MAS - Z Softech Solutions Inc. - 47QTCA20D005K
DOCX document 2 MB
- Attached to
- Federal Supply Schedule 47QTCA20D005K Federal contract IDV
- Contract number
- 47QTCA20D005K
- Issued by
- GSA Federal Acquisition Service
About this file
This document provides a price list for a federal supply schedule contract to provide information technology services. The contractor, Z SofTech Solutions, was awarded a multiple award schedule contract with the General Services Administration effective January 31, 2020 through January 30, 2025. Services offered under the contract include highly adaptive cybersecurity services, cloud and cloud-related IT professional services, healthcare information technology, and general IT services. Labor categories on the contract range from entry-level positions such as testing and validation specialists to senior positions such as cybersecurity subject matter experts. Rates are provided for each labor category. The contract enables government agencies to issue task orders for the provided IT services.
Z Softech Solutions, Inc. Pricelist and/or Vendor Terms and Conditions for 47QTCA20D005K, a Federal Supply Schedule awarded to Z Softech Solutions, Inc., under Information Technology Schedule 70 (IT-70)
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
U.S. General Services Administration
MAS
Federal Supply Service
Authorized Federal Supply Schedule Price List On-line access to contract ordering information, terms and conditions, up-to-date pricing, and the option to create an electronic delivery order are available through GSA Advantage! ®, a menu-driven database system. The INTERNET address GSA Advantage!
® is: GSAAdvantage.gov.
SPECIAL ITEM NUMBER 54151HACS – Highly Adaptive Cybersecurity Services (HACS) SPECIAL ITEM NUMBER 518210C – Cloud and Cloud Related IT Professional Services SPECIAL ITEM NUMBER 54151HEAL- Healthcare Informational Technology
SPECIAL ITEM NUMBER 54151S- InformationTechnology (IT) Services
FPDS Code D301 IT Facility Operation and Maintenance FPDS Code D302 IT Systems Development Services FPDS Code D306 IT Systems Analysis Services
FPDS Code D307 Automated Information Systems Design and Integration Services FPDS Code D308 Programming Services
FPDS Code D310 IT Backup and Security Services FPDS Code D311 IT Data Conversion Services
FPDS Code D313 Computer Aided Design/Computer Aided Manufacturing (CAD/CAM) Services FPDS Code D316 IT Network Management Services
FPDS Code D317 Creation/Retrieval of IT Related Automated News Services, Data Services, or
Other Information Services (All other information services belong under Schedule 76) FPDS Code D399 Other Information Technology Services, Not Elsewhere Classified z SofTech Solutions, INC 235 Peachtree Street, Suite 400
Atlanta, GA 30303 www.zsoftechsolutions.com
678-778-7817
Contract Number: 47QTCA20D005K
Period Covered by Contract: January 31, 2020 through Janauray 30, 2025
For more information on ordering from Federal Supply Schedules click on the FSS Schedules button at fss.gsa.gov.
Contract period
Note 1: All non-professional labor categories must be incidental to and used solely to support hardware, software, and/or professional services, and cannot be purchased separately.
Note 2: Offerors and Agencies are advised that the Group 70 – Information Technology Schedule is not to be used as a means to procure services which properly fall under the Brooks Act. These services include, but are not limited to, architectural, engineering, mapping, cartographic production, remote sensing, geographic information systems, and related services. FAR 36.6 distinguishes between mapping services of an A/E nature and mapping services which are not connected nor incidental to the traditionally accepted A/E Services.
Note 3: This solicitation is not intended to solicit for the reselling of IT Professional Services, except for the provision of implementation, maintenance, integration, or training services in direct support of a product. Under such circumstances the services must be performance by the publisher or manufacturer or one of their authorized agents.
Customer Information:
1a. Table of Awarded Special Item Number(s) with appropriate cross-reference to page numbers:
SIN Description 54151HACS Highly Adaptive Cybersecurity Services (HACS)
518210C Cloud and Cloud Related IT Professional Services 54151HEAL Healthcare Information Technology (HIT)
54151S - InformationTechnology (IT) Services
1b. Identification of the lowest priced model number and lowest unit price for that model for each special item number awarded in the contract. This price is the Government price based on a unit of one, exclusive of any quantity/dollar volume, prompt payment, or any other concession affecting price. Those contracts that have unit prices based on the geographic location of the customer, should show the range of the lowest price, and cite the areas to which the prices apply.
