This IT Specialist (Infosec) position is with Deputy Assistant Secretary for Information and Technology (Department of Veterans Affairs) in Phoenix, AZ.
The Office of Information Security (OIS) provides information security and privacy infrastructure for the U.S. Department of Veterans Affairs (VA). The office assures the confidentiality, integrity, and risk management, record management, Freedom of Information Act (FOIA) requests. In addition, the OIS team develops, implements, and oversees the training, communication how VA and its partners safeguard the personally identifiable information (PII) of Veterans and VA employees.
Key duties:
• Major Duties: Conduct risk and vulnerability assessments of planned and installed information systems to identify vulnerabilities, risks, and protection needs. Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials). Interpret patterns of non-compliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program. Provide input in drafting information systems security documentation (e.g., systems security plans, risk assessments, disaster recovery plans, business continuity plans, and user security guides). Develop, maintain, and administer a highly complex information security program which involves security program issues and develop VA security program objectives and plans that respond to current and future VA information technology and information security program requirements. Mastery knowledge of contemporary information technology including hardware, software, communications, networking, data management and administration, higher order computer languages, and expert knowledge of information security and VA's Information Security Program. Mastery knowledge of regulations, federal-wide laws, policies and standards related to CFO and CIO programs generally, and to information security, in particular. Incumbent has the ability to complete fact gathering, organizing, and presentations inherent in requirements analysis, alternatives analysis, technical project proposals, project plans, and overall program coordination. Evaluate security architectures and designs to determine the adequacy of security design and architecture proposed or provided in response to requirements contained in acquisition documents. Ensure that protection and detection capabilities are acquired or developed using the IS security engineering approach and are consistent with organization-level cybersecurity architecture. Participate in the development or modification of the computer environment cybersecurity program plans and requirements. Collaborate with stakeholders to establish the enterprise continuity of operations program, strategy, and mission assurance. The incumbent works under the administrative supervision of the Risk Management Framework Director. Supervisor provides administrative direction, making assignments in terms of broadly defined missions, functions, or team goals. As a recognized authority, the incumbent is delegated complete responsibility to independently organize, plan, carry out assignments, and coordinate as a peer with experts within and across VA. Work Schedule: Monday - Friday, 8:00am - 4:30pm Compressed/Flexible: Compressed/flexible schedule available at the manager's discretion Telework: This position may be authorized for telework. Virtual: This is not a virtual position. Position Description/PD#: IT Specialist (Infosec)/PD17190A Relocation/Recruitment Incentives: Not Authorized Permanent Change of Station (PCS): Not Authorized PCS Appraised Value Offer (AVO): Not Authorized
Qualifications:
To qualify for this position, applicants must meet all requirements by the closing date of this announcement, 10/02/2026. Applicants must have IT-related experience demonstrating each of the four competencies listed below at a proficiency level equivalent to the next lower grade level in federal service You must meet both the Basic Requirement and the Specialized Experience to qualify for this series as described below. Attention to Detail - Is thorough when performing work and conscientious about attending to detail. Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. AND Specialized Experience: You must have one year of specialized experience equivalent to at least the next lower grade GS-13 in the normal line of progression for the occupation in the organization. Specialized experience is defined as Experience developing, maintaining, and administering complex enterprise information security programs where solutions are not off-the-shelf, requiring interpretation of federal-wide laws, policies, and standards; applying and interpreting NIST Risk Management Framework (RMF) guidance, including leading or overseeing Assessment & Authorization (A&A) activities; leading or contributing to enterprise cybersecurity compliance programs, including Governance, Risk, and Compliance (GRC) capabilities; modernizing, sustaining, or overseeing an enterprise Cybersecurity Continuous Monitoring (CCM) program, including automation, integration of risk data, and optimization of monitoring capabilities; overseeing, selecting, implementing, or optimizing enterprise cybersecurity risk management tools (e.g., GRC platforms, vulnerability management systems, dashboards, RMF automation tools); and developing strategic roadmaps or modernization plans to improve continuous monitoring, technology adoption, or enterprise cyber risk visibility. For more information on these qualification standards, please visit the United States Office of Personnel Management's website at https://www.opm.gov/policy-data-oversight/classification-qualifications/general-schedule-qualification-standards/. This occupation is being considered for a Veterans Health Administration enterprise-wide Critical Skills Incentive (CSI). Candidates may be eligible for a lump sum CSI. The amount of lump sum CSI is determined based on appointment date and may be pro-rated as determined by the end date of the CSI. Eligible candidates will be required to sign a service agreement agreeing to an obligated service period and failure to complete the obligated service period may result in a debt for the unearned portion of the CSI. This occupation is currently approved for a Veterans Health Administration enterprise-wide Critical Skills Incentive through [insert date]. Candidates may be eligible for a lump sum CSI for a pro-rated amount if onboard prior to the CSI expiration date. Eligible candidates will be required to sign a service agreement agreeing to an obligated service period and failure to complete the obligated service period may result in a debt for the unearned portion of the CSI. Receiving Service Credit or Earning Annual (Vacation) Leave: Federal Employees earn annual leave at a rate (4, 6 or 8 hours per pay period) which is based on the number of years they have served as a Federal employee. VA may offer newly-appointed Federal employee's credit for their job-related non-federal experience or active duty uniformed military service. This credited service can be used in determining the rate at which they earn annual leave. Such credit must be requested and approved prior to the appointment date and is not guaranteed.
View the full announcement and apply on USAJOBS.gov.