MAS - Disruptive Solutions LLC - 47QTCA19D00M4
PDF 440 KB
- Attached to
- Federal Supply Schedule 47QTCA19D00M4 Federal contract IDV
- Contract number
- 47QTCA19D00M4
- Issued by
- GSA Federal Acquisition Service
About this file
This federal supply schedule price list provides labor rates for information technology and cybersecurity services. Disruptive Solutions LLC was awarded contract number 47QTCA19D00M4 on September 26, 2019 through GSA Federal Acquisition Service, with an initial period of performance through September 25, 2024. The contract includes 24 labor categories under SINs 54151S for IT professional services and 54151HACS for highly adaptive cybersecurity services. Labor categories cover positions such as cyber analysts, security engineers, project managers, and penetration testers, with fully burdened hourly rates ranging from $99 to $299 for years 4 and 5 of the contract based on experience levels. Services offered include cybersecurity consulting, vulnerability assessments, security engineering, and incident response support.
Disruptive Solutions, LLC Pricelist and/or Vendor Terms and Conditions for 47QTCA19D00M4, a Federal Supply Schedule awarded to Disruptive Solutions, LLC, under Information Technology Schedule 70 (IT-70)
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Disruptive Solutions LLC 47QTCA19D00M4 Page 1
General Services Administration Federal Supply Service
AUTHORIZED FEDERAL SUPPLY SCHEDULE PRICELIST
Online access to contract ordering information, terms and conditions, up-to-date pricing and the option to create an electronic delivery order are available through GSA Advantage!, a menu driven database system. The INTERNET address for GSA Advantage! is www.gsaadvantage.gov
Multiple Award Schedule (MAS)
FSC Group: Information Technology FSC Class: DA01, DJ01
Small Business
Service-Disabled Veteran Owned Small business
Disruptive Solutions LLC
46040 Center Oak Plaza Suite 165
Sterling, VA 20166 Contract Administration:
Chris Arbore Phone: (703) 203-7500
Email: Contracts@disruptivesol.com www.disruptivesol.com
Contract Number: 47QTCA19D00M4
Period Covered by Contract: September 26, 2024, through September 25, 2029 Pricelist current through Modification PS-0014 effective 9-9-24 http://www.disruptivesol.com/
Disruptive Solutions LLC 47QTCA19D00M4 Page 2
Table of Contents
CUSTOMER INFORMATION
LABOR CATEGORY DESCRIPTIONS
GSA PRICES FOR PROFESSIONAL SERVICES (54151S)
GSA PRICES FOR PROFESSIONAL SERVICES (54151HACS)
Disruptive Solutions LLC 47QTCA19D00M4 Page 3
1a. AUTHORIZED SPECIAL ITEM NUMBERS (SINs):
SIN DESCRIPTION
54151S Information Technology Professional Services
54151HACS Highly Adaptive Cybersecurity Services
OLM Order Level Materials
1b. Lowest Priced Service and Price for each Service Rate: See Page 28
1c. Labor Category Descriptions: See Page 6
2. MAXIMUM ORDER PER SIN:
SIN
MAXIMUM ORDER
54151S
54151HACS
OLM
$500,000.00 $500,000.00 $250,000.00
3. MINIMUM ORDER LIMITATION: $100
4. GEOGRAPHIC COVERAGE (DELIVERY AREA): The geographic scope of this contract is the 48 contiguous United States and District of Columbia.
5. POINT OF PRODUCTION: United States
6. DISCOUNT FROM LIST PRICES or STATEMENT of NET PRICE: Prices shown are NET Prices; Basic Discounts have been deducted.
7. QUANTITY DISCOUNTS: None
8. PROMPT PAYMENT TERMS: Net 30 Days. Prompt payment terms cannot be negotiated out of the contractual agreement in exchange for other concessions.
9. FOREIGN ITEMS: None
10a. TIME OF DELIVERY: Not applicable to professional services.
