MAS - Assurit Consulting Group LLC - 47QTCA18D00JZ

PDF 2 MB

Attached to
Federal Supply Schedule 47QTCA18D00JZ Federal contract IDV
Contract number
47QTCA18D00JZ
Issued by
GSA Federal Acquisition Service

About this file

This document provides a price list for a federal supply schedule contract held by Assurit Consulting Group, LLC. The contract was awarded on September 5, 2018 as a Multiple Award Schedule contract under GSA's Federal Acquisition Service. It includes labor rates for cybersecurity specialists, program managers, technical specialists, and technical writers through September 4, 2028. SINs awarded include IT professional services, highly adaptive cybersecurity services, and order level materials. The price list outlines hourly rates by labor category and option year. Highly adaptive cybersecurity services subcategories awarded are high value asset assessments, risk and vulnerability assessments, cyber hunt, incident response, and penetration testing.

Assurit Consulting Group, LLC Pricelist and/or Vendor Terms and Conditions for 47QTCA18D00JZ, a Federal Supply Schedule awarded to Assurit Consulting Group, LLC, under Information Technology Schedule 70 (IT-70)

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Contract #47QTCA18D00JZ

General Services General Services Administration Multiple Administration Multiple Award ScheduleAward Schedule Large Category Information Technology

Special Item No. SIN 54151S – IT Professional Services Special Item No. SIN 54151HACS – Highly Adaptive Cybersecurity Services (HACS) Special Item No. SIN OLM – Order Level Materials

Authorized Information Technology Schedule Pricelist General Purpose Commercial Information Technology Equipment, Software and Services

Period Covered by Contract September 5, 2024 through September 4, 2029

Minority-Owned, 8(a) Small Disadvantaged Company

Products and ordering information in this Authorized Information Technology Schedule Pricelist are also available on the GSA Advantage! System (http://www.gsaadvantage.gov)

Assurit Consulting Group, LLC 11325 Random Hills Road, Suite 360 Fairfax, Virginia 22030

(703) 225-3305 www.assurit.com

2Assurit | Contract Number: 47QTCA18D00JZ

GSA Multiple Award Schedule Large Category Information Technology

General Services Administration

Ordering on Federal Schedules For more information on ordering on ordering go to the following website: https://www.gsa.gov/schedules.

Contractor

Assurit Consulting Group, LLC 11325 Random Hills Road, Suite 360 Fairfax, VA 22030

(703) 225-3305 info@assurit.com www.assurit.com

Contractor’s Administration Source Sandeep K. Tuteja President and CEO 11325 Random Hills Road, Suite 360 Fairfax, VA 22030

(703) 927-4111 sunny.tuteja@assurit.com

Business Size 8(a) Small Business

Federal Acquisition Service Authorized Federal Supply Schedule FSS Price List Online access to contract ordering information, terms and conditions, up-to-date pricing, and the option to create an electronic delivery order is available through GSA Advantage!, a menu-driven database system. The internet address for GSA Advantage! Is http://www.gsaadvantage.

gov

Schedule Title Multiple Award Schedule (PSC Group: Information Technology Category)

FSC Classes/Product Codes

• D310 - IT and Telecom - Cyber Security and Data

Backup

• D399 - IT and Telecom - Other IT and Telecommunications

Contract Number

47QTCA18D00JZ

Contract Period 09/05/2024 through 09/04/2029

Modification Number PS-A888 - Jan 26, 2025

Assurit | Contract Number: 47QTCA18D00JZ 3

Large Category Information Technology

Customer Information

5. Point(s) Of Production

N/A

6. Discount From List Prices

GSA Net Prices are shown in the below GSA Pricelist. Negotiated discounts have been applied and the IFF has been added.

7. Quantity Discount(s)

None

8. Prompt Payment Terms

1% Net 10. Information for Ordering Offices:

Prompt payment terms cannot be negotiated out of the contractual agreement in exchange for other concessions.

9. Foreign Items

N/A

10a. Time of Delivery

Negotiated at Task Order Level.

10b. Expedited Delivery

Items available for expedited delivery are noted in this price list or negotiated at the task order level.

10c. Overnight And 2-Day Delivery

Overnight and 2-day delivery are available.

Contact the Contractor for rates.

10d. Urgent Requirements

Agencies can contact the Contractor’s representative to affect a faster delivery.

Customers are encouraged to contact the contractor for the purpose of requesting accelerated delivery.

11. FOB Point

Destination

12a. Ordering Address

Same as contractor’s address.

1a. Table Of Awarded Special Item Numbers (SINs)

SINs Description

54151S IT Professional Services

54151HACS Highly Adaptive Cybersecurity

OLM Order Level Materials

1b. Lowest Priced Model Number and Unit Price for Each

SIN

N/A (Government net price based on a unit of one)

1c. Hourly Rates (Services only)

Available on Page 19.

