Posted July 24, 2026

IT Cybersecurity Specialist (INFOSEC)


Phoenix, AZOnsiteFull Time

Compensation: $106,437 to $197,200 Annually


This IT Cybersecurity Specialist (INFOSEC) position is with Office of the Assistant Secretary for Administration and Management (Department of Labor) in Phoenix, AZ. The Office of the Chief Information Officer (OCIO) serves as the IT hub of the U.S. Department of Labor. We develop, maintain and protect IT solutions and data across our 27 agencies to enable mission outcomes through technology and service. OCIO continually enhances federal IT and digital capability with a focus on cybersecurity and customer experience to serve America's wage earners, job seekers and retirees. Key duties: • The Department of Labor may use certain incentives and hiring flexibilities, currently offered by the Federal government to attract highly qualified candidates. Relocation Expenses, Recruitment Incentives, Superior Qualifications and Special Needs Pay-Setting Authority may be negotiable. Click here for Additional Information. The position may be located at any of the DOL office locations, if available. The advertised salary range reflects the minimum and maximum pay for all locations. Final salary will be determined based on the selectee's assigned duty station in accordance with applicable locality pay tables. The role supports the Chief Information Officer (OCIO) and its Directorate of Cybersecurity, which consists of the following divisions: Cybersecurity Governance, Cybersecurity Authorization, and Security Operations Center. Under the direction of the Department's Chief Information Security Officer(CISO), the Directorate manages the enterprise-wide organizational risk associated with the operation of unclassified and classified information systems through a distribution model that provides resiliency in the face of evolving threats. Major duties include, but are not limited to: Review and evaluate security control assessment findings to determine risk significance, recommend appropriate responses, and align remediation actions with organizational risk tolerance and priorities. Consult with authorizing officials. Advises on whether findings represent significant risk and require immediate remediation. Develop informed recommendations for initiating immediate remediation activities where findings can be easily remediated. Update assessment reports with results from reassessments while preserving original findings. Revise and maintain security and privacy plans to reflect the current state of implemented controls, including updates resulting from corrective actions taken by system owners or common control providers. Verify that system security and privacy documentation accurately describes all implemented controls, including compensating controls applied to meet security requirements. Develop comprehensive Plans of Action and Milestones (POA&Ms) that include timelines, deadlines, methods, Measures of Effectiveness, and Measures of Success to track remediation progress. Administer the Agency Computer Security Awareness Training Program, ensuring mandatory compliance and delivering specialized cybersecurity training tailored to workforce needs. Design, maintain, and implement the Department's IT Security Training and Awareness Program in collaboration with departmental IT leaders and security professionals. Enhance secure system operations by proactively addressing security issues identified through continuous monitoring, control assessments, and incident response activities. Major duties for this position at the GS-14 level are similar to the GS-13, however, they are performed under less supervision. Qualifications: You must meet the Basic Requirements and the Specialized Experience to qualify for the IT Specialist (AI), as described below. Basic Qualifications: Applicants must have IT-related experience demonstrating each of the following competencies listed below: Attention to Detail - Is thorough when performing work and conscientious about attending to detail. Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. Decision Making - Makes sound, well-informed, and objective decisions; perceives the impact and implications of decisions; commits to action, even in uncertain situations, to accomplish organizational goals; causes change. Information Management - Identifies a need for and knows where or how to gather information; organizes and maintains information or information management systems. Interpersonal Skills - Shows understanding, friendliness, courtesy, tact, empathy, concern, and politeness to others; develops and maintains effective relationships with others; may include effectively dealing with individuals who are difficult, hostile, or distressed; relates well to people from varied backgrounds and different situations Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. Teamwork - Encourages and facilitates cooperation, pride, trust, and group identity; fosters commitment and team spirit; works with others to achieve goals. Technical Competence - Uses knowledge that is acquired through formal training or on-the-job experience to perform one's job; works with, understands, and evaluates technical information related to the job; advises others on technical issues. AND Applicants must have 52 weeks of specialized experience equivalent to at least the next lower grade level, in the Federal Service. For GS-13 : Applicants must have 52 weeks of specialized experience equivalent to at least the next lower grade level GS-12 in the Federal Service. For GS-14 : Applicants must have 52 weeks of specialized experience equivalent to at least the next lower grade level, GS-13 in the Federal Service. Specialized Experience is the experience that equipped the applicant with the particular knowledge, skills, and abilities (KSA's) to perform the duties of the position successfully, and that is typically in or related to the position to be filled. To be creditable, specialized experience must have been equivalent to at least the next lower grade level. Applicants must meet 3 of the 4 statements below to be found qualified. Qualifying specialized experience for GS-13 includes: Experience independently managing, implementing, and maintaining enterprise cloud services and cloud applications within a defined program area, ensuring reliability, availability, and compliance with organizational standards. Experience applying expert-level knowledge of the Federal Information Security Modernization Act (FISMA), National Institute of Standards and Technology (NIST) Risk Management Framework (RMF), and related Cybersecurity policies to assigned systems. Experience conducting detailed analysis of vulnerability scan results, collaborating with system owners and technical teams to coordinate remediation, and verifying the secure deployment of IT applications and systems. Experience supporting the development, review, and implementation of agency security policies, procedures, and standards, and ensuring program-level compliance with governance and regulatory mandates. Qualifying specialized experience for GS-14 includes: Experience with leading the management, implementation, and optimization of enterprise cloud services and cloud applications across multiple programs. Experience with serving as a technical authority on FISMA, NIST RMF, and federal cybersecurity policies; interpreting requirements for senior leadership, shaping organizational risk decisions, and developing enterprise-level compliance strategies. Experience with coordinating remediation efforts across cross-functional teams and ensuring secure deployment practices are integrated into enterprise processes. Experience with developing, implementing, and evaluating agency-wide security governance frameworks, and advising executives on security posture, compliance risks, and mitigation strategies. View the full announcement and apply on USAJOBS.gov.
Expires August 23, 2026

Share this Job

Location

Map of Phoenix, AZ

Browse by Category

Jobs by City