CUSTOMER INFORMATION
Disruptive Solutions LLC 47QTCA19D00M4 Page 4
10b. EXPEDITED DELIVERY: Contact Contractor
10c. OVERNIGHT AND 2-DAY DELIVERY: Contact Contractor
10d. URGENT REQUIREMENTS: Contact Contractor
11. F.O.B. POINT: Destination
12a. ORDERING ADDRESS:
ATTN: GSA Order Processing Disruptive Solutions LLC 46040 Center Oak Plaza Suite 165 Sterling, VA 20166 Phone: (703) 203-7500 Email: Contracts@disruptivesol.com Web: www.disruptivesol.com
12b. ORDERING PROCEDURES: For supplies and service the ordering procedures, information on Blanket Purchase Agreements (BPAs) are found in Federal Acquisition Regulation (FAR) 8.405-3
13. PAYMENT ADDRESS:
ATTN: Accounts Payable – GSA Orders Disruptive Solutions LLC 46040 Center Oak Plaza Suite 165 Sterling, VA 20166 Phone: (703) 203-7500 Email: Contracts@disruptivesol.com
Web: www.disruptivesol.com
14. WARRANTY PROVISION: Standard Commercial Warranty
15. EXPORT PACKING CHARGES: Not Applicable
16. TERMS AND CONDITIONS OF RENTAL, MAINTENANCE, AND REPAIR (IF
APPLICABLE) - Not Applicable
17. TERMS AND CONDITIONS OF INSTALLATION: Not Applicable
18a. TERMS AND CONDITIONS OF REPAIR PARTS: Contact Contractor
18b. TERMS AND CONDITIONS FOR ANY OTHER SERVICES: Contact Contractor mailto:Contracts@disruptivesol.com http://www.disruptivesol.com/ mailto:Contracts@disruptivesol.com http://www.disruptivesol.com/
Disruptive Solutions LLC 47QTCA19D00M4 Page 5
19. LIST OF SERVICE AND DISTRIBUTION POINTS: Contact Contractor
20. LIST OF PARTICIPATING DEALERS: Not Applicable
21. PREVENTIVE MAINTENANCE: Contact Contractor
22a. SPECIAL ATTRIBUTES SUCH AS ENVIRONMENTAL ATTRIBUTES:
Not Applicable
22b. SECTION 508 COMPLIANCE INFORMATION is available on Electronic and
Information Technology (EIT) supplies and services and show where full details can be found (e.g., contractor’s website or other location.) The EIT standards can be found at:
www.Section508.gov/: Not Applicable
23. UNIQUE ENTITY IDENTIFIER (UEI) NUMBER: VMQBY7FWUPF9
24. CONTRACTOR IS CURRENTLY REGISTERED IN THE SYSTEM FOR AWARD
MANAGEMENT (SAM) DATABASE.
Disruptive Solutions LLC 47QTCA19D00M4 Page 6
Labor Category Descriptions
54151HACS Highly Adaptive Cybersecurity Services
Cyber Analyst Level 6
Functional Responsibility: Services performed include, but are not limited to, applying management analysis processes, statistical methods, and advanced technical and analytical research techniques to determine solutions based on client requirements with an IT services/solutions-based scope. Analyzes operational activities to obtain a quantitative, rational basis for decision making and resource allocation. Employs process improvements and reengineering methodologies and principles for modernization of systems and projects. Creates project plans to achieve performance-based objectives, enhancing implementation, systems and service. Provides integral support in mission requirements determination, conceptualization, design, development, testing, verification and validation, documentation, and implementation of system applications. Senior staff manages, plans, and conducts major phases of significant projects. In general, work complexity and responsibility will be greater at higher levels.
Minimum Education: Bachelors
Minimum Experience: 10 Years
Cyber Information Assurance Specialist Level 3
Functional Responsibility: Services performed include, but are not limited to, designing, developing, engineering, and implementing integrated security system solutions that will ensure proprietary/confidential data and systems are protected. Gathers and organizes technical information about an organization's mission goals and needs, existing security products, and ongoing programs in computer security in the strategic design process to translate security and business requirements into technical designs. Configures and validates secure systems; tests security products and systems to detect security weakness. Conducts regular audits to ensure that systems are being operated securely, and computer security policies and procedures are being implemented as defined in security plans. Duties include architecture design, system/network analysis, vulnerability and risk assessments, and security assessment of hardware and software.
Performs duties on tasks that require expertise in firewall, cyber, cloud computing, implementation/configuration, physical security analysis of facilities, security assessment/risk analysis, security design of local area networks and wide area networks, security analysis of network operating systems and applications, continuity of operations, planning, policy development and disaster recovery. In general, work complexity and responsibility will be greater at higher levels.
Minimum Experience: 1 Year
Disruptive Solutions LLC 47QTCA19D00M4 Page 7
Cyber Information Assurance Specialist Level 4 developing, engineering, and implementing integrated security system solutions that will ensure proprietary/confidential data and systems are protected. Gathers and organizes technical information about an organization's mission goals and needs, existing security products, and ongoing programs in computer security in the strategic design process to translate security and business requirements into technical designs. Configures and validates secure systems; tests security products and systems to detect security weakness. Conducts regular audits to ensure that systems are being operated securely, and computer security policies and procedures are being implemented as defined in security plans. Duties include architecture design, system/network analysis, vulnerability and risk assessments, and security assessment of hardware and software.
Performs duties on tasks that require expertise in firewall, cyber, cloud computing, implementation/configuration, physical security analysis of facilities, security assessment/risk analysis, security design of local area networks and wide area networks, security analysis of network operating systems and applications, continuity of operations, planning, policy development and disaster recovery. In general, work complexity and responsibility will be greater at higher levels.
Minimum Experience: 3 Years
Cyber Project / Task Manager Level 6
Functional Responsibility: Performs day-to-day management of cyber security delivery, from original concept through final implementation. Responsible for the overall management of cyber security projects/tasks and ensuring that the technical solutions and schedules in are implemented in a timely manner. Possesses experience managing cyber security-focused projects/tasks and utilizes those proven skills to analyze new and complex project related problems and create innovative solutions involving financial management, scheduling, technology, methodology, tools, and solution components. Organizes, directs, and coordinates the planning and production of all activities associated with assigned delivery order projects. Defines project scope and objectives including developing detailed work plans, schedules, project estimates, resource plans, status reports, and project and financial tracking and analysis. Conducts project meetings and ensures quality standards. Provides technical and strategic guidance to project team and reviews project deliverables. In general, work complexity and responsibility will be greater at higher levels. Performs enterprise-wide horizontal integration planning and interfaces to other functional areas as needed.
Disruptive Solutions LLC 47QTCA19D00M4 Page 8
Cyber Systems Engineer Level 5
Functional Responsibility: Designs and implements systems that meet agency Cybersecurity policy and regulations. Applies National Institute of Standards and Technology (NIST) security controls, governance, risk management, and compliance security documentation tool, and has strong understanding of the DoD 8500 Series Risk Management Framework (RMF). Applies knowledge of DoD security processes, the Enterprise Mission Assurance Support Service, Security Technical Implementation Guides and cloud and mobile security. Possesses demonstrated experience of implementing cyber security methodologies, identifying threats and developing appropriate protection measures, reviewing system changes for security implications and recommending improvements. Services performed include, but are not limited to, contributing to overall strategic vision and integrates a broad range of cyber security solutions in support of client requirements for IT projects. Works with Cybersecurity tools, network topologies, intrusion detection, public key infrastructure (PKI), and secured networks. Integrates secure practices such as PKI integration, Identity and Access Management, multi-factor authentication, service-oriented architectures, and network or Web related protocols. Formulates and defines system scope and objectives, develops or modifies processes to solve complex cyber security-related problems for computer systems and business and electronic interfaces to achieve desired results through the use of innovative technologies. Senior staff manages, plans, and conducts major phases of significant projects. In general, work complexity and responsibility will be greater at higher levels.
Minimum Experience: 4 Years
Cyber Systems Engineer Level 6
Functional Responsibility: Designs and implements systems that meet agency Cybersecurity policy and regulations. Applies National Institute of Standards and Technology (NIST) security controls, governance, risk management, and compliance security documentation tool, and has strong understanding of the DoD 8500 Series Risk Management Framework (RMF). Applies knowledge of DoD security processes, the Enterprise Mission Assurance Support Service, Security Technical Implementation Guides and cloud and mobile security. Possesses demonstrated experience of implementing cyber security methodologies, identifying threats and developing appropriate protection measures, reviewing system changes for security implications and recommending improvements. Services performed include, but are not limited to, contributing to overall strategic vision and integrates a broad range of cyber security solutions in support of client requirements for IT projects. Works with Cybersecurity tools, network topologies, intrusion detection, public key infrastructure (PKI), and secured networks. Integrates secure practices such as PKI integration, Identity and Access Management, multi-factor authentication, service-oriented architectures, and network or Web related protocols. Formulates and defines system scope and objectives, develops or modifies processes to solve complex cyber security-related problems for computer systems and business and electronic interfaces to achieve desired results through the use of innovative technologies. Senior staff manages, plans, and
Disruptive Solutions LLC 47QTCA19D00M4 Page 9 conducts major phases of significant projects. In general, work complexity and responsibility will be greater at higher levels.
Cyber Security Engineer Level 3
Functional Responsibility: Services performed include, but are not limited to, specialized technical tasks in support of business operations and management of the IT infrastructure, including IT administration, hardware and software support, installation, configuration, maintenance, testing, security, electrical, mechanical, facilities, and help desk support. a cyber security engineer is expected to have experience identifying threats and developing appropriate protection measures, the ability to review system changes for security implications and recommending improvements, have a strong understanding of cyber security methodologies, have knowledge of DoD (Department of Defense) 8500 series Risk Management Framework (RMF) processes.
Minimum Education: High School
Minimum Experience: 2 Years
Cyber Security Engineer Level 4 technical tasks in support of business operations and management of the IT infrastructure, including IT administration, hardware and software support, installation, configuration, maintenance, testing, security, electrical, mechanical, facilities, and help desk support. a cyber security engineer is expected to have experience identifying threats and developing appropriate protection measures, the ability to review system changes for security implications and recommending improvements, have a strong understanding of cyber security methodologies, have knowledge of DoD (Department of Defense) 8500 series Risk Management Framework (RMF) processes.
Cyber Security Engineer Level 5 technical tasks in support of business operations and management of the IT infrastructure, including IT administration, hardware and software support, installation, configuration, Disruptive Solutions LLC 47QTCA19D00M4 Page 10 maintenance, testing, security, electrical, mechanical, facilities, and help desk support. a cyber security engineer is expected to have experience identifying threats and developing appropriate protection measures, the ability to review system changes for security implications and recommending improvements, have a strong understanding of cyber security methodologies, have knowledge of DoD (Department of Defense) 8500 series Risk Management Framework (RMF) processes.