1c. If the Contractor is proposing hourly rates a description of all corresponding commercial job titles, experience, functional responsibility, and education for those types of employees or subcontractors who will perform services shall be provided. If hourly rates are not applicable, indicate “Not applicable” for this item.
2. Maximum Order: $500,000.00
3. Minimum Order: $100.00
4. Geographic Coverage (delivery Area): Domestic (50 States, DC, PR) & Overseas
5. Point(s) of production (city, county, and state or foreign country): N/A
6. Discount from list prices or statement of net price: Government net prices (discounts already deducted).
7. Quantity discounts: None offered
8. Prompt payment terms: Net 30 days
9a. Notification that Government purchase cards are accepted up to the micro-purchase threshold: Yes
9b. Notification whether Government purchase cards are accepted or not accepted above the micro-purchase threshold:
Will not accept over the micro purchase threshold
10. Foreign items (list items by country of origin): None
11a. Time of Delivery (Contractor insert number of days): Specified on the Task Order and shall deliver or perform services in accordance with the terms negotiated in an agency’s order.
11b. Expedited Delivery. The Contractor will insert the sentence “Items available for expedited delivery are noted in this price list.” under this heading. The Contractor may use a symbol of its choosing to highlight items in its price list that have expedited delivery: Contact Contractor
11c. Overnight and 2-day delivery. The Contractor will indicate whether overnight and 2-day delivery are available. Also, the Contractor will indicate that the schedule customer may contact the Contractor for rates for overnight and 2-day delivery: Contact Contractor
11d. Urgent Requirements. The Contractor will note in its price list the “Urgent Requirements” clause of its contract and advise agencies that they can also contact the Contractor’s representative to effect a faster delivery: Contact Contractor
12. F.O.B Points(s): Destination
13a. Ordering Address(es):
Z SofTech Solutions, INC 235 Peachtree Street, Suite 400 Atlanta, GA 30303
13b. Ordering procedures: For supplies and services, the ordering procedures, information on Blanket Purchase Agreements (BPA’s), and a sample BPA can be found at the GSA/FSS Schedule homepage (fss.gsa.gov/schedules).
14. Payment address(es):
Z SofTech Solutions, INC 235 Peachtree Street, Suite 400 Atlanta, GA 30303
15. Warranty provision.: Contractor’s standard commercial warranty.
16. Export Packing Charges (if applicable): N/A
17. Terms and conditions of Government purchase card acceptance (any thresholds above the micro-purchase level):
Contact Contractor
18. Terms and conditions of rental, maintenance, and repair (if applicable): N/A
19. Terms and conditions of installation (if applicable): N/A
20. Terms and conditions of repair parts indicating date of parts price lists and any discounts from list prices (if applicable):
N/A
20a. Terms and conditions for any other services (if applicable): N/A
21. List of service and distribution points (if applicable): N/A
22. List of participating dealers (if applicable): N/A
23. Preventive maintenance (if applicable): N/A
24a. Environmental attributes, e.g., recycled content, energy efficiency, and/or reduced pollutants: N/A
24b. If applicable, indicate that Section 508 compliance information is available on Electronic and Information Technology
(EIT) supplies and services and show where full details can be found (e.g. contactor’s website or other location.) The EIT standards can be found at: www.Section508.gov/.
25. Data Universal Numbering System (DUNS) number: 079434552 and CAGE CODE:78H69
26. Notification regarding registration in the System for Award Management (SAM) Database: Registered
TERMS AND CONDITIONS APPLICABLE TO Highly Adaptive Cybersecurity Services (HACS)
(SPECIAL ITEM NUMBER 54151HACS)
Vendor suitability for offering services through the Highly Adaptive Cybersecurity Services (HACS) SIN must be in accordance with the following laws and standards when applicable to the specific task orders, including but not limited to:
● Federal Acquisition Regulation (FAR) Part 52.204-21
● OMB Memorandum M-17-12 - Preparing for and Responding to a Breach of Personally Identifiable Information (PII)
● OMB Memorandum M- 19-03 - Strengthening the Cybersecurity of Federal Agencies by enhancing the High Value Asset Program
● 2017 Report to the President on Federal IT Modernization
● The Cybersecurity National Action Plan (CNAP)
● NIST SP 800-14 - Generally Accepted Principles and Practices for Securing Information Technology Systems
● NIST SP 800-27A - Engineering Principles for Information Technology Security (A Baseline for Achieving Security)
● NIST SP 800-30 - Guide for Conducting Risk Assessments
● NIST SP 800-35 - Guide to Information Technology Security Services
● NIST SP 800-37 - Risk Management Framework for Information Systems and Organizations: A Systems Life Cycle Approach for
Security and Privacy
● NIST SP 800-39 - Managing Information Security Risk: Organization, Mission, and Information System View
● NIST SP 800-44 - Guidelines on Securing Public Web Servers
● NIST SP 800-48 - Guide to Securing Legacy IEEE 802.11 Wireless Networks
● NIST SP 800-53 – Security and Privacy Controls for Federal Information Systems and Organizations
● NIST SP 800-61 - Computer Security Incident Handling Guide
● NIST SP 800-64 - Security Considerations in the System Development Life Cycle
● NIST SP 800-82 - Guide to Industrial Control Systems (ICS) Security
● NIST SP 800-86 - Guide to Integrating Forensic Techniques into Incident Response
● NIST SP 800-115 - Technical Guide to Information Security Testing and Assessment
● NIST SP 800-128 - Guide for Security-Focused Configuration Management of Information Systems
● NIST SP 800-137 - Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations
● NIST SP 800-153 - Guidelines for Securing Wireless Local Area Networks (WLANs)
● NIST SP 800-160 - Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of
Trustworthy Secure Systems
● NIST SP 800-171 - Protecting Controlled Unclassified Information in non-federal Information Systems and Organizations
1. SCOPE
a. The labor categories, prices, terms and conditions stated under Special Item Number 54151HACS Highly Adaptive
Cybersecurity Services (HACS) apply exclusively to Highly Adaptive Cybersecurity Services within the scope of this Information Technology Schedule.
b. Services under this SIN are limited to Highly Adaptive Cybersecurity Services only. Software and hardware products are under different Special Item Numbers on MAS and may be quoted along with services to provide a total solution.
c. This SIN provides ordering activities with access to Highly Adaptive Cybersecurity services only.
d. Highly Adaptive Cybersecurity Services provided under this SIN shall comply with all Cybersecurity certifications and industry standards as applicable pertaining to the type of services as specified by ordering agency.
e. SCOPE:
54151HACS Highly Adaptive Cybersecurity Services (HACS) - SUBJECT TO COOPERATIVE PURCHASING includes proactive and reactive cybersecurity services that improve the customer’s enterprise-level security posture.
The scope of this category encompasses a wide range of fields that include, but are not limited to, Risk Management Framework
(RMF) services, information assurance (IA), virus detection, network management, situational awareness and incident response, secure web hosting, and backup and security services.
The seven-step RMF includes preparation, information security categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring. RMF activities may also include
Information Security Continuous Monitoring Assessment (ISCMA) which evaluate organization-wide ISCM implementations, and also Federal Incident Response Evaluations (FIREs), which assess an organization’s incident management functions.
The scope of this category also includes Security Operations Center (SOC) services. The SOC scope includes services such as:
24x7x365 monitoring and analysis, traffic analysis, incident response and coordination, penetration testing, anti-virus management, intrusion detection and prevention, and information sharing. HACS vendors are able to identify and protect a customer’s information resources, detect and respond to cybersecurity events or incidents, and recover capabilities or services impaired by any incidents that emerge.