2. Maximum Order*

$500,000 per SIN and $500,000 per order

*NOTE TO ORDERING ACTIVITIES: If the best value selection places your order over the Maximum Order identified in this catalog/pricelist, you have an opportunity to obtain a better schedule contract price.

Before placing your order, contact the aforementioned contactor for a better price. The contractor may (1) offer a new price for this requirement (2) offer the lowest price available under this contract or (3) decline the order. A delivery order that exceeds the maximum order may be placed under the schedule contract in accordance with FAR 8.404.

3. Minimum Order

$100

4. Geographic Coverage

Domestic and overseas delivery within the 48 contiguous states, Alaska, Hawaii, Puerto Rico, Washington, DC, and U.S. Territories. Note that for products, domestic delivery also includes a port or consolidation point, within the aforementioned areas, for orders received from overseas activities.

4Assurit | Contract Number: 47QTCA18D00JZ

Large Category Information Technology

12b. Ordering Procedures

Ordering procedures: See Federal Acquisition Regulation (FAR) 8.405-3.

13. Payment Address

Same as contractor’s address.

14. Warranty Provision

N/A

15. Export Packing Charges

N/A

16. Terms and Conditions of Rental, Maintenance, And Repair (If Applicable)

N/A

17. Terms And Conditions of Installation (If Applicable)

N/A

18a. Terms and Conditions of Repair Parts Indicating Date Of Parts Price Lists And Any Discounts From List Prices (If Applicable)

N/A

18b. Terms and Conditions for Any Other Services (If Applicable)

N/A

19. List Of Service and Distribution Points (If Applicable)

N/A

20. List Of Participating Dealers (If Applicable)

N/A

21. Preventive Maintenance (If Applicable)

N/A

22a. Special Attributes Such as Environmental Attributes (e.g. recycled content, energy efficiency, and/or reduced pollutants)

N/A

22b. Section 508 Compliance for Electronic and Information Technology (EIT)

Section 508 compliance information on the supplies and services in this contract are available at the following website address (URL): N/A

23. UEI Number & Cage Code

UEI: DL3JL6J1XG98

CAGE CODE: 6VE87

24. Notification Regarding Registration in System for Award Management (SAM) Database

Contractor has an Active Registration in the SAM.

G

SA

M ultiple A w ard Schedule

L A B O R C AT E G O R Y D E S C R I P T I O N S

54151HACS

LABOR CATEGORIES

CS Cybersecurity Specialist

CS PM Cybersecurity Program Manager

IAM Identity and Access Management Engineer

IAA Information Assurance Analyst

HVA High Value Asset Assessor

VME Vulnerability Management Engineer

OSE Offensive Security Engineer

PT Penetration Tester

6Assurit | Contract Number: 47QTCA18D00JZ

Large Category Information Technology

Cybersecurity Specialist (CS)

Level Minimum Experience Functional Responsibility Minimum Education

CS I

1 year of general work experience OR demonstrated ability to perform based on certifications, training, experience and/or education

The Cybersecurity Specialist may be responsible for managing and/or performing one or several of the following functions:

risk and vulnerability assessments via the use of automated vulnerability and compliance tools and/or manual assessment based on applicable laws, regulations and guidance; penetration testing to determine the security posture of a system through the use of ethical hacking techniques and automated and manual testing; post-breach forensic activities to determine the vulnerabilities exploited to gain access to systems and/ or information and creation/implementation of a post-breach remediation plan; incident response, contingency plan and/ or disaster recovery planning, training, implementation or remediation activities; information security policy/procedure development; information security training activities;

Information System Security Officer (ISSO) duties to onboard and continuously monitor General Support Systems (GSS) and/ or Major Applications (MA) through the Risk Management Framework (RMF); internal or external security assessments/ audits; security architecture development, review and implementation based on industry best practices; security-related activities for GSSs and/or MAs deployed in a cloud environment including Amazon Web Services (AWS), Microsoft Azure, and others; cybersecurity support services to properly implement applicable laws, regulations, directives, guidelines and acts such as the Federal Information Security Management Act (FISMA), National Institute of Standards and Technology (NIST) Special Publication (SP) 800 Series, Federal Risk and Authorization Management Program (FedRAMP), Health Insurance Portability and Accountability Act (HIPAA), and others;

installation, configuration and use of industry leading security tools such as Splunk, Nessus, WebInspect, DbProtect, Burp Suite Pro and others; Plan of Action and Milestone (POA&M) creation, tracking and remediation.

Associate’s Degree

CS II

1 year of general work experience OR 1 year of applicable functional experience

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• CISSP, CISA, CEH,

GWAPT, GPEN, CCSP or equivalent = 2 years of general work experience each

• SEC+, NET+, GSEC, CCSK

or equivalent = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2 years of applicable functional experience

CS III

3 years of general work experience OR 2 years of applicable functional experience

CS IV

6 years of general work experience OR 3 years of applicable functional experience

CS V

8 years of general work experience OR 6 years of applicable functional experience

CS VI

10 years of general work experience OR 8 years of applicable functional experience

CS SME

12 years of general work experience OR 10 years of applicable functional experience

Assurit | Contract Number: 47QTCA18D00JZ 7

Large Category Information Technology

Cybersecurity Specialist (CS)

Level Minimum Experience Functional Responsibility Minimum Education

CS SME II

14 years of general work experience OR 12 years of applicable functional experience

The Cybersecurity Specialist may be responsible for managing and/or performing one or several of the following functions:

risk and vulnerability assessments via the use of automated vulnerability and compliance tools and/or manual assessment based on applicable laws, regulations and guidance; penetration testing to determine the security posture of a system through the use of ethical hacking techniques and automated and manual testing; post-breach forensic activities to determine the vulnerabilities exploited to gain access to systems and/ or information and creation/implementation of a post-breach remediation plan; incident response, contingency plan and/ or disaster recovery planning, training, implementation or remediation activities; information security policy/procedure development; information security training activities;

Information System Security Officer (ISSO) duties to onboard and continuously monitor General Support Systems (GSS) and/ or Major Applications (MA) through the Risk Management Framework (RMF); internal or external security assessments/ audits; security architecture development, review and implementation based on industry best practices; security-related activities for GSSs and/or MAs deployed in a cloud environment including Amazon Web Services (AWS), Microsoft Azure, and others; cybersecurity support services to properly implement applicable laws, regulations, directives, guidelines and acts such as the Federal Information Security Management Act (FISMA), National Institute of Standards and Technology (NIST) Special Publication (SP) 800 Series, Federal Risk and Authorization Management Program (FedRAMP), Health Insurance Portability and Accountability Act (HIPAA), and others;

installation, configuration and use of industry leading security tools such as Splunk, Nessus, WebInspect, DbProtect, Burp Suite Pro and others; Plan of Action and Milestone (POA&M) creation, tracking and remediation. Operates as an advanced subject matter expert (SME), leading strategic technical initiatives and influencing organizational direction through deep expertise.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• CISSP, CISA, CEH,

GWAPT, GPEN, CCSP or equivalent = 2 years of general work experience each

• SEC+, NET+, GSEC, CCSK

or equivalent = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2 years of applicable functional experience

8Assurit | Contract Number: 47QTCA18D00JZ

Large Category Information Technology

Cybersecurity Program Manager (CS PM)

Level Minimum Experience Functional Responsibility Minimum Education

CS PM I

5 years of general work experience OR 3 years of applicable functional experience

The Cybersecurity Program Manager is responsible for overseeing and managing cybersecurity programs, ensuring alignment with client objectives, and maintaining a secure and resilient IT environment. This role involves serving as the primary interface with the client's senior management, providing strategic guidance to meet cybersecurity goals. The Cybersecurity Program Manager directs lower-level managers, cybersecurity specialists, and technical staff, ensuring effective use of resources and adherence to cybersecurity best practices. They lead cross-functional teams, employing advanced cybersecurity management and technical skills to achieve program objectives.

This includes developing and overseeing budgets, controlling costs, and generating reports to track project status and cybersecurity metrics. The Cybersecurity Program Manager formulates and enforces cybersecurity work standards, assigns tasks, manages schedules, resolves technical issues, and supervises staff to ensure adherence to cybersecurity policies.

Additionally, they communicate the organization’s cybersecurity goals, policies, and standards to team members and subcontractors to maintain a secure operational environment.

Oversees projects, coordinating resources, managing risks, and maintaining schedules.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• PM-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2 years of applicable functional experience

CS PM II

8 years of general work experience OR 6 years of applicable functional experience

The Cybersecurity Program Manager is responsible for overseeing and managing cybersecurity programs, ensuring alignment with client objectives, and maintaining a secure and resilient IT environment. This role involves serving as the primary interface with the client's senior management, providing strategic guidance to meet cybersecurity goals. The Cybersecurity Program Manager directs lower-level managers, cybersecurity specialists, and technical staff, ensuring effective use of resources and adherence to cybersecurity best practices. They lead cross-functional teams, employing advanced cybersecurity management and technical skills to achieve program objectives.

This includes developing and overseeing budgets, controlling costs, and generating reports to track project status and cybersecurity metrics. The Cybersecurity Program Manager formulates and enforces cybersecurity work standards, assigns tasks, manages schedules, resolves technical issues, and supervises staff to ensure adherence to cybersecurity policies.

Additionally, they communicate the organization’s cybersecurity goals, policies, and standards to team members and subcontractors to maintain a secure operational environment.

Leads projects from start to finish, fostering collaboration and achieving objectives.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• PM-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2

Assurit | Contract Number: 47QTCA18D00JZ 9

Large Category Information Technology

Identity and Access Management Engineer (IAM)

Level Minimum Experience Functional Responsibility Minimum Education

IAM I

3 year of general work experience OR 2 years of applicable functional experience

The Identity and Access Management (IAM) Engineer is responsible for designing, implementing, and managing identity and access management solutions to ensure secure access to systems, applications, and data. This includes developing and maintaining identity governance frameworks, enforcing access controls, and managing authentication and authorization processes. The IAM Engineer designs and implements solutions such as identity governance, single sign-on (SSO), multi-factor authentication (MFA), and role-based access control (RBAC).

They manage identity lifecycles, including provisioning and de-provisioning, and collaborate with IT, security, and compliance teams to ensure alignment with federal regulations and industry best practices. The IAM Engineer also monitors IAM systems, conducts risk assessments, implements federated identity solutions, and troubleshoots issues to ensure the high availability and performance of IAM platforms. Completes tasks with limited supervision, addressing straightforward technical challenges.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2 years of applicable functional experience

IAM II

4 years of general work experience OR 3 years of applicable functional experience

The Identity and Access Management (IAM) Engineer is responsible for designing, implementing, and managing identity and access management solutions to ensure secure access to systems, applications, and data. This includes developing and maintaining identity governance frameworks, enforcing access controls, and managing authentication and authorization processes. The IAM Engineer designs and implements solutions such as identity governance, single sign-on (SSO), multi-factor authentication (MFA), and role-based access control (RBAC).

They manage identity lifecycles, including provisioning and de-provisioning, and collaborate with IT, security, and compliance teams to ensure alignment with federal regulations and industry best practices. The IAM Engineer also monitors IAM systems, conducts risk assessments, implements federated identity solutions, and troubleshoots issues to ensure the high availability and performance of IAM platforms. Independently performs tasks, solving moderately complex problems and applying advanced knowledge.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2 years of applicable functional experience

IAM III

5 years of general work experience OR 4 years of applicable functional experience

The Identity and Access Management (IAM) Engineer is responsible for designing, implementing, and managing identity and access management solutions to ensure secure access to systems, applications, and data. This includes developing and maintaining identity governance frameworks, enforcing access controls, and managing authentication and authorization processes. The IAM Engineer designs and implements solutions such as identity governance, single sign-on (SSO), multi-factor authentication (MFA), and role-based access control (RBAC).

They manage identity lifecycles, including provisioning and de-provisioning, and collaborate with IT, security, and compliance teams to ensure alignment with federal regulations and industry best practices. The IAM Engineer also monitors IAM systems, conducts risk assessments, implements federated identity solutions, and troubleshoots issues to ensure the high availability and performance of IAM platforms. Handles complex tasks, ensuring deliverables meet technical requirements and standards.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2

10Assurit | Contract Number: 47QTCA18D00JZ

Large Category Information Technology

Information Assurance Analyst (IAA)

Level Minimum Experience Functional Responsibility Minimum Education

IAA I

1 year of general work experience OR 1 year of applicable functional experience

The Information Assurance Analyst is responsible for ensuring the confidentiality, integrity, and availability of systems and data through the development, implementation, and enforcement of security policies, procedures, and controls. This role involves performing security assessments, vulnerability scans, and risk analyses to identify potential threats and weaknesses in systems. The Information Assurance Analyst ensures compliance with federal regulations and industry standards by conducting security audits, managing incident response, and collaborating with stakeholders to implement security solutions.

They maintain security documentation, assist in the development of disaster recovery plans, and continuously monitor systems to detect and mitigate security incidents. Additionally, the analyst provides guidance on security best practices and collaborates with IT teams to enhance security postures and prevent breaches. Performs tasks under close supervision, focusing on building foundational technical skills.

Associate’s Degree

IAA II

2 years of general work experience OR 1 years of applicable functional experience

The Information Assurance Analyst is responsible for ensuring the confidentiality, integrity, and availability of systems and data through the development, implementation, and enforcement of security policies, procedures, and controls. This role involves performing security assessments, vulnerability scans, and risk analyses to identify potential threats and weaknesses in systems. The Information Assurance Analyst ensures compliance with federal regulations and industry standards by conducting security audits, managing incident response, and collaborating with stakeholders to implement security solutions.

They maintain security documentation, assist in the development of disaster recovery plans, and continuously monitor systems to detect and mitigate security incidents. Additionally, the analyst provides guidance on security best practices and collaborates with IT teams to enhance security postures and prevent breaches. Completes tasks with limited supervision, addressing straightforward technical challenges.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2 years of applicable functional experience

IAA III

3 years of general work experience OR 2 years of applicable functional experience

The Information Assurance Analyst is responsible for ensuring the confidentiality, integrity, and availability of systems and data through the development, implementation, and enforcement of security policies, procedures, and controls. This role involves performing security assessments, vulnerability scans, and risk analyses to identify potential threats and weaknesses in systems. The Information Assurance Analyst ensures compliance with federal regulations and industry standards by conducting security audits, managing incident response, and collaborating with stakeholders to implement security solutions.

They maintain security documentation, assist in the development of disaster recovery plans, and continuously monitor systems to detect and mitigate security incidents. Additionally, the analyst provides guidance on security best practices and collaborates with IT teams to enhance security postures and prevent breaches. Independently performs tasks, solving moderately complex problems and applying advanced knowledge.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2

Assurit | Contract Number: 47QTCA18D00JZ 11

Large Category Information Technology

Information Assurance Analyst (IAA)

Level Minimum Experience Functional Responsibility Minimum Education

IAA IV

4 years of general work experience OR 3 years of applicable functional experience

The Information Assurance Analyst is responsible for ensuring the confidentiality, integrity, and availability of systems and data through the development, implementation, and enforcement of security policies, procedures, and controls. This role involves performing security assessments, vulnerability scans, and risk analyses to identify potential threats and weaknesses in systems. The Information Assurance Analyst ensures compliance with federal regulations and industry standards by conducting security audits, managing incident response, and collaborating with stakeholders to implement security solutions.

They maintain security documentation, assist in the development of disaster recovery plans, and continuously monitor systems to detect and mitigate security incidents. Additionally, the analyst provides guidance on security best practices and collaborates with IT teams to enhance security postures and prevent breaches. Handles complex tasks, ensuring deliverables meet technical requirements and standards.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2

12Assurit | Contract Number: 47QTCA18D00JZ

Large Category Information Technology

High Value Asset Assessor (HVA)

Level Minimum Experience Functional Responsibility Minimum Education

HVA I

3 years of general work experience OR 1 year of applicable functional experience

The High Value Asset (HVA) Assessor is responsible for identifying, assessing, and securing critical assets within an organization that are essential to national security, economic stability, or public health and safety. This role involves conducting comprehensive risk assessments and security evaluations to ensure that HVAs are protected against cyber threats and vulnerabilities. The HVA Assessor collaborates with stakeholders to prioritize assets, implement security controls, and ensure compliance with federal regulations and standards, such as the Federal Information Security Modernization Act (FISMA) and guidelines from the Cybersecurity and Infrastructure Security Agency (CISA). Key responsibilities include performing asset identification, risk analysis, vulnerability assessments, and implementing mitigation strategies. The assessor also develops incident response plans, provides recommendations for security enhancements, and supports continuous monitoring of HVAs to safeguard them from emerging threats. Completes tasks with limited supervision, addressing straightforward technical challenges.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2 years of applicable functional experience

HVA II

5 years of general work experience OR 3 years of applicable functional experience

The High Value Asset (HVA) Assessor is responsible for identifying, assessing, and securing critical assets within an organization that are essential to national security, economic stability, or public health and safety. This role involves conducting comprehensive risk assessments and security evaluations to ensure that HVAs are protected against cyber threats and vulnerabilities. The HVA Assessor collaborates with stakeholders to prioritize assets, implement security controls, and ensure compliance with federal regulations and standards, such as the Federal Information Security Modernization Act (FISMA) and guidelines from the Cybersecurity and Infrastructure Security Agency (CISA). Key responsibilities include performing asset identification, risk analysis, vulnerability assessments, and implementing mitigation strategies. The assessor also develops incident response plans, provides recommendations for security enhancements, and supports continuous monitoring of HVAs to safeguard them from emerging threats. Independently performs tasks, solving moderately complex problems and applying advanced knowledge.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2

Assurit | Contract Number: 47QTCA18D00JZ 13

Large Category Information Technology

High Value Asset Assessor (HVA)

Level Minimum Experience Functional Responsibility Minimum Education

HVA III

7 years of general work experience OR 5 years of applicable functional experience

The High Value Asset (HVA) Assessor is responsible for identifying, assessing, and securing critical assets within an organization that are essential to national security, economic stability, or public health and safety. This role involves conducting comprehensive risk assessments and security evaluations to ensure that HVAs are protected against cyber threats and vulnerabilities. The HVA Assessor collaborates with stakeholders to prioritize assets, implement security controls, and ensure compliance with federal regulations and standards, such as the Federal Information Security Modernization Act (FISMA) and guidelines from the Cybersecurity and Infrastructure Security Agency (CISA). Key responsibilities include performing asset identification, risk analysis, vulnerability assessments, and implementing mitigation strategies. The assessor also develops incident response plans, provides recommendations for security enhancements, and supports continuous monitoring of HVAs to safeguard them from emerging threats. Handles complex tasks, ensuring deliverables meet technical requirements and standards.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2

14Assurit | Contract Number: 47QTCA18D00JZ

Large Category Information Technology

Vulnerability Management Engineer (VME)

Level Minimum Experience Functional Responsibility Minimum Education

VME I

3 years of general work experience OR 1 year of applicable functional experience

The Vulnerability Management Engineer is responsible for identifying, analyzing, and remediating security vulnerabilities across an organization’s network, systems, and applications.

This role involves the implementation and operation of vulnerability scanning tools, managing the vulnerability lifecycle, and coordinating with IT and security teams to address identified weaknesses. The Vulnerability Management Engineer performs regular scans, risk assessments, and penetration testing to ensure that vulnerabilities are promptly discovered and mitigated. They prioritize vulnerabilities based on criticality, develop remediation plans, and track the resolution of issues to closure. Additionally, the engineer collaborates with stakeholders to maintain compliance with security standards and regulations, provides guidance on patch management, and continuously monitors the threat landscape to enhance the organization’s security posture. Completes tasks with limited supervision, addressing straightforward technical challenges.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2 years of applicable functional experience

VME II

5 years of general work experience OR 3 years of applicable functional experience

The Vulnerability Management Engineer is responsible for identifying, analyzing, and remediating security vulnerabilities across an organization’s network, systems, and applications.

This role involves the implementation and operation of vulnerability scanning tools, managing the vulnerability lifecycle, and coordinating with IT and security teams to address identified weaknesses. The Vulnerability Management Engineer performs regular scans, risk assessments, and penetration testing to ensure that vulnerabilities are promptly discovered and mitigated. They prioritize vulnerabilities based on criticality, develop remediation plans, and track the resolution of issues to closure. Additionally, the engineer collaborates with stakeholders to maintain compliance with security standards and regulations, provides guidance on patch management, and continuously monitors the threat landscape to enhance the organization’s security posture. Independently performs tasks, solving moderately complex problems and applying advanced knowledge.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2 years of applicable functional experience

VME III

7 years of general work experience OR 5 years of applicable functional experience

The Vulnerability Management Engineer is responsible for identifying, analyzing, and remediating security vulnerabilities across an organization’s network, systems, and applications.

This role involves the implementation and operation of vulnerability scanning tools, managing the vulnerability lifecycle, and coordinating with IT and security teams to address identified weaknesses. The Vulnerability Management Engineer performs regular scans, risk assessments, and penetration testing to ensure that vulnerabilities are promptly discovered and mitigated. They prioritize vulnerabilities based on criticality, develop remediation plans, and track the resolution of issues to closure. Additionally, the engineer collaborates with stakeholders to maintain compliance with security standards and regulations, provides guidance on patch management, and continuously monitors the threat landscape to enhance the organization’s security posture. Handles complex tasks, ensuring deliverables meet technical requirements and standards.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2

Assurit | Contract Number: 47QTCA18D00JZ 15

Large Category Information Technology

Offensive Security Engineer (OSE)

Level Minimum Experience Functional Responsibility Minimum Education

OSE I

3 years of general work experience OR 1 year of applicable functional experience

The Offensive Security Engineer is responsible for simulating advanced cyber attacks to identify and exploit security vulnerabilities across an organization’s infrastructure, applications, and networks. This role involves developing and executing offensive security tests, including penetration testing, red teaming, and adversarial simulations, to assess the effectiveness of existing security measures. The Offensive Security Engineer uses a wide range of tools, tactics, and techniques to mimic real-world threat actors, identifying gaps in defenses and providing actionable insights for improvement.

They collaborate with security and IT teams to remediate vulnerabilities, develop threat models, and enhance overall security posture. The engineer also stays up to date on emerging threats and attack vectors, continuously refining testing methodologies to stay ahead of cyber threats and ensure proactive defense strategies. Completes tasks with limited supervision, addressing straightforward technical challenges.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2 years of applicable functional experience

OSE II

5 years of general work experience OR 3 years of applicable functional experience

The Offensive Security Engineer is responsible for simulating advanced cyber attacks to identify and exploit security vulnerabilities across an organization’s infrastructure, applications, and networks. This role involves developing and executing offensive security tests, including penetration testing, red teaming, and adversarial simulations, to assess the effectiveness of existing security measures. The Offensive Security Engineer uses a wide range of tools, tactics, and techniques to mimic real-world threat actors, identifying gaps in defenses and providing actionable insights for improvement.

They collaborate with security and IT teams to remediate vulnerabilities, develop threat models, and enhance overall security posture. The engineer also stays up to date on emerging threats and attack vectors, continuously refining testing methodologies to stay ahead of cyber threats and ensure proactive defense strategies. Independently performs tasks, solving moderately complex problems and applying advanced knowledge.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2 years of applicable functional experience

OSE III

7 years of general work experience OR 5 years of applicable functional experience

The Offensive Security Engineer is responsible for simulating advanced cyber attacks to identify and exploit security vulnerabilities across an organization’s infrastructure, applications, and networks. This role involves developing and executing offensive security tests, including penetration testing, red teaming, and adversarial simulations, to assess the effectiveness of existing security measures. The Offensive Security Engineer uses a wide range of tools, tactics, and techniques to mimic real-world threat actors, identifying gaps in defenses and providing actionable insights for improvement.

They collaborate with security and IT teams to remediate vulnerabilities, develop threat models, and enhance overall security posture. The engineer also stays up to date on emerging threats and attack vectors, continuously refining testing methodologies to stay ahead of cyber threats and ensure proactive defense strategies. Handles complex tasks, ensuring deliverables meet technical requirements and standards.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2

16Assurit | Contract Number: 47QTCA18D00JZ

Large Category Information Technology

Penetration Tester (PT)

Level Minimum Experience Functional Responsibility Minimum Education

PT I

1 year of general work experience OR 1 year of applicable functional experience

The Penetration Tester is responsible for conducting authorized simulated attacks on an organization’s systems, networks, and applications to identify and exploit vulnerabilities before they can be leveraged by malicious actors. This role involves performing thorough penetration tests, vulnerability assessments, and security audits to uncover weaknesses in security controls and infrastructure. The Penetration Tester uses a variety of tools and techniques to assess the security posture of assets and develops comprehensive reports detailing vulnerabilities, risks, and recommended remediation strategies. Additionally, they collaborate with IT, security teams, and stakeholders to prioritize findings and implement corrective actions, ensuring continuous improvement in the organization's overall security posture.

The tester stays informed of the latest threat intelligence and evolving attack methodologies to refine testing strategies and keep defenses robust. Performs tasks under close supervision, focusing on building foundational technical skills.

Associate’s Degree

PT II

3 years of general work experience OR 2 years of applicable functional experience

The Penetration Tester is responsible for conducting authorized simulated attacks on an organization’s systems, networks, and applications to identify and exploit vulnerabilities before they can be leveraged by malicious actors. This role involves performing thorough penetration tests, vulnerability assessments, and security audits to uncover weaknesses in security controls and infrastructure. The Penetration Tester uses a variety of tools and techniques to assess the security posture of assets and develops comprehensive reports detailing vulnerabilities, risks, and recommended remediation strategies. Additionally, they collaborate with IT, security teams, and stakeholders to prioritize findings and implement corrective actions, ensuring continuous improvement in the organization's overall security posture.

The tester stays informed of the latest threat intelligence and evolving attack methodologies to refine testing strategies and keep defenses robust. Completes tasks with limited supervision, addressing straightforward technical challenges.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2 years of applicable functional experience

PT III

5 years of general work experience OR 3 years of applicable functional experience

The Penetration Tester is responsible for conducting authorized simulated attacks on an organization’s systems, networks, and applications to identify and exploit vulnerabilities before they can be leveraged by malicious actors. This role involves performing thorough penetration tests, vulnerability assessments, and security audits to uncover weaknesses in security controls and infrastructure. The Penetration Tester uses a variety of tools and techniques to assess the security posture of assets and develops comprehensive reports detailing vulnerabilities, risks, and recommended remediation strategies. Additionally, they collaborate with IT, security teams, and stakeholders to prioritize findings and implement corrective actions, ensuring continuous improvement in the organization's overall security posture.

The tester stays informed of the latest threat intelligence and evolving attack methodologies to refine testing strategies and keep defenses robust. Independently performs tasks, solving moderately complex problems and applying advanced knowledge.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2

Assurit | Contract Number: 47QTCA18D00JZ 17

Large Category Information Technology

Penetration Tester (PT)

Level Minimum Experience Functional Responsibility Minimum Education

PT IV

7 years of general work experience OR 4 years of applicable functional experience

The Penetration Tester is responsible for conducting authorized simulated attacks on an organization’s systems, networks, and applications to identify and exploit vulnerabilities before they can be leveraged by malicious actors. This role involves performing thorough penetration tests, vulnerability assessments, and security audits to uncover weaknesses in security controls and infrastructure. The Penetration Tester uses a variety of tools and techniques to assess the security posture of assets and develops comprehensive reports detailing vulnerabilities, risks, and recommended remediation strategies. Additionally, they collaborate with IT, security teams, and stakeholders to prioritize findings and implement corrective actions, ensuring continuous improvement in the organization's overall security posture.

The tester stays informed of the latest threat intelligence and evolving attack methodologies to refine testing strategies and keep defenses robust. Handles complex tasks, ensuring deliverables meet technical requirements and standards.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2 years of applicable functional experience

PT V

9 years of general work experience OR 5 years of applicable functional experience

The Penetration Tester is responsible for conducting authorized simulated attacks on an organization’s systems, networks, and applications to identify and exploit vulnerabilities before they can be leveraged by malicious actors. This role involves performing thorough penetration tests, vulnerability assessments, and security audits to uncover weaknesses in security controls and infrastructure. The Penetration Tester uses a variety of tools and techniques to assess the security posture of assets and develops comprehensive reports detailing vulnerabilities, risks, and recommended remediation strategies. Additionally, they collaborate with IT, security teams, and stakeholders to prioritize findings and implement corrective actions, ensuring continuous improvement in the organization's overall security posture.

The tester stays informed of the latest threat intelligence and evolving attack methodologies to refine testing strategies and keep defenses robust. Designs and implements advanced technical solutions, coordinating with others as needed.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2

M ultiple A w ard Schedule

L A B O R C AT E G O R Y D E S C R I P T I O N S

54151S

LABOR CATEGORIES

P SME Principal SME

PJM Project Manager

PM Program Manager

TW Technical Writer

TS Technical Specialist

IT IT Consultant

AN Analyst

Assurit | Contract Number: 47QTCA18D00JZ 19

Large Category Information Technology

Principal SME (P SME)

Level Minimum Experience Functional Responsibility Minimum Education

P SME

10 years of general work experience OR 8 years of applicable functional experience

The Principal Subject Matter Expert provides advanced Information Technology (IT) professional services by collaborating with clients and internal teams to define complex technical requirements and deliver innovative IT solutions tailored to their needs. They lead the design, development, and validation of IT systems, ensuring scalability, robustness, and alignment with project goals while adhering to industry standards and best practices. By partnering with stakeholders, they assess options that consider the client’s environment, budget, and business objectives. This role also involves mentoring team members, managing task allocation, and contributing to project planning efforts, including cost estimation and scheduling. Throughout the project lifecycle, they ensure quality control, compliance with IT standards, and the delivery of secure, high-performing solutions that provide seamless user experiences and successful outcomes.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• IT-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2

20Assurit | Contract Number: 47QTCA18D00JZ

Large Category Information Technology

Project Manager (PJM)

Level Minimum Experience Functional Responsibility Minimum Education

PJM I

3 years of general work experience OR 1 year of applicable functional experience

The Project Manager provides comprehensive oversight of Information Technology (IT) projects, ensuring alignment with client objectives and delivering results in accordance with industry best practices. Serving as the primary liaison with the client’s management personnel, they maintain clear communication and ensure project goals are met efficiently.

They provide leadership to team leads, technical staff, and business personnel, coordinating cross-functional IT efforts to achieve seamless integration and performance. By leveraging management and technical expertise, they effectively manage resources, control project costs, monitor work standards, assign tasks, resolve discrepancies, and supervise personnel. The Project Manager ensures compliance with IT policies, standards, and security requirements while fostering collaboration among team members and subcontractors. Their role guarantees the successful delivery of IT solutions that meet operational, technical, and strategic goals. Supports project efforts with limited oversight, managing smaller tasks and timelines.

Bachelor’s Degree

Acceptable substitutions:

• Master’s Degree = 4 years of general work experience

• PM-related certifications = 1 year of general work experience each

• Associate’s Degree will be considered for individuals with >= 2 years of applicable functional experience

PJM II

5 years of general work experience OR 3 years of applicable functional experience

The Project Manager provides comprehensive oversight of Information Technology (IT) projects, ensuring alignment with client objectives and delivering results in accordance with industry best practices. Serving as the primary liaison with the client’s management personnel, they maintain clear communication and ensure project goals are met efficiently.

They provide leadership to team leads, technical staff, and business personnel, coordinating cross-functional IT efforts to achieve seamless integration and performance. By leveraging management and technical expertise, they effectively manage resources, control project costs, monitor work standards, assign tasks, resolve discrepancies, and supervise personnel.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .