MAS - The One 23 Group Inc. - 47QTCA19D0092

DOCX document 547 KB

Attached to
Federal Supply Schedule 47QTCA19D0092 Federal contract IDV
Contract number
47QTCA19D0092
Issued by
GSA Federal Acquisition Service

About this file

This document provides a price list for labor categories and services available under a General Services Administration (GSA) Federal Supply Schedule (FSS) contract. The contract was awarded to Technical and Management Resources, Inc. on March 29, 2019 and extends through March 28, 2029.

Labor categories covered include cybersecurity specialists, engineers, analysts, and project managers at various levels of experience. Services in the areas of information technology, cybersecurity, and management consulting are offered under Special Item Numbers including Information Technology Professional Services, Highly Adaptive Cybersecurity Services, and Management and Financial Consulting. Products and services are available for order by federal agencies through March 2029. Pricing is provided on a net basis with prompt payment terms of net 30 days.

Technical And Management Resources, Inc. (DBA TMR) Pricelist and/or Vendor Terms and Conditions for 47QTCA19D0092, a Federal Supply Schedule awarded to Technical And Management Resources, Inc. (DBA TMR), under Information Technology Schedule 70 (IT-70)

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

The One 23 Group Inc.

2303 Dulles Station Blvd, Ste 210

Herndon, Virginia 20171 www.theone23group.com Telephone (703) 323-1700 Fax (703) 579-1593

Page | 1

GENERAL SERVICES ADMINISTRATION

Federal Acquisition Service

Authorized Federal Supply Schedule FSS Price List

On-line access to contract ordering information, terms and conditions, up-to-date pricing, and the option to create an electronic delivery order are available through GSA Advantage!®, a menu-driven database system. The INTERNET address GSA Advantage!® is:

GSAAdvantage.gov.

Multiple Award Schedule

FSC Group: Information Technology Services FSC Class: D399

Contract Number: 47QTCA19D0092

Period Covered by Contract: March 29, 2024 through March 28, 2029

Business Size: Small

For more information on ordering go to the following website: https://www.gsa.gov/ schedules GSA Schedules page

Price List current through Modification PS-0011, effective July 25, 2022 Prices

Shown Herein are Net (discount deducted)

2303 Dulles Station Blvd. Ste 210, Herndon, VA 20171 Tel: 703-323-1700 Fax: 703-579-1593

Contract Administrator: Carol Armstrong Email: Carol.Armstrong@theone23group.com http://www.theone23group.com/ http://www.gsa.gov/ mailto:Contracts@theone23group.com

Herndon, Virginia 20171 www.theone23group.com Telephone (703) 323-1700 Fax (703) 579-1593

Page | 2

INFORMATION FOR ALL ORDERING ACTIVITIES

1a. Table of awarded Special Item Numbers:

SIN Disaster Recovery Description 54151HACS 54151HACS/RC Highly Adaptive Cybersecurity Services (HACS) 54151S 54151S/RC Information Technology Professional Services

541611 541611/RC

Management and Financial Consulting, Acquisition and Grants Management Support, and Business Program and Project Management Services

ANCILLARY ANCILLARY/RC Ancillary Supplies and Services OLM OLM/RC Order-Level Materials (OLM)

1b. Identification of the lowest priced model number and lowest unit price for that model for each special item number awarded in the contract.

See Attached Pricelist

1c. If the Contractor is proposing hourly rates, a description of all corresponding commercial job titles, experience, functional responsibility and education for those types of employees or subcontractors who will perform services shall be provided: See Attached Pricelist

2. Maximum order:

SIN 54151S: $500,000.00

SIN 54151HACS: $500,000.00 SIN

OLM: $250,000

SIN ANCILLARY: $250,000 SIN

541611: $1,000,000

3. Minimum order: $100.00

4. Geographic coverage: The Geographic Scope of the Contract will be domestic (50 states, D.C., Puerto Rico).

5. Points of production: N/A

6. Discount from list prices or statement of net price: All pricing represents net prices, discount deducted.

7. Quantity discounts, single shipment to single location: None

8. Prompt payment terms: Net 30; Information for Ordering Offices: Prompt payment terms cannot be negotiated out of the contractual agreement in exchange for other concessions.

9. Foreign items: N/A

10a. Time of Delivery: As negotiated on the task order level

10b. Expedited Delivery: As negotiated on the task order level

10c. Overnight and 2-day delivery: As negotiated on the task order level

10d. Urgent Requirements: As negotiated on the task order level

11. F.O.B. point: Destination http://www.theone23group.com/

Herndon, Virginia 20171 www.theone23group.com Telephone (703) 323-1700 Fax (703) 579-1593

Page | 3

12a. Ordering address: Same as contractor

12b. Ordering procedures: See Federal Acquisition Regulation (FAR) 8.405-3.

13. Payment address: Same as contractor

14. Warranty provision: Standard Commercial Warranty

15. Export packing charges: N/A

16. Terms and conditions of rental, maintenance, and repair: N/A

17. Terms and conditions of installation: N/A

18a. Terms and conditions of repair parts indicating date of parts price lists and any discounts from list prices: N/A

18b. Terms and conditions for any other services: N/A

19. List of service and distribution points: N/A

20. List of participating dealers: N/A

21. Preventive maintenance: N/A

22a. Special attributes such as environmental attributes: N/A

22b. If applicable, indicate that Section 508 compliance information is available on Information and Communication Technology (ICT) supplies and services and show where full details can be found (e.g. contractor’s website or other location.) The ICT standards can be found at: www.Section508.gov/. N/A

23. Unique Entity Identifier (UEI) number: GPJHF5MRR8W5

24. The One 23 Group Inc. is registered in the System for Award Management (SAM) database. Cage Code: 1RC96 http://www.section508.gov/

Herndon, Virginia 20171 www.theone23group.com Telephone (703) 323-1700 Fax (703) 579-1593

Page | 4

Labor Category Descriptions

Job Title: Cybersecurity Accreditation and Certification Analyst Function Responsibility: Serves as a Cybersecurity Subject Matter Expert (SME) with regards to Risk Management of information systems and all associated cybersecurity policies and procedures. Fully versed in the general tenets supporting the overall implementation of incident management and re incident management and response processes, to include supporting cybersecurity policy, procedures, and processes. Performs cybersecurity process while serving as a SME for an information system. Must possess an understanding of how security controls identified in the NIST 800-53 apply to the process of assessing and authorizing a large organization’s IT infrastructure, and AIS applications and outsourced IT processes. Reviews audit trail logs and scans. Ensures systems maintenance by providing weekly Vulnerability Remediation Asset management (VRAM) compliance reports. Familiar with performing automated security scans with the following tools: assured compliance assessment solutions, center for internet security benchmarks, security content automation protocol, and retina.

Accurately analyze and document scan results and familiarity with following framework: DIACAO, DCID 6/3, ICD 503, NIST. Knowledgeable about IC tools, systems and reporting mechanisms. Knowledgeable of DoD, IC and National Level system security initiative and LAN/WAN technologies. Ability to Identify and classify attack vectors, malware, IDS/IPS rule writing development. Working knowledge of MS Office Suite. Must possess one of the following certifications: CISSP, CAP, GIAC, GSLC, CISM or Security +.

Minimum Education: Bachelor’s Degree Minimum/General Experience: Minimum of four (4) years of experience performing C&A responsibilities including acting as a POC for matters of cybersecurity.

Job Title: Cybersecurity Auditor – Intermediate Function Responsibility: Performs incident response and complex security analysis of classified and unclassified applications, systems, and enclaves for compliance with security requirements. Performs Command Cyber Readiness Inspections and cybersecurity vulnerability evaluations. Uses a variety of security techniques, technologies, and tools to evaluate security posture in highly complex computer systems and networks. Probes the safety and effectiveness of computer systems and their related security components. After conducting a security audit, issue a detailed report that outlines the effectiveness of the system, explains any security issues, and suggests changes and improvements. Plan, execute, and lead security audits across an organization. Inspect and evaluate financial and information systems, management procedures and security controls. Evaluate the efficiency, effectiveness, and compliance of operation processes with corporate security policies and related government regulations. Develop and administer risk-focused exams for IT systems. Review or interview personnel to establish security risks and complications. Execute and properly document the audit process on a variety of computing environments and computer applications. Assess the exposures resulting from ineffective or missing control practices. Accurately interpret audit results against defined criteria and weigh the relevancy, accuracy and perspective of conclusions against audit evidence. Provide a written and verbal report of audit findings. Develops rigorous “best practice” recommendations to improve security on all levels and works with management to ensure security recommendations comply with company mandates.

Minimum Education: Bachelor's degree in Information Technology, Computer Science or an applicable technical field.

Minimum/General Experience: Minimum three (3) years of experience in IT.

Herndon, Virginia 20171 www.theone23group.com Telephone (703) 323-1700 Fax (703) 579-1593

Page | 5

Job Title: Cybersecurity Auditor – Senior Function Responsibility: Senior SME. Leads a team of Cyber Security auditors as that team performs complex security analysis of classified and unclassified applications, systems, and enclaves for compliance with security requirements. Performs Command Cyber Readiness Inspections and cybersecurity vulnerability evaluations. Uses a variety of security techniques, technologies, and tools to evaluate security posture in highly complex computer systems and networks. Probes the safety and effectiveness of computer systems and their related security components. After conducting a security audit, issue a detailed report that outlines the effectiveness of the system, explains any security issues, and suggests changes and improvements. Plan, execute and lead security audits across an organization. Inspect and evaluate financial and information systems, management procedures and security controls. Evaluate the efficiency, effectiveness, and compliance of operation processes with corporate security policies and related government regulations. Develop and administer risk-focused exams for IT systems. Review or interview personnel to establish security risks and complications. Execute and properly document the audit process on a variety of computing environments and computer applications. Assess the exposures resulting from ineffective or missing control practices. Accurately interpret audit results against defined criteria and weigh the relevancy, accuracy, and perspective of conclusions against audit evidence.