Sub-Categories - (not all vendors have been placed within the following subcategories. To view a complete list of vendors, click on the SIN)
● High Value Asset (HVA) Assessments include Risk and Vulnerability Assessment (RVA) which assesses threats and vulnerabilities, determines deviations from acceptable configurations, enterprise or local policy, assesses the level of risk, and develops and/or recommends appropriate mitigation countermeasures in operational and non-operational situations. The services offered in the RVA sub-category include Network Mapping, Vulnerability Scanning, Phishing Assessment, Wireless Assessment, Web Application Assessment, Operating System Security Assessment (OSSA), Database Assessment, and Penetration Testing. Security Architecture Review (SAR) evaluates a subset of the agency’s HVA security posture to determine whether the agency has properly architected its cybersecurity solutions and ensures that agency leadership fully understands the risks inherent in the implemented cybersecurity solution. The SAR process utilizes in-person interviews, documentation reviews, and leading practice evaluations of the HVA environment and supporting systems. SAR provides a holistic analysis of how an HVA’s individual security components integrate and operate, including how data is protected during operations. Systems Security Engineering (SSE) identifies security vulnerabilities and minimizes or contains risks associated with these vulnerabilities spanning the Systems Development Life Cycle. SSE focuses on, but is not limited to the following security areas:
perimeter security, network security, endpoint security, application security, physical security, and data security.
● Risk and Vulnerability Assessment (RVA) assesses threats and vulnerabilities, determines deviations from acceptable configurations, enterprise or local policy, assesses the level of risk, and develops and/or recommends appropriate mitigation countermeasures in operational and non-operational situations. The services offered in the RVA sub-category include Network Mapping, Vulnerability Scanning, Phishing Assessment, Wireless Assessment, Web Application Assessment, Operating System Security Assessment (OSSA), Database Assessment, and Penetration Testing
● Cyber Hunt activities respond to crises or urgent situations within the pertinent domain to mitigate immediate and potential threats.
Cyber Hunts start with the premise that threat actors known to target some organizations in a specific industry or with specific systems are likely to also target other organizations in the same industry or with the same systems.
● Incident Response services help organizations impacted by a cybersecurity compromise determine the extent of the incident, remove the adversary from their systems, and restore their networks to a more secure state.
● Penetration Testing is security testing in which assessors mimic real-world attacks to identify methods for circumventing the security features of an application, system, or network.
f. The Contractor shall provide services at the Contractor’s facility and/or at the ordering activity location, as agreed to by the
Contractor and the ordering activity.
2. ORDER
a. Agencies may use written orders, Electronic Data Interchange (EDI) orders, Blanket Purchase Agreements, individual purchase orders, or task orders for ordering services under this contract. Blanket Purchase Agreements shall not extend beyond the end of the contract period; all services and delivery shall be made and the contract terms and conditions shall continue in effect until the completion of the order. Orders for tasks which extend beyond the fiscal year for which funds are available shall include FAR 52.232-19 (Deviation – May 2003) Availability of Funds for the Next Fiscal Year. The purchase order shall specify the availability of funds and the period for which funds are available.
b. All task orders are subject to the terms and conditions of the contract. In the event of conflict between a task order and the contract, the contract will take precedence.
3. PERFORMANCE OF SERVICES
a. The Contractor shall commence performance of services on the date agreed to by the Contractor and the ordering activity. All
Contracts will be fully funded.
b. The Contractor agrees to render services during normal working hours, unless otherwise agreed to by the Contractor and the ordering activity.
c. The ordering activity should include the criteria for satisfactory completion for each task in the Statement of Work or Delivery
Order. Services shall be completed in a good and workmanlike manner.
d. Any Contractor travel required in the performance of Highly Adaptive Cybersecurity Services must comply with the Federal
Travel Regulation or Joint Travel Regulations, as applicable, in effect on the date(s) the travel is performed. Established Federal Government per diem rates will apply to all Contractor travel. Contractors cannot use GSA city pair contracts. All travel will be agreed upon with the client prior to the Contractor’s travel.
4. INSPECTION OF SERVICES
Inspection of services is in accordance with 552.212-4 - CONTRACT TERMS AND CONDITIONS COMMERCIAL ITEMS (Jan
2017) & (ALTERNATE I-Jan 2017) for Time-and-Materials and Labor-Hour orders placed under this contract.
5. RESPONSIBILITIES OF THE CONTRACTOR
Contractor shall comply with all laws, ordinances, and regulations (Federal, State, City, or otherwise) covering work of this character.
If the end product of a task order is software, then FAR 52.227-14 (May 2014) Rights in Data – General, may apply.
The Contractor shall comply with contract clause (52.204-21) to the Federal Acquisition Regulation (FAR) for the basic safeguarding of contractor information systems that process, store, or transmit Federal data received by the contract in performance of the contract. This includes contract documents and all information generated in the performance of the contract.
6. RESPONSIBILITIES OF THE ORDERING ACTIVITY
Subject to the ordering activity security regulations, the ordering activity shall permit Contractor access to all facilities necessary to perform the requisite Highly Adaptive Cybersecurity Services.
7. INDEPENDENT CONTRACTOR
All Highly Adaptive Cybersecurity Services performed by the Contractor under the terms of this contract shall be as an independent
Contractor, and not as an agent or employee of the ordering activity.
8. ORGANIZATIONAL CONFLICTS OF INTEREST
a. Definitions.
“Contractor” means the person, firm, unincorporated association, joint venture, partnership, or corporation that is a party to this contract.
“Contractor and its affiliates” and “Contractor or its affiliates” refers to the Contractor, its chief executives, directors, officers, subsidiaries, affiliates, subcontractors at any tier, and consultants and any joint venture involving the Contractor, any entity into or with which the Contractor subsequently merges or affiliates, or any other successor or assignee of the Contractor.
An “Organizational conflict of interest” exists when the nature of the work to be performed under a proposed ordering activity contract, without some restriction on ordering activities by the Contractor and its affiliates, may either (i) result in an unfair competitive advantage to the Contractor or its affiliates or (ii) impair the Contractor’s or its affiliates’ objectivity in performing contract work.
b. To avoid an organizational or financial conflict of interest and to avoid prejudicing the best interests of the ordering activity, ordering activities may place restrictions on the Contractors, its affiliates, chief executives, directors, subsidiaries and subcontractors at any tier when placing orders against schedule contracts. Such restrictions shall be consistent with FAR 9.505 and shall be designed to avoid, neutralize, or mitigate organizational conflicts of interest that might otherwise exist in situations related to individual orders placed against the schedule contract. Examples of situations, which may require restrictions, are provided at FAR 9.508.
9. INVOICES
The Contractor, upon completion of the work ordered, shall submit invoices for Highly Adaptive Cybersecurity Services.
Progress payments may be authorized by the ordering activity on individual orders if appropriate. Progress payments shall be based upon completion of defined milestones or interim products. Invoices shall be submitted monthly for recurring services performed during the preceding month.
10. RESUMES
Resumes shall be provided to the GSA Contracting Officer or the user ordering activity upon request.
11. APPROVAL OF SUBCONTRACTS
The ordering activity may require that the Contractor receive, from the ordering activity Contracting Officer, written consent before placing any subcontract for furnishing any of the work called for in a task order.
12. DESCRIPTION OF HIGHLY ADAPTIVE CYBERSECURITY SERVICES AND PRICING
Please refer to the labor category descriptions and pricing incorporated into this GSA Pricelist.
LABOR CATEGORY DESCRIPTIONS:
HIGHLY ADAPTIVE CYBERSECURITY SERVICES (HACS) SIN 54151HACS
Testing and Validation Specialist Cybersecurity- Functional Responsibility: Cybersecurity subject matter specialist providing test and evaluation plans for the support of user requirements of complex to highly complex software/hardware applications. Directs and/or participates in all phases of risk management assessments, vulnerability scans and software/hard- ware development with emphasis on identifying security issues based on vulnerabilities and/or data configuration. May conduct and support authorized penetration testing on enterprise network assets. Suggest security controls in order to mitigate risk.
Educational Requirements: Bachelor’s Degree in Computer Science, Computer Information Systems, or Engineering Experience:
Minimum / General - 5 Years’ Experience
Security Operations Center (SOC) Analyst 1 Minimum/General Experience: 0 Functional Responsibility: Provide cyber threat analysis and reporting to support SOC and Program’s situational awareness. Actively monitor security threats and risks. Track investigation results and report on findings. Duties may include: support Security Operations Center and monitors security tools to review and analyze pre-defined events indicative of incidents and provide first tier response to security incidents; follow standard operating procedures for detecting, classifying, and reporting incidents under the supervision of Tier 2 and Tier 3 staff; and, managing cases within incident management systems.
Minimum Education: Bachelor’s Degree
Risk and Vulnerability Threat Analyst 1 Minimum/General Experience: 2 Functional Responsibility: Participate in conduct of controls and security assessments to assess risk of exposure of proprietary data through weaknesses in platforms, access procedures, or forms of access to the organization’s systems and the data contained in them. Duties may include: provides technical support on post event network security logs and trend analysis; uncovers security and compliance violations; associates and correlates IP address related events with specific systems or devices in the IT infrastructure; support development and analysis of system and security documentation; maintain documentation for exceptions to standards.
Minimum Education: Bachelor’s Degree
Incident Response Analyst 1- Minimum/General Experience: 2 Functional Responsibility: Contributes to generating response to crisis or urgent situations to mitigate immediate and/or potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security. Duties may include: handle and respond to cyber security incidents through coordination with stakeholders such as internal IT entities, security leadership, legal affairs, internal affairs, law enforcement, and privacy offices; intake incident reporting, conduct ticket updates, and notify stakeholders of cyber security incidents and forensic investigations in relation to computer security incidents and escalate when necessary as well as coordinate response to computer security incidents; recommend a course of action on each incident and creates, manages, and records all actions taken and serve as initial POC for Events of Interest reported both internally and externally; establishes alarm/incident escalation process and tracks, follows-up, and resolves incidents; and, initiates and maintains contact with affected parties during incident response lifecycle.
Investigates potential incidents/intrusions.
Minimum Education: Bachelor’s Degree
Cyber Technical Architect 1 - Minimum/General Experience: 2 Functional Responsibility: The Cyber Technical Architect 1 provides thought leadership related to current and future customer plans with regard to protecting customer information technology from cyber threats. This individual possesses knowledge of the future direction and trends associated with the stated information technology, and is up to date with current threats associated with it. This individual is experienced in designing and implementing protections for information architecture solutions for the stated information technology. This individual designs secure architecture to include the software, hardware, and communications to support the total requirements as well as provide for present and future cross-functional requirements and interfaces.
Minimum Education: Bachelor’s Degree
Cyber Security Analyst I - Minimum/General Experience: 2 Functional Responsibility: Cyber Security Analyst I will have a basic understandings of concepts and terms related access control systems; cryptography; security architecture; operations security; applications security and systems development; statutory and regulatory compliance; forensics, investigations, or security ethics. The Cyber Security Analyst I will assist in penetration testing, incident response and cyber hunt activities as well as systems certification and accreditation projects, including the development of system documentation, system hardening, safeguard implementation, vulnerability assessments, and risk analysis. They will assist with the management and administration of enterprise security programs.
Minimum Education: Bachelor’s Degree
Cyber Security Engineer I - Minimum/General Experience: 2 Functional Responsibility: Participate in special projects or investigations into specific technology or solution issues and research and piloting of new technologies. Serve as a point of contact for engineering efforts while assisting in maintaining compliance with the customer's policies and guidelines. Duties may include: provide administrative support to enterprise security devices; provide support of various applications and implement security standards; and, assist with configuration, validate secure complex systems, and test security products and systems to detect security weakness. Cyber Security Engineer I develops cyber security systems assurance programs and control guidelines.
Capable of performing vulnerability scans of networks, providing technical evaluations, identifying risks and proposing mitigation strategies, conducting system-specific tests and evaluations in realistic network configurations to validate secure operational capabilities and/or discover vulnerabilities, performing residual risk analysis to support system assessment and authorization.
Minimum Education: Bachelor’s Degree
Security Operations Center (SOC) Analyst 2 Minimum/General Experience: 2 Functional Responsibility: Provide cyber threat analysis and reporting to support SOC and Program’s situational awareness. Actively monitor security threats and risks. Track investigation results and report on findings. Duties may include: support Security Operations Center and monitors security tools to review and analyze pre-defined events indicative of incidents and provides first tier response to security incidents; monitor network traffic for security events and perform triage analysis to identify security incidents; respond to computer security incidents by collecting, analyzing, preserving digital evidence and ensure that incidents are recorded and tracked in accordance with SOC requirements; work closely with the other teams to assess risk and provide recommendations for improving our security posture; recommend content to detect security events; managing cases within incident management systems; perform network Forensics and deep packet analysis; and, identify countermeasures to detect and prevent security incidents.
Minimum Education: Bachelor’s Degree
Cyber Security Specialist 1 - Minimum/General Experience: 2 Functional Responsibility: The Cyber Security Specialist 1 may identify and resolve highly complex issues to prevent cyber attacks on information systems and to keep computer information systems secure from interruption of service, intellectual property theft, network viruses, data mining, financial theft, and theft of sensitive customer data, allowing business to continue as normal. This is accomplished through the systematic implementation of a cyber framework and process. The Cyber Security Specialist designs, installs, and manages security mechanisms that protect networks and information systems against hackers, breaches, viruses, and spyware. This individual responds to incidents, investigates violations, and recommends enhancements to plug potential security gaps. Level 1 performs more routine aspects of the position and is supervised by higher levels.
Minimum Education: Bachelor’s Degree
Cyber Application Architect 1 - Minimum/General Experience: 2 Functional Responsibility: The Cyber Application Architect may plan, design, develop, redesign or enhance, install, or implement various cyber technology products, or enhance computer programs. This individual applies knowledge of software and programming to develop and test the security of computer systems and produce the necessary outcome for clients. The Application Architect may draft technical white papers to better understand the cyber technology behind them, and to provide instructions that help the client better understand the nature and applications of a specific cyber product.
Risk and Vulnerability Threat Analyst 2 - Minimum/General Experience: 4 Functional Responsibility: Participates in the conduct of controls and security assessments to assess risk of exposure of proprietary data through weaknesses in platforms, access procedures, or forms of access to the organization’s systems and the data contained in them. Duties may include: develop, document and execute containment strategies; document and brief the business on remediation options and execute the plan with stakeholders; produce final report and recommendation; coordinate efforts of, and provide timely updates to, multiple business units during response;
performing in-depth analysis in support of incident response operations; develop requirements for technical capabilities for cyber incident management; investigate major breaches of security and recommending appropriate control improvements; work with infrastructure and application support teams to drive closure of follow up actions identified through incident and problem management; performs Security Control Assessments on systems to validate the results of risk assessments and ensure controls in the security plan are present and operating correctly on the system; provides thorough report of the risks to the system and its data; and, develop and analyze system and security documentation.
Minimum Education: Bachelor’s Degree
Incident Response Analyst 2 - Minimum/General Experience: 4 Functional Responsibility: Contributes to generating responses to crisis or urgent situations to mitigate immediate and/or potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security. Duties may include: provides oversight for incident data flow and response, content, and remediation, and partners with other incident response centers in maintaining an understanding of threats, vulnerabilities, and exploits that could impact networks and assets; performs real-time proactive event investigation on various security enforcement systems, such as SIEM, Anti-virus, Internet content filtering/reporting, malcode prevention, Firewalls, IDS & IPS, Web security, anti-spam, etc; performs the role of Incident Coordinator for IT Security events requiring focused response, containment, investigation, and remediation;
performs forensic analysis on hosts supporting investigations; and, conducts malware analysis in out-of-band environment (static and dynamic), including complex malware.
Minimum Education: Bachelor’s Degree
Cyber Program Analyst - Minimum/General Experience: 4 Functional Responsibility: The Cyber Program Analyst analyzes and critiques existing computer programs and systems security measures, and develops new measures. The program analyst may: review users’ requests for new or modified computer programs to determine feasibility, cost and time required, compatibility with current system, and security capabilities; outline steps required to develop program, using structured security analysis and design; and, plan, develop, test, and document computer programs, applying knowledge of cyber security, programming techniques, and computer systems.
Minimum Education: Bachelor’s Degree
Cyber Security Analyst II Minimum/General Experience: 4 Functional Responsibility: Cyber Security Analyst II supports development of technical solutions to support client’s requirements in solving moderately complex network, platform, and system security problems. They will assist with the management and administration of enterprise security programs. Responsibilities include: assisting with incident response, cyber hunt activities, penetration testing, cyber system engineering, development, and monitoring. Cyber Security Analyst II will also conduct security control assessments with cyber security stakeholders