must meet the minimum qualification requirements as well as the specialized experience requirements outlined below: MINIMUM REQUIREMENTS FOR GRADE 12 and Above (GS or Equivalent): The competencies listed in the "How You Will Be Evaluated" section will be used to evaluate whether or not you meet the minimum proficiency level established for the 2210 series SPECIALIZED EXPERIENCE for Cybersecurity Infrastructure and Architecture (IA): A qualified candidate's online application and resume must demonstrate at least one (1) year of specialized experience equivalent in difficulty and responsibility to the next lower grade level GS-12 in the Federal service (obtained in either the public or private sectors). Specialized experience for this position is defined as having at least two (2) of the following: Test, analyze, and/or implement existing and future systems to complement existing cybersecurity architectures; often leading Authority to Operate (ATO) job functions such as control testing and validation, Plan of Actions & Milestones (POAM) tracking or Risk Acceptance (RA). Analyze security events, including threat model development and resulting security risk analysis of systems. Design and develop security architecture to execute a company's cybersecurity program to meet Federal Information Security Modernization Act (FISMA), North American Electric Reliability (NERC), Critical Information Protection (CIP), or NIST 800-53 Controls. Perform vulnerability management to include scans, assessments, and remediation in conjunction with other IT business units to reduce company-wide risk. -OR- SPECIALIZED EXPERIENCE for Cybersecurity Operations (Ops): A qualified candidate's online application and resume must demonstrate at least one (1) year of specialized experience equivalent in difficulty and responsibility to the next lower grade level GS-12 in the Federal service (obtained in either the public or private sectors). Specialized experience for this position is defined as having at least two (2) of the following: Configure and manage and/or manage the lifecycle of at least 1 (one) of the following cybersecurity systems: Axonius, Carbon Black App Control, Carbon Black Endpoint Detection and Response (EDR), Corelight, Forescout, Splunk, and Tenable. Apply the Risk Management Framework (RMF) and assess cybersecurity systems against federal and industry compliance standards, such as NIST SP 800-53, FISMA, or NERC CIP. Conduct incident response activities, vulnerability assessments, and/or digital forensics, including analyzing security events to understand and mitigate active potential cybersecurity threats. View the full announcement and apply on USAJOBS.gov.
Expires September 11, 2026

Share this Job

Location

Map of Phoenix, AZ

Browse by Category

Jobs by City