Provide a written and verbal report of audit findings. Develops rigorous “best practice” recommendations to improve security on all levels and works with management to ensure security recommendations comply with company procedure.

Minimum Education: Bachelor's degree in Information Technology, Computer Science or an applicable technical field.

Minimum/General Experience: Minimum of five (5) years of experience in IT

Job Title: Cybersecurity Compliance Analyst Function Responsibility: Evaluates, reviews, analyzes, and recommends available products to support cyber security solutions. Performs a variety of Cybersecurity analysis tasks, independently, which are broad in nature and are concerned with the design, analysis, and implementation, including personnel, hardware, software, and support facilities and/or equipment. Perform security research, analysis, and design for the clients’ computing systems and network infrastructure. Facilitate security vulnerability assessments and support penetration tests.

Work on security alerts, events, and security incidents, including forensics analysis. Contribute general consulting (risk analysis) and project support in the area of information security to IT infrastructure and projects as needed to support new business requirements. Participate in internal security audits and investigations. Manage and maintain a library of security audit tools and corresponding processes. Monitor trends in information technology and security. Research emerging technologies and maintain awareness of current security risks in support of security enhancement and development efforts. Monitor security systems for anomalies and respond to potential security events. Perform periodic policy compliance reviews, risk assessments, and control testing. Assist in the investigation of security incidents as required and recommend corrective actions and process improvements. A deep knowledge of NIST and ISO standards as well as industry-specific regulatory requirements (e.g., financial, healthcare and manufacturing).

Ability to research solutions where required.

Minimum Education: Bachelor's degree in Information Technology, Computer Science or an applicable technical

Minimum/General Experience: Three (3) years relevant experience

Herndon, Virginia 20171 www.theone23group.com Telephone (703) 323-1700 Fax (703) 579-1593

Page | 6

Job Title: Cybersecurity Engineer Function Responsibility: Works on various network types of equipment and related devices from a security protection emphasis to include installing; troubleshooting; modifying; testing. Can independently build test network or system prototypes, performing equipment set-up, testing, and participating in test report writing. Has the ability to develop attack programs to verify security assurance and weakness capability. Gathers and organizes technical information about an organization's missions, goals, and requirements, existing security products, and ongoing programs in the IA arena. Performs command and control functions in response to incidents. Aids and helps transform Federal Government cybersecurity risk management through effective collaboration, operational governance, and training. Provides meaningful metrics and assessments in support of agency decision making.

Assist in the development of innovative approaches to drive change in cybersecurity risk management across the federal government to prevent or minimize disruptions to critical information infrastructure. Works as a team member and contributes to the assessment of current cybersecurity systems, policies, and processes to enforce standards and identify vulnerabilities and capability gaps, and to synthesize this data to reduce cybersecurity risk of customer networks. Analyzes user needs to determine functional requirements and define problems. Develop plans and requirements in the subject matter area for moderately complex to complex systems related to information systems architecture, networking; telecommunications, automation, communications protocols, risk management/electronic analysis, software, lifecycle management, software development methodologies, and modeling and simulation.

Minimum Education: Bachelor's Degree Minimum/General Experience: Three (3) years relevant experience

Job Title: Cybersecurity Subject Matter Expert Function Responsibility: Provide expert advice to senior leaders and stakeholders on the extent of an incident, impact analysis, recommends eradication strategies and plans to restore networks to a more secure state to resolve Cybersecurity related incidents. Ensures that all systems and data repositories maintain appropriate levels of confidentiality, security, and integrity. Works with cybersecurity specialists to provide expert consultation across a wide range of cross-functional areas of cyber security. Provides project planning, guidance, and technical expertise in the following areas: cyber security engineering program, policy, process, and planning; risk management, auditing, and assessments; Assessment and Authorization (A&A) using the NIST Risk Management Framework (RMF) guidelines; and quality control. Leads and manages cyber security team in an operations and maintenance environment. Uses industry best practices in cyber security and security engineering related to vulnerability management, intrusion. Assist with development and maintain Operational Level Agreements (OLAs) and end-to- end Standard Operating Procedures (SOPs) to identify collaborative responsibilities and support process interaction with other Government and contractor IT groups. Advises system owners on all matters, technical and otherwise, involving the security of assigned IT systems. Perform continuous monitoring of security controls to ensure that they continue to be implemented correctly, operating as intended and producing the desired outcome with respect to meeting the cyber security requirements for assigned IT systems. Work with technical teams to mitigate security control deficiencies for assigned IT systems. Assess the cybersecurity impact of changes to assigned IT systems.

Develop, update, and maintain the System Security Plan (SSP) for assigned systems.

Minimum Education: Master’s degree in a related discipline or equivalent experience in a discipline related to the nature of the contract work or in a business- related field.

Minimum/General Experience: Six (6) years of demonstrated cybersecurity engineering experience; verifiable IAM Level III Certification (CISSP, CISM, or GSLC); ITIL v3Foundation Certification; and three (3) years of RMF experience.

Herndon, Virginia 20171 www.theone23group.com Telephone (703) 323-1700 Fax (703) 579-1593

Page | 7

Job Title: Cybersecurity Technical Writer Function Responsibility: Works in collaboration with the Incident Management and Cyber Risk Team and Federal Government clients to document cyber risk and threats. Conduct relevant research, data analysis, and create reports. Maintain responsibility for completion and accuracy of work products. Design and develop documentation of highly technical IT products and deployments. Serves as the lead author for risk management and security focused documents. Collaborates with infrastructure SMEs to define documentation requirements.

Supports the development of cybersecurity presentation and policy guidance based on recommended eradication strategies and plans to restore networks to a more secure state. Knowledge of the Risk Management Framework (RMF) or NIST standards. Experience developing documents: IT Service Management (ITSM), IT Infrastructure Library (ITIL), or COBIT. Supports the development of cybersecurity presentation and policy guidance based on recommended eradication strategies and plans to restore networks to a more secure state.

Minimum Education: Bachelor's degree in Information Technology, Computer Science or an applicable technical

Minimum/General Experience: One (1) year of technical writing experience

Job Title: Data Control Clerk Function Responsibility: Performs analysis, development, and review of program administrative operating procedures. Support tasks requiring the collecting, compiling, evaluating, and publishing of information and statistical data included in documents, records, forms, reports, plans, policies, and regulations. Also supports the technical, business, and administrative aspects of the program.

Minimum Education: A high school diploma. College level study in Computer Science or a related field will be considered in place of general experience.

Minimum/General Experience: Minimum of 2-3 years of experience

Job Title: DR/COOP SME Function Responsibility: Supports development, testing, and maintenance of Continuity of Support/IT Contingency, Cyber Incident Response, and Information Technology Disaster Recovery Plans, develops Contingency Planning Guides for IT Systems. Drafts contingency planning policy statements; conducts the business impact analysis (BIA); identifies preventive controls; develops recovery strategies; develops the IT Contingency Plan; conducts testing, training, and exercises of the plans; and updates plans as changes to the IT environment occur. Requires a bachelor’s degree or equivalent (equivalent is 2 years’ experience per year of college), five to seven years of related experience, and the ability to obtain and maintain a security clearance.

Minimum Education: B.A. or B.S. degree.

Minimum/General Experience: Must have 12 years of experience in the IT field. At least 10 years of combined new and related older technical experience in the IT field directly related to the required area of expertise. Top Secret Clearance, clearable up to Top Secret with Sensitive Compartmented Information TS/SCI.

Herndon, Virginia 20171 www.theone23group.com Telephone (703) 323-1700 Fax (703) 579-1593

Page | 8

Job Title: Enterprise Architect Function Responsibility: This Senior Level Architect will design, build, and implement enterprise-class security solutions within a multi-tenant cloud environment to support federal agencies. This individual must be versatile and articulate with the ability to successfully convey Cyber Security risks and effectively position our solutions and delivery capabilities that address the cyber security challenges. Provides guidance on government architectures, lines of business, the Technical Reference Model (TRM) and threat intelligence specifically focused on incidents to identify attacks. Works with stakeholders to build a holistic view of the organization's strategy, processes, information, and IT assets. Ensures business and IT are in alignment and protected from cyber threats. Assesses and links the business mission, strategy, and processes of the organization to its IT strategy, including security, and documents this using multiple architectural models or views that show how the current and future needs of an organization will be met.

Minimum Education: Bachelor’s degree Minimum/General Experience: Three (3) years of experience defining and implementing enterprise architecture strategies. Extensive experience with enterprise architecture best practices and goals. Federated Enterprise Architecture Certification (FEAC) required.

Job Title: Functional Analyst Function Responsibility: Analyzes user needs to determine functional requirements, tasks, and their interrelationships. Identifies resources required for each task, Identifies technical problems, and risk areas.

Develops solutions and risk mitigation strategy. Prepares reports and presents interim and final task order results to all concerned. Document procedures and processes for improvement. Provides daily supervision and direction to staff.

Minimum Education: A Bachelor’s degree in a related scientific or technical discipline.

Minimum/General Experience: Over five (5) years’ experience as a consultant or manager in a specific functional area (such as strategic business and action planning, systems alignments, organization assessments, etc.).

Job Title: Information Assurance (IA) Management Analyst Function Responsibility: Responsible for responding to all information systems incidents to restore them to be functional and secure; recommends information security assurance/security solutions. Performs scanning analysis. Provides technical planning and systems engineering for NIST compliance. Serves as the primary customer engagement point of contact. Provides onsite/remote offsite services and support during hours of operations.

Provides Technical Knowledge Transfer. Perform security updates. Develop/Review/Maintain artifacts and documentation. Documents and maintains system configurations. Instructs on security policies and procedures.

Monitors network activity and ensures data is protected from unauthorized users. Identifies, reports, and resolves security violations. Relies on knowledge and professional discretion to plan and achieve goals. Advises and assists Federal Government clients on incident response, security and privacy policy, trusted product assessment, enterprise security engineering, secure systems management, penetration and exploitation, insider threat analysis and protection, cyber situation awareness, attack sensing and warning, secure wireless networking and mobile computing, secure operating systems, secure workstations, secure data management, secure web technology, and secure protocols, authentication. Performs Incident Response analysis.

Minimum Education: Bachelor's degree in Computer Science, Information Systems or related field.

Minimum/General Experience: Three (3) years of experience.

Herndon, Virginia 20171 www.theone23group.com Telephone (703) 323-1700 Fax (703) 579-1593

Page | 9

Job Title: Information Assurance (IA) Project Engineer Function Responsibility: Provides Information Assurance, Cyber Security, and Systems Engineering support for critical processes and projects; Performs command and Control functions in response to incidents. Assesses and mitigates system security threats/risks throughout the program life cycle; validates system security requirements definition and analysis; establishes system security designs; implements security designs in hardware, software, data, and procedures; verifies security requirements; performs system certification and accreditation planning and testing and liaison activities and supports secure systems operations and maintenance. Responsible for safeguarding Government organization’s computer networks and systems by planning and carrying out security measures to monitor and protect sensitive data and systems from infiltration and cyber-attacks. Works in concert with a larger IT team. Developing Information Security plans and policies. Develops a set of security standards and best practices for the organization and recommends security enhancements to management as needed. Develops strategies to respond to and recover from a security breach. Information Assurance Security Engineers are also responsible for educating the workforce on information security through training and building awareness.

Implement protections, installs, and uses software, such as firewalls and data encryption programs, to protect organizations’ sensitive information, while also assisting computer users with installation or processing of new security products and procedures. Test for vulnerabilities; conducts periodic scans of networks to find any vulnerability; and conducts penetration testing.

Monitor for security breaches. Constantly monitors networks and systems for security breaches or intrusions.

Installs software to notify of intrusions and watches out for irregular system behavior. Investigate security breaches; if a breach occurs, leads incident response activities to minimize the impact. Leads a post-incident technical and forensic investigation into how the breach happened and the extent of the damage. Prepares reports of findings to be reported to management.

Minimum Education: Bachelor's degree in Computer Science, Information Systems or related field.

Minimum/General Experience: Four (4) years of experience

Job Title: Information Assurance Security Engineer Function Responsibility: Provides guidance on IA artifacts in the area of Cybersecurity and tooling to include vulnerability testing and related network and system test tools, e.g., Retina, NMap, Nessus, STIG compliance checker, ACAS, Klocwork, WASSP, SECSCN, Security Content Automation Protocol (SCAP). Responsible for safeguarding Government organization’s computer networks and systems by planning and carrying out security measures to monitor and protect sensitive data and systems from infiltration and cyber-attacks. Works in concert with a larger IT team. Developing Information Security plans and policies. Develops a set of security standards and best practices for the organization and recommends security enhancements to management as needed. Develops strategies to respond to and recover from a security breach. Information Assurance Security Engineers are also responsible for educating the workforce on information security through training and building awareness.

Implement protections, installs and uses software, such as firewalls and data encryption programs, to protect organizations’ sensitive information, while also assisting computer users with installation or processing of new security products and procedures. Test for vulnerabilities; conducts periodic scans of networks to find any vulnerability; and conducts penetration testing. Monitor for security breaches. Constantly monitors networks and systems for security breaches or intrusions. Installs software to notify of intrusions and watches out for irregular system behavior. Investigate security breaches; if a breach occurs, leads incident response activities to minimize the impact. Leads a post-incident technical and forensic investigation into how the breach happened and the extent of the damage. Prepares reports of findings to be reported to management.

Minimum Education: Bachelor's degree in Computer Science or a similar field Minimum/General Experience: Two (2) years of experience in cyber technology or a related area, with appropriate cyber security certifications.

Herndon, Virginia 20171 www.theone23group.com Telephone (703) 323-1700 Fax (703) 579-1593

Page | 10

Job Title: Intermediate Administrative Specialist Function Responsibility: Specializes in coordinating and planning office administration and support. Reports directly to a client, usually at the client location, to support its operations as required. Understands and provides documentation planning and support, project administration, general office support, executive secretarial support, human resource planning, event planning and administration, office relocation planning, etc. required in changing office environments.

Minimum Education: High School Diploma or equivalent. There is no experience substitution for a High School degree, however a G.E.D., other degree equivalency program, or a technical trade school certificate is acceptable.

With a bachelor’s degree no experience is required.

Minimum/General Experience: Two (2) years related work experience.

Job Title: Intermediate Communication Engineer Function Responsibility: Performs systems engineering planning; performance management; capacity planning, testing and validation; benchmarking; information engineering. Develops and staffs a systems engineering management plan. Supports a Sr. Systems Engineer, as required. Analyzes and develops technical documentation detailing the integration and system performance. Coordinates the activities of Systems Engineers and Jr. Systems Engineers assigned to specific systems engineering projects.

Minimum Education: Bachelor's degree or equivalent.

Minimum/General Experience: Five (5) years’ experience. With a Master's degree, three (3) years of experience is acceptable.