Cyber Security SME Level 3 technical tasks in support of business operations and management of the IT infrastructure, including IT administration, hardware and software support, installation, configuration, maintenance, testing, security, electrical, mechanical, facilities, and help desk support.
Safeguards information system assets by identifying and solving potential and actual security problems. Protects system by defining access privileges, control structures, and resources.
Recognizes problems by identifying abnormalities, reporting violations. Implements security improvements by assessing current situation; evaluating trends; anticipating requirements.
Determines security violations and inefficiencies by conducting periodic audits. Upgrades system by implementing and maintaining security controls.
Cyber Security SME Level 4 technical tasks in support of business operations and management of the IT infrastructure, including IT administration, hardware and software support, installation, configuration, maintenance, testing, security, electrical, mechanical, facilities, and help desk support.
Safeguards information system assets by identifying and solving potential and actual security problems. Protects system by defining access privileges, control structures, and resources.
Recognizes problems by identifying abnormalities, reporting violations. Implements security improvements by assessing current situation; evaluating trends; anticipating requirements.
Determines security violations and inefficiencies by conducting periodic audits. Upgrades system by implementing and maintaining security controls.
Disruptive Solutions LLC 47QTCA19D00M4 Page 11
Cyber Security SME Level 5 technical tasks in support of business operations and management of the IT infrastructure, including IT administration, hardware and software support, installation, configuration, maintenance, testing, security, electrical, mechanical, facilities, and help desk support.
Safeguards information system assets by identifying and solving potential and actual security problems. Protects system by defining access privileges, control structures, and resources.
Recognizes problems by identifying abnormalities, reporting violations. Implements security improvements by assessing current situation; evaluating trends; anticipating requirements.
Determines security violations and inefficiencies by conducting periodic audits. Upgrades system by implementing and maintaining security controls.
Cyber Security SME Level 6 technical tasks in support of business operations and management of the IT infrastructure, including IT administration, hardware and software support, installation, configuration, maintenance, testing, security, electrical, mechanical, facilities, and help desk support.
Safeguards information system assets by identifying and solving potential and actual security problems. Protects system by defining access privileges, control structures, and resources.
Recognizes problems by identifying abnormalities, reporting violations. Implements security improvements by assessing current situation; evaluating trends; anticipating requirements.
Determines security violations and inefficiencies by conducting periodic audits. Upgrades system by implementing and maintaining security controls.
Cyber ISSO Engineer Level 6 technical tasks in support of business operations and management of the IT infrastructure, including IT administration, hardware and software support, installation, configuration, maintenance, testing, security, electrical, mechanical, facilities, and help desk support. As an Information System Security Engineer (ISSE), the Cybersecurity Engineer's role is to conduct information system security engineering activities, confirm that information security requirements are effectively implemented throughout the security architecting, design, development, configuration, and implementation processes.
Disruptive Solutions LLC 47QTCA19D00M4 Page 12
The ISSO will perform research system computer security, system exploitation, penetration testing, and software security assessment for applications. Responsible for capturing and refining information security requirements. Employs best practices when implementing security requirements within an information system including software engineering methodologies, system/security engineering principles, secure design, secure architecture, and secure coding techniques. Insures (IDAM) Software Integration policy and oversight including Username/password and PKI authentication, security access controls, limiting user access to any data at or below the security level assigned to the user's account, Monitor and restrict all network traffic, encrypt all mission data at rest and in transit, require and force all data to be appropriately tagged in accordance with department guidance. Prepare SSPs, Risk Assessment Reports, A&A packages, and Security Controls Traceability Matrix (SCTM), monthly and quarterly risk compliance reports. Has experience in Cloud and vulnerability management leveraging tools.
Cyber Cloud Engineer Level 3 technical tasks in support of business operations and management of the IT infrastructure, including IT administration, hardware and software support, installation, configuration, maintenance, testing, security, electrical, mechanical, facilities, and help desk support, to include all cloud activities. Develop and execute best practices, including providing support engineering architectures in a cloud environment. Troubleshoot and resolve operational issues, assisting with issues arising from product upgrades, installations, and configurations. Experience architecting solutions on the cloud.
Minimum Education: High School
Cyber Cloud Engineer Level 6 technical tasks in support of business operations and management of the IT infrastructure, including IT administration, hardware and software support, installation, configuration, maintenance, testing, security, electrical, mechanical, facilities, and help desk support, to include all cloud activities. Develop and execute best practices, including providing support engineering architectures in a cloud environment. Troubleshoot and resolve operational issues, assisting with issues arising from product upgrades, installations, and configurations. Experience architecting solutions on the cloud.
Disruptive Solutions LLC 47QTCA19D00M4 Page 13
Cyber Pen Tester Level 3 technical tasks in support of business operations and management of the IT infrastructure, including IT administration, hardware and software support, installation, configuration, maintenance, testing, security, electrical, mechanical, facilities, and help desk support.
Contribute to Enterprise program around penetration testing and overall web application security.
Responsible for scoping and execution of penetration tests against a variety of technologies including web application, mobile and infrastructure. Provide network/application vulnerability assessment and penetration testing services globally through a comprehensive testing process, identifying weaknesses and vulnerabilities within the system and proposing countermeasures.
Contribute both on an individual assessment basis global strategic basis to raise the security posture across the organization. The ability to perform computer network vulnerability assessment and penetration testing. Act as the subject matter expert for Enterprise Information Security (EIS) and on penetration testing. Act as the subject matter expert for all aspects of penetration testing. Be an individual contributor for the entire enterprise-wide penetration testing program and all its components. Examine current penetration testing practices and identify key risks, then execute programs to address them.
Cyber Pen Tester Level 4 technical tasks in support of business operations and management of the IT infrastructure, including IT administration, hardware and software support, installation, configuration, maintenance, testing, security, electrical, mechanical, facilities, and help desk support.
Contribute to Enterprise program around penetration testing and overall web application security.
Responsible for scoping and execution of penetration tests against a variety of technologies including web application, mobile and infrastructure. Provide network/application vulnerability assessment and penetration testing services globally through a comprehensive testing process, identifying weaknesses and vulnerabilities within the system and proposing countermeasures.
Contribute both on an individual assessment basis global strategic basis to raise the security posture across the organization. The ability to perform computer network vulnerability assessment and penetration testing. Act as the subject matter expert for Enterprise Information Security (EIS) and on penetration testing. Act as the subject matter expert for all aspects of penetration testing. Be an individual contributor for the entire enterprise-wide penetration testing program and all its components. Examine current penetration testing practices and identify key risks, then execute programs to address them.
Disruptive Solutions LLC 47QTCA19D00M4 Page 14
Cyber Pen Tester Level 6 technical tasks in support of business operations and management of the IT infrastructure, including IT administration, hardware and software support, installation, configuration, maintenance, testing, security, electrical, mechanical, facilities, and help desk support.
Contribute to Enterprise program around penetration testing and overall web application security.
Responsible for scoping and execution of penetration tests against a variety of technologies including web application, mobile and infrastructure. Provide network/application vulnerability assessment and penetration testing services globally through a comprehensive testing process, identifying weaknesses and vulnerabilities within the system and proposing countermeasures.
Contribute both on an individual assessment basis global strategic basis to raise the security posture across the organization. The ability to perform computer network vulnerability assessment and penetration testing. Act as the subject matter expert for Enterprise Information Security (EIS) and on penetration testing. Act as the subject matter expert for all aspects of penetration testing. Be an individual contributor for the entire enterprise-wide penetration testing program and all its components. Examine current penetration testing practices and identify key risks, then execute programs to address them.
EXPERIENCE & DEGREE SUBSTITUTION for 54151HACS
The above describes the functional responsibilities and education and experience requirements for each labor category. These requirements are a guide to the types of experience and educational background of typical personnel in each labor category.
Education and experience may be substituted for each other. Each year of relevant experience may be substituted for one year of education, and vice versa. In addition, certifications, professional licenses, and vocational technical training may be substituted for experience or education.
Degree/Experience Equivalency* Degree Experience Equivalence Other Equivalence Bachelors Associate degree +2 years relevant experience, or 4 years relevant experience
Professional certification
Masters Bachelors +2 years relevant experience, or Associates + 4 years relevant experience
Professional license
Disruptive Solutions LLC 47QTCA19D00M4 Page 15
Doctorate Masters + 2 years relevant experience, Bachelors + 4 years relevant experience
* Successful completion of higher education which has not yet resulted in a degree may be counted as 1 for 1 years of experience for each year of college completed.
54151S Information Technology Professional Services
IT Security Engineer
Functional Responsibility: Provides Cyber Security consulting support to organizations.
Minimum Education: Bachelor’s Degree in a Technical or related field. 2 years direct experience may be substituted for degree.
Minimum Experience: Two (2) years of technical experience related to Cyber and/or IT security.
Experience should include IT Security Assessments/Support, and/or Vulnerability Assessments.
Experience in one (1) or more of the following is desired: Penetration Testing, Computer/Network/Mobile Device Forensics and Exploitation, Cyber Training, or Incident Response.
Cyber Security Engineer
Functional Responsibility: Provides IT Security consulting support to organizations. Assists Cyber Security team with Cyber projects.
Minimum Education: Bachelor’s Degree in a Technical or related field. 8 years direct experience may be substituted for degree.
Minimum Experience: Two (2) years of technical experience related to Cyber and or IT security.
Experience should include one (1) or more of the following: IT Security Assessments/Support, Vulnerability Assessments, Penetration Testing, Computer/Network/Mobile Device Forensics and Exploitation, Cyber Training, or Incident Response.
Senior Cyber Security Engineer
Cyber Security team with Cyber projects.
Minimum Education: Bachelor’s Degree in a Technical or related field. 2 years direct experience may be substituted for degree.
Disruptive Solutions LLC 47QTCA19D00M4 Page 16
Minimum Experience: Six (6) years of technical experience related to Cyber and or IT security.
Experience should include two (2) or more of the following: IT Security Assessments/Support, Principal Cyber Security Engineer
Cyber Security team with Cyber projects.
Minimum Education: Bachelor’s Degree in a Technical or related field. 8 years direct experience may be substituted for degree.
Minimum Experience: Eight (8) years of technical experience related to Cyber and IT security.
Experience should include at least four (4) years of direct experience in Incident Response, and Computer/Network Forensics and Exploitation.
Incident Response Engineer
Cyber Security team with Cyber projects.
Minimum Education: Bachelor’s Degree in a Technical or related field. 12 years direct experience may be substituted for degree.
Minimum Experience: Ten (10) years of technical experience related to Cyber and IT security.
Experience should include two (2) or more of the following: IT Security Assessments/Support, Cyber Analyst Level 6
Functional Responsibility: Services performed include, but are not limited to, applying management analysis processes, statistical methods, and advanced technical and analytical research techniques to determine solutions based on client requirements with an IT services/solutions-based scope. Analyzes operational activities to obtain a quantitative, rational basis for decision making and resource allocation. Employs process improvements and reengineering methodologies and principles for modernization of systems and projects. Develops and delivers cybersecurity-related training courses/training materials as needed. Participates in development and refinement of assessment methods and procedures and communicates to stakeholders appropriately. Creates project plans to achieve performance-based objectives, enhancing implementation, systems and service. Provides integral support in mission requirements determination, conceptualization, design, development, testing, verification and validation, documentation, and implementation of system applications or cybersecurity related
Disruptive Solutions LLC 47QTCA19D00M4 Page 17 assessments. Serve in a lead role managing, planning, and conducting major phases of significant tasks or projects, and working closely with stakeholders Must possess excellent oral and written communication skills. In general, work complexity and responsibility will be greater at higher levels. Must be able to work independently or with minimal supervision.
Certifications: One or more related certifications in a cybersecurity or information security field is preferred; for example, Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Security + or equivalent.
Cyber Information Assurance Specialist Level 3 developing, engineering, and implementing cybersecurity or information security solutions that will ensure proprietary/confidential data and systems are protected. Follows established written processes and procedures and may recommend/implement improvements to processes and procedures to complete essential cybersecurity tasks. Gathers and organizes technical information about an organization's mission goals and needs, existing security products, and ongoing programs in cybersecurity in the strategic design process to translate security and business requirements into technical designs. As part of a security assessment process, may configure and validate secure systems or assets; test security products and systems to detect security weakness. Conducts regular security assessments audits to ensure that systems are being operated securely, and computer security policies and procedures are being implemented as defined in security plans. Duties include architecture design, system/network/security analysis, vulnerability and risk assessments, and security assessment of hardware and software. Performs duties on tasks that require expertise in firewall, cyber, cloud computing, implementation/configuration, physical security analysis of facilities, security assessment/risk analysis, security design of local area networks and wide area networks, security analysis of network operating systems and applications, continuity of operations, planning, policy development and disaster recovery. In general, work complexity and responsibility will be greater at higher levels.
Certifications: One or more related certifications in a cybersecurity or information security field is preferred; for example, Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Security +, or equivalent.
Disruptive Solutions LLC 47QTCA19D00M4 Page 18
Cyber Information Assurance Specialist Level 4
Functional Responsibility: Services performed include but are not limited to leading or providing oversight of tasks focused on designing, developing, engineering, and implementing integrated cybersecurity or information security solutions that will ensure proprietary/confidential data and secure systems are protected. Gathers and organizes technical information about an organization's mission goals and needs, existing security products, and ongoing programs in computer security in the strategic design process to translate security and business requirements into technical designs. Follows established policies, written processes and procedures, and makes recommendations to improve policies, processes and procedures to complete essential cybersecurity tasks. As part of the security assessment process, configures and validates secure systems; tests security products and systems to detect security weakness. Conducts regular audits to ensure that systems are being operated securely, and computer security policies and procedures are being implemented as defined in security plans. Duties include system and network architecture design and analysis, vulnerability and risk assessments, and security assessment of assets. Performs duties on tasks that require expertise in firewall, cyber, cloud computing, implementation/configuration, physical security analysis of facilities, security assessment/risk analysis, security design of local area networks and wide area networks, security analysis of network operating systems and applications, continuity of operations, planning, policy development and disaster recovery. In general, work complexity and responsibility will be greater at higher levels. Must be able to work independently with minimal supervision.
Certifications: One or more related certifications in a cybersecurity or information security field is preferred; for example, Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Network +, Security +, or equivalent.
Cyber Project / Task Manager Level 6
Functional Responsibility: Performs day-to-day management of cyber security delivery, from original concept through final implementation. Responsible for the overall management of cyber security projects/tasks and ensuring that the technical solutions and schedules in are implemented in a timely manner. Possesses experience managing cyber security-focused projects/tasks and utilizes those proven skills to analyze new and complex project related problems and create innovative solutions involving financial management, scheduling, technology, methodology, tools, processes, standard operating procedures, and solution components. Understands relevant cybersecurity policies. Organizes, directs, and coordinates the planning and production of all activities associated with assigned delivery order projects. Defines and manages execution of project scope and objectives including developing detailed work plans, schedules, project estimates, resource plans, status reports, and project and financial tracking and analysis.
Conducts project meetings and ensures quality standards. Provides technical and strategic guidance to project team and reviews project deliverables. Works closely with government
Disruptive Solutions LLC 47QTCA19D00M4 Page 19 stakeholders to communicate project/task schedule and progress, as well as mitigate risks and issues. In general, work complexity and responsibility will be greater at higher levels. Performs enterprise-wide horizontal integration planning and interfaces to other functional areas as needed. Must possess strong communication skills (oral and written) and be able to work independently with minimal supervision.
Certifications: One or more related certifications in a cybersecurity or information security field is preferred; for example, Project Management Professional (PMP), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Security + or equivalent.
Cyber Systems Engineer Level 5
Functional Responsibility: Designs and implements solutions that meet agency Cybersecurity policy and regulations and makes recommendations for improvement. Applies National Institute of Standards and Technology (NIST) security controls, governance, risk management, and compliance security documentation tool, and has strong understanding of the DoD 8500 Series Risk Management Framework (RMF). Applies knowledge of DoD security processes, the Enterprise Mission Assurance Support Service, Security Technical Implementation Guides and cloud and mobile security. Possesses demonstrated experience of implementing cyber security policies, methodologies, identifying threats and developing appropriate protection measures, reviewing system changes for security implications and recommending improvements. Works with Cybersecurity tools, network topologies, intrusion detection, public key infrastructure (PKI), and secured networks. Integrates secure practices such as PKI integration, Identity and Access Management, multi-factor authentication, service-oriented architectures, and network or Web related protocols. Supports security audits and assessments. Formulates and defines solution scope and objectives, develops or modifies processes to solve complex cyber security-related problems through the use of innovative technologies. May perform in a leadership role managing, planning, and conducting major phases of significant projects, and overseeing work products. In general, work complexity and responsibility will be greater at higher levels.
Certifications: One or more related certifications in a cybersecurity or information security field is preferred; for example, Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Security + or equivalent.
Disruptive Solutions LLC 47QTCA19D00M4 Page 20
Cyber Systems Engineer Level 6
Functional Responsibility: Designs and implement solutions that meet agency Cybersecurity policy and regulations. Applies National Institute of Standards and Technology (NIST) security controls, governance, risk management, and compliance security documentation tool, as well as the DoD 8500 Series Risk Management Framework (RMF). Applies knowledge of DoD security processes, the Enterprise Mission Assurance Support Service, Security Technical Implementation Guides and cloud and mobile security. Possesses demonstrated experience of implementing cyber security policies, methodologies, identifying threats and developing appropriate protection measures, reviewing system changes for security implications and recommending improvements. Supports security audits and assessments Works with Cybersecurity tools, network topologies, intrusion detection, public key infrastructure (PKI), and secured networks. Formulates and defines system scope and objectives, develops or modifies processes to solve complex cyber security-related problems for computer systems and business and electronic interfaces to achieve desired results through the use of innovative technologies.
Must be able to work independently or with minimal supervision.
May perform in a leadership role managing, planning, and conducting major phases of significant projects, and overseeing work products. In general, work complexity and responsibility will be greater at higher levels.
Certifications: One or more related certifications in a cybersecurity or information security field is preferred; for example, Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Security + or equivalent.
Cyber Security Engineer Level 3 cybersecurity and technical tasks related protect and secure systems that store organizational data, as well as the IT infrastructure, including IT administration, hardware and software support, installation, configuration, maintenance, testing, security, electrical, mechanical, facilities, and help desk support. Research and analyze new cyber security technologies. Investigate cyber security solution issues. Ensure cyber security solutions are in compliance with organizational policies and guidelines. Assists with configurations, validates secure complex systems, and tests security products and systems to detect security weaknesses. Implement safeguards that prevent intrusions and threats. Identify threats and develop appropriate protection measures, review system changes for security implications and recommend improvements, applying a strong understanding of National Institute of Standards and Technology (NIST) security controls, governance, risk management, cyber security methodologies, and DoD (Department of Defense) 8500 series Risk Management Framework (RMF) processes.
Disruptive Solutions LLC 47QTCA19D00M4 Page 21
Certifications: One or more related certifications in a cybersecurity or information security field is preferred; for example, Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Network +, Security +, or equivalent.
Minimum Education: Associate degree or High School
Cyber Security Engineer Level 4 cybersecurity and technical tasks related protect and secure systems that store organizational data, as well as the IT infrastructure, including IT administration, hardware and software support, installation, configuration, maintenance, testing, security, electrical, mechanical, facilities, and help desk support. Research and pilot new cyber security technologies. Investigate cyber security solution issues. Ensure cyber security solutions are in compliance with organizational policies and guidelines. Assists with configurations, validates secure complex systems, and tests security products and systems to detect security weaknesses. Implement safeguards that prevent intrusions and threats. Identify threats and develop appropriate protection measures, review system changes for security implications and recommend improvements, applying a strong understanding of National Institute of Standards and Technology (NIST) security controls, governance, risk management, cyber security methodologies, and DoD (Department of Defense) 8500 series Risk Management Framework (RMF) processes.
Certifications: One or more related certifications in a cybersecurity or information security field is preferred; for example, Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Network +, Security +, or equivalent.
Cyber Security Engineer Level 5 cybersecurity and technical tasks related protect and secure systems that store organizational data, as well as the IT infrastructure, including IT administration, hardware and software support, installation, configuration, maintenance, testing, security, electrical, mechanical, facilities, and help desk support Research and pilot new cyber security technologies. Investigate cyber security solution issues. Ensure cyber security solutions are in compliance with organizational policies and guidelines. Assists with configurations, validates secure complex systems, and tests security products and systems to detect security weaknesses. Implement safeguards that prevent intrusions and threats. Identify threats and develop appropriate protection measures, review system changes for security implications and recommending improvements, applying a strong understanding of National Institute of Standards and Technology (NIST) security controls, Disruptive Solutions LLC 47QTCA19D00M4 Page 22 governance, risk management, cyber security methodologies, and DoD (Department of Defense) 8500 series Risk Management Framework (RMF) processes. Must be able to work independently or with minimal supervision. May perform in a leadership capacity conducting tasks and overseeing work products. In general, work complexity and responsibility will be greater at higher levels.
Certifications: One or more related certifications in a cybersecurity or information security field is preferred; for example, Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Network +, Security +, or equivalent.
Cyber Security SME Level 3
Functional Responsibility: Responsible for developing solutions to cybersecurity-related technical issues and problems that are undefined and complex. Participates in the development of solutions to complex technical issues and problems that impact multiple areas or disciplines.
Regularly employs ingenuity and creativity to develop new cybersecurity-related technical solutions and systems in order to achieve functional objectives. Safeguards information system assets by identifying and solving potential and actual security problems. Protects system by defining access privileges, control structures, and resources.
Recognizes problems by identifying abnormalities, reporting violations. Implement security improvements by assessing the current situation; evaluating trends; anticipating requirements.
Determines security violations and inefficiencies by conducting periodic audits. Upgrades system by implementing and maintaining security controls. Stays abreast of emerging cybersecurity trends and threats and communicates potential impact across stakeholders. Must be able to work independently or with minimal supervision.
Certifications: One or more related certifications or continuing education in a cybersecurity or information security field is preferred; for example, Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Network +, Security +, or equivalent.
Cyber Security SME Level 4 technical issues and problems that are undefined and complex. Develop solutions to complex technical issues and problems that impact multiple area or disciplines. Regularly employs ingenuity and creativity to develop new cybersecurity-related technical solutions and systems in
Disruptive Solutions LLC 47QTCA19D00M4 Page 23 order to achieve functional objectives. Safeguards information system assets by identifying and solving potential and actual security problems. Protects system by defining access privileges, control structures, and resources. Recognizes problems by identifying abnormalities, reporting violations. Implement security improvements by assessing the current situation; evaluating trends; anticipating requirements. Determines security violations and inefficiencies by conducting periodic audits. Upgrades system by implementing and maintaining security controls.
Develops cutting-edge solutions that display ingenuity and are achieved through collaboration and dialogue with other experts in the field. Resolves undefined, highly complex and multi-dimensional problems that require significant technical depth, conceptualization and interpretation. Requires expert knowledge and mastery of highly advanced technologies, scientific principles, theories and concepts. Stays abreast of emerging cybersecurity trends and threats and communicates potential impact across stakeholders. Must be able to work independently or with minimal supervision. Mentors and coaches junior technical staff.
Certifications: One or more related certifications in a cybersecurity or information security field is preferred; for example, Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Network +, Security +, or equivalent.
Cyber Security SME Level 5 technical issues and problems that are undefined and complex. Develop solutions to complex technical issues and problems that impact multiple area or disciplines. Regularly employs ingenuity and creativity to develop new cybersecurity-related technical solutions and systems in order to achieve functional objectives. Safeguards information system assets by identifying and solving potential and actual security problems. Protects system by defining access privileges, control structures, and resources. Recognizes problems by identifying abnormalities, reporting violations. Implement security improvements by assessing the current situation; evaluating trends; anticipating requirements. Determines security violations and inefficiencies by conducting periodic audits. Upgrades system by implementing and maintaining security controls.
Develops cutting-edge solutions that display ingenuity and are achieved through collaboration and dialogue with other experts in the field.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .