hirly

Centers for Medicare & Medicaid Services

IT Specialist (Security)

Woodlawn, Maryland, United States

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Centers for Medicare & Medicaid Services first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Mid level
Stated salary
$121,785 – $158,322 per year
Country
US
Work mode
On-site / unstated
First seen by hirly
2 Oct 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Summary

This position is located in the Department of Health & Human Services (HHS), Centers for Medicare & Medicaid Services (CMS), Office of Communications(OC), Web & Emerging Technologies Group (WETG), Division of Website Operations (DWO). As a IT Specialist (Security), GS-2210-13, you will review, analyze, develop, publish, promote, and implement awareness of enterprise-wide HHS information technology (IT) security and/or system development life cycle (SDLC) policies and standards.

Duties

  • Acts as ISSO for assigned WETG systems, ensuring ADOs and contractors meet security and risk framework requirements (NIST 800-53, FISMA, FedRAMP) across the authorization lifecycle, including control testing, risk decisions, and threat modeling.
  • Direct integration of security controls into the DevSecOps pipeline, guiding contractors on compliance-as-code (e.g., InSpec), automated vulnerability scanning, and evidence generation, while verifying automated results truly reflect compliance.
  • Oversee contractor and vendor security performance by assessing security impacts of changes, reviewing assessment reports, tracking POA-Ms to closure, enforcing CMS testing standards, and holding ADOs accountable to contract security commitments.
  • Drive incident response and continuous monitoring, reporting security incidents per CMS Incident Handling Guidelines, partnering with CMS security operations, and ensuring 24x7x365 monitoring coverage for assigned systems.
  • Keep security documentation current, including System Security Plans, Risk Assessment Reports, and Contingency Plans, and coordinates annual assessments and penetration testing to support Authority to Operate (ATO) decisions.

Qualifications

ALL QUALIFICATION REQUIREMENTS MUST BE MET BY THE CLOSING DATE OF THIS ANNOUNCEMENT. Your resume (limited to no more than 2 pages) must include detailed information as it relates to the responsibilities and specialized experience for this position. Evidence of copying and pasting directly from the vacancy announcement without clearly documenting supplemental information to describe your experience will result in an ineligible rating. This will prevent you from being considered further. There is a BASIC REQUIREMENT AND MINIMUM QUALIFICATION REQUIREMENT for this position. You must meet both requirements. BASIC REQUIREMENT: You must have IT-related experience, at the GS-12 grade level in the federal government, demonstrating each of the four competencies listed: I have IT-related experience, demonstrated by paid or unpaid experience obtained in either the private or public sector and/or completion of specific, intensive training that demonstrates that I possess each of the following four competencies: (1) Attention to Detail - Is thorough when performing work and conscientious about attending to detail. (2) Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. (3) Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. (4) Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. AND MINIMUM QUALIFICATION: In order to qualify for the GS-13, you must meet the following: You must demonstrate in your resume at least one year (52 weeks) of qualifying specialized experience equivalent to the GS-12 grade level in the Federal government, obtained in either the private or public sector, to include: 1) Applying security policies, standards, and risk management frameworks (such as NIST SP 800-53, FISMA, FedRAMP, or equivalent industry frameworks like ISO 27001 or SOC 2) to assess, authorize, and continuously monitor the security posture of information systems; 2) Overseeing or advising on the integration of security controls into a DevSecOps pipeline, including compliance-as-code, automated vulnerability scanning, and automated generation of security control evidence; 3) Managing or coordinating third-party contractor or vendor security deliverables, including reviewing security assessment reports, tracking remediation of findings, and enforcing compliance with security requirements and timelines; AND 4) Leading or contributing to incident response activities, security control assessments, and the development or maintenance of system security documentation (such as System Security Plans, Contingency Plans, or Risk Assessment Reports). Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional, philanthropic, religious, spiritual, community, student, social). Volunteer work helps build critical competencies, knowledge, and skills, and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.

Original posting on Centers for Medicare & Medicaid Services's site ↗

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job