Job Title: Intermediate Information Engineer Function Responsibility: Applies business process improvement practices to re-engineer methodologies/principles and business process modernization projects. Applies, as appropriate, activity and data modeling, transaction flow analysis, internal control and risk analysis and modern business methods and performance measurement techniques. Assist in establishing standards for information systems procedures. Develops and applies organization wide information models for use in designing and building integrated, shared software and database management systems. Constructs logical business improvement opportunities consistent with corporate information management guiding principles, cost savings, and open system architecture objectives.

Minimum Education: A Bachelor's degree in Computer Science, Information Systems, Engineering, Business, or other related scientific or technical discipline.

Minimum/General Experience: Five (5) years’ specialized experience, in information systems development, functional and data requirements analysis, systems analysis and design, programming, program design and documentation preparation. The following experience is also required demonstrated experience in the implementation of information engineering projects; systems analysis, design and programming using CASE and IE tools and methods, systems planning, business information planning, and business analysis.

Herndon, Virginia 20171 www.theone23group.com Telephone (703) 323-1700 Fax (703) 579-1593

Page | 11

Job Title: Lead Business Systems Analyst Function Responsibility: Top level technical contributor supporting Penetration Testing and other cybersecurity and Information Assurance tasks with expertise in Information Technology and Cybersecurity cradle to grave processes related to applications and infrastructure. Responsible for analyzing and documenting existing operations and practices and developing test plans to circumvent the security and features of applications, systems, networks, and processes. Acts as a member of the team responsible for providing technical guidance concerning the “business”. Supports analyzing site/enterprise Computer Network Defense policies and evaluates compliance with regulations and Enterprise Directives; Assists with the selection of cost-effective security controls to mitigate risks (e.g., protection of business information and processes.) Plans, designs, develops, and launches exercises to circumvent security features. Gathers and analyzes data in support of business cases, proposed projects, and systems requirements. Responsible for generating and compiling reports based on the findings, complete with probable causes and possible solutions. Meets with decision makers, systems owners, and end users to define business, financial, and operations requirements and systems goals, and identify and resolve systems issues. Reviews and analyzes the effectiveness and efficiency of existing systems and develops strategies for improvement. Identifies and establishes scope and parameters of systems analysis to define outcome criteria and measure-taking actions.

Supports Red and Blue Team activities.

Minimum Education: Bachelor’s degree Minimum/General Experience: Five (5) years of business analysis experience.

Job Title: Lead Sr. Security Engineer Function Responsibility: Provides technical, managerial, and administrative direction for problem definition, analysis, requirements development and implementation for complex to extremely complex systems in the subject matter area. Makes recommendations and advises on organization-wide system improvements, optimization, or maintenance efforts in the following specialties: information systems architecture; networking;

telecommunications; automation; communications protocols; risk management/electronic analysis; software; life-cycle management; software development methodologies; and modeling and simulation.

Minimum Education: B.A. or B.S. degree.

Minimum/General Experience: Must have 15 years of experience in the IT field. At least 10 years of combined new and related technical experience in the IT field directly related to the required area of expertise. Top Secret Clearance, clearable up to Top Secret with Sensitive Compartmented Information TS/SCI.

Job Title: Mid-Level Security Engineering Function Responsibility: Develops requirements from a project’s inception to its conclusion in the subject matter area for simple to moderately complex systems. Assists other senior consultants with analysis and evaluation and with the preparation of recommendations for system improvements, optimization, development, and/or maintenance efforts in the following specialties: information systems architecture; networking;

telecommunications; automation; communications protocols; risk management/electronic analysis; software; life-cycle management; software development methodologies; and modeling and simulation.

Minimum Education: B.A. or B.S. degree.

Minimum/General Experience: Must have 8 years of experience in the IT field. At least 5 years of combined new and related technical experience in the IT field directly related to the required area of expertise. Top Secret Clearance, clearable up to Top Secret with Sensitive Compartmented Information TS/SCI.

Herndon, Virginia 20171 www.theone23group.com Telephone (703) 323-1700 Fax (703) 579-1593

Page | 12

Job Title: Network Engineer I Function Responsibility: Provides support monitoring the networks and systems for cyber threats and cyber vulnerabilities. Identifies security risks, threats and vulnerabilities of networks, systems, applications, and other technologies. Design, support, and troubleshoot for the client’s network within a team environment. Performs product evaluations, recommends, and implements services for network security. Responsible for validating and testing complex security architecture. Performs Network Mapping including Wireless Access Point (WAP) detection to support penetration testing. Ascertains user needs and system requirements to design, monitor, and maintain computer networks. Utilizes prior experience with years of direct experience in hands on implementation of network backbone technology (Cisco routers, switches, and firewalls), experience creating cyber security architecture guidelines for multiple instances of technology, capability to explain and design technology on an engineering and management level, and concise understanding of complete technology requirements and underlying technology fundamentals. Provides thought leadership in the design of cyber network infrastructure services to meet business requirements and operational objectives. Delegate tasking to the network engineering team staff. Provides architect engineering and supervisory services in support of emerging technology integration into network backbone systems. Monitor and maintains computer systems. This may include troubleshooting wide area networks, servers and routers, local area networks, and switches. Installs or upgrades software and hardware.

Minimum Education: Bachelor's degree in Computer Science, Information Systems, or Engineering Minimum/General Experience: One (1) year of experience with CompTIA Network+ credential

Job Title: Network Engineer, Sr.

Function Responsibility: Conducts assessments of threats and vulnerabilities, determines deviations from acceptable network configurations, network policies, and develops recommendations of mitigation countermeasure in operational and non-operational situations. Provides high level support monitoring the networks and systems for cyber threats and works with leadership and stakeholders to mitigate and remediate the cyber vulnerabilities.

Identifies security risks, threats and vulnerabilities of networks, systems, applications, and other technologies.

Performs highly complex product evaluations, recommends, and implements services for network security.

Responsible for validating and testing complex security architecture. Determines deviations from acceptable network configurations, network policies, and develops recommendations of mitigation countermeasures in operational and non-operational situations. Supports Ethical Hacking and Compliance Management on network appliances. Defines the problems and analyzes and develops plans and requirements in the subject matter area for moderately complex to complex systems. Coordinates and manages the preparation of analysis, evaluations, and recommendations for proper implementation of programs and systems specifications in the following specialties: information systems architecture, networking, telecommunications; automation, communications protocols, risk management/electronic analysis, software, life-cycle management, software development methodologies, and modeling and simulation, leads network tech and design engineers.

Minimum Education: Bachelor's degree in Computer Science or a similar field Minimum/General Experience: Six (6) years of experience in the IT field.

Herndon, Virginia 20171 www.theone23group.com Telephone (703) 323-1700 Fax (703) 579-1593

Page | 13

Job Title: Network Security Analyst Function Responsibility: Provides continued operation of network and security enabled solutions. Strong knowledge of cyber security network monitoring principles, including vulnerability management, incident response, computer security forensics and vulnerability/penetration testing. Use various tools, techniques, and procedures.

Supports end point security, penetration testing, vulnerability assessments, and forensics. Provides security assessments and architecture recommendations to management. Supports analyzing site/enterprise Computer Network Defense configurations and evaluates compliance with regulations and Enterprise Directives; Assists with the selection of cost-effective security controls to mitigate risks (e.g., systems and networks).

Minimum Education: Bachelor's degree in Computer Science or a similar field Minimum/General Experience: Three (3) years of experience in Computer Science or a similar field

Job Title: Penetration Tester – II Function Responsibility: In furtherance of cyber security objectives, conducts and /or supports authorized manual penetration tests of networks, applications, web applications, servers, endpoints, wireless, mobile technologies and on enterprise network assets. Develops custom exploits. Utilizes automated tools to conduct penetration testing.

Analyze results to mitigate the risk of false positives. Finds security vulnerabilities in target systems, networks, and applications to help enterprises improve their security; identification of flaws to cause business risk, provides crucial insights into the most pressing issues and suggests how to prioritize security resources; Works under general supervision and usually reports to a supervisor, though some ingenuity and flexibility is required.

Conducting and/or supporting authorized penetration testing on enterprise network assets. Analyzing site/enterprise Computer Network Defense (CND) policies, configurations, and evaluate compliance with regulations and enterprise directives. Assisting with the selection of cost-effective security controls to mitigate risk.

Minimum Education: Bachelor's degree in Computer Science, Information Systems or related field Minimum/General Experience: Three (3) years of experience; Knowledge of general attack stages; ability to identify systemic security issues based on the analysis of vulnerability and configuration data.

Job Title: Penetration Tester – III Function Responsibility: Possesses knowledge of industry-standard penetration testing components and processes including reconnaissance, scanning, ranking/scoring vulnerabilities, selecting targets for exploit, escalation of privilege, removal of exploits/restoration of exploited targets, and reporting. Has knowledge of penetration testing applications or processes. Performs penetration testing activities and prepares “Rules of Engagement” document, plans all activities, and provides direction to junior level penetration testers. Performs final analysis of testing results and prepares technical reports. Leads the effort to find cyber security vulnerabilities in target systems, networks, and applications to help enterprises improve their security; leads the identifying of which key flaws can be exploited to cause business risk, provides crucial insights into the most pressing issues and suggests how to prioritize security resources. Conducts and/or supports authorized penetration testing on enterprise network assets. Analyzes site/enterprise Computer Network Defense (CND) policies, configurations, and evaluates compliance with regulations and enterprise directives. Assist with the selection of cost-effective security controls to help mitigate risk.

Minimum Education: Bachelor's degree in Computer Science, Information Systems or related field Minimum/General Experience: Six (6) years of experience; Knowledge of general attack stages; Ability to identify systemic security issues based on the analysis of vulnerability and configuration data.

Herndon, Virginia 20171 www.theone23group.com Telephone (703) 323-1700 Fax (703) 579-1593

Page | 14

Job Title: Program Manger Function Responsibility: Directs the performance of a variety of related projects, which may be organized by technology, program, or client. Oversees the technology development and/or application, marketing, and resource allocation within program client base. Program areas typically represent more than three functional areas that may include engineering, systems analysis, quality control, administration, etc. Primary duties and responsibilities Responsible for the effective management of funds and personnel and is accountable for the quality and timely delivery of all contractual items. Operates within client guidance, contractual limitations, and Company business and policy directives. Serves as focal point of contact with client regarding program activities. Ensures that all required resources including manpower, production standards, computer time, and facilities are available for program implementation. Manages program consisting of multiple projects including project identification, design, development, and delivery. Maintains the development and execution of business opportunities based on broad, general guidance. Confers with project manager to provide technical advice and to assist with problem resolution.

Responsible for marketing new technology and follow on business acquisitions. Performs other duties as assigned.

Minimum Education: Bachelor's degree or equivalent Minimum/General Experience: Ten (10) years’ experience within program development and management.

Job Title: Project Manager Function Responsibility: Provides project oversight and reports to the Program Manager and the COTR. Provides competent leadership and responsible program direction through successful performance of a variety of detailed, diverse elements of project transitioning. Directs completion of tasks within estimated time frames and budget constraints. Schedules and assigns duties to subordinates and subcontractors and ensures assignments are completed as directed. Enforces work standards and reviews/resolves work discrepancies to ensure compliance with contract requirements. Interfaces with the Program Manager as well as Government Technical Management personnel including, but not limited to, the Contracting Officer and the Contracting Officer’s Technical Representative.

Reports in writing and orally to contractor management and Government representatives. Defines and directs technical specification and tasks to be performed by team members and defines target dates of tasks and subtasks. Provides guidance and assistance in coordinating output and ensuring the technical adequacy of the end product. Ability to work with Government contracts personnel. Provides competent leadership and responsible program direction through successful performance of a variety of details, diverse elements of project transitioning. Directs completion of tasks within estimated timeframes and budget constraints. Schedules and assigns duties to subordinates and subcontractors and ensures assignments are completed as directed. Enforces work standards and reviews/resolves work discrepancies to ensure compliance with contract requirements.

Reports in writing and orally to contractor management and Government representatives.

Minimum Education: BS in Engineering, Computer Science, Management Minimum/General Experience: 5 to 10 Years of Project Management or Contract Administration for Federal and Civilian Government Contracts

Herndon, Virginia 20171 www.theone23group.com Telephone (703) 323-1700 Fax (703) 579-1593

Page | 15

Job Title: Risk Vulnerability Assessment Analyst/Specialist Function Responsibility: Conducts vulnerability assessments and penetration tests for applications (e.g., Web, application services, databases, etc.) and articulates security issues to technical and non-technical audiences.

Provide support by leveraging analytic and technical skills to discover cyber risks, assess vulnerabilities, prioritize assets, and remediate/mitigate. Management of daily assessment of vulnerabilities, evaluate, rate, and perform risk assessments of assets. Provide advice and assistance to the client and leadership to ensure that the policies and procedures established by the client are met. Provide Cybersecurity and consulting throughout the security assessment and compliance life cycle process. Performs data gathering, research, and analysis while conducting threat, vulnerability, risk, and maturity assessments; works under the direct supervision of manager/supervisor.

Works under general supervision and usually reports to a supervisor, though some ingenuity and flexibility is required. Maintaining applicable Computer Network Defense (CND) policies, regulations, and compliance documents specifically related to Computer Network Defense auditing.

Minimum Education: Bachelor's degree in Computer Science, Information Systems or related field Minimum/General Experience: Four years of experience

Job Title: Risk Vulnerability Assessment Analyst/Specialist (Infrastructure) Function Responsibility: Conduct vulnerability assessments and penetration tests for infrastructure and articulate security issues to technical and non-technical audience. Provide support by leveraging analytic and technical skills to discover cyber risks, assess vulnerabilities, prioritize assets, and remediate/mitigate. Management of daily assessment of vulnerabilities, evaluate, rate, and perform risk assessments of assets. Provide advice and assistance to the client and leadership to ensure that the policies and procedures established by the client are met. Provide Cybersecurity and consulting throughout the security assessment and compliance life cycle process.

Performs data gathering, research, and analysis while conducting threat, vulnerability, risk, and maturity assessments. May apply critical thinking, conduct gap analysis, and develop implementation plans for the improvement of the risk management-related program and contribute to constant innovation and improvement;

Works under general supervision and usually reports to a supervisor, though some ingenuity and flexibility is required. Maintaining applicable Computer Network Defense (CND) policies, regulations, and compliance documents specifically related to Computer Network Defense auditing.

Minimum Education: Bachelor's degree in Computer Science, Information Systems or related field Minimum/General Experience: Three years of experience; knowledge of how traffic flows across the network and Internet Protocol (IP), Open System Interconnection Model (OSI), and Information Technology Infrastructure Library, v3 (ITIL); knowledge of network protocol; knowledge of IA principles and organizational requirements;

knowledge of network security architecture concepts. Knowledge of network access, identity, and access management.

Hern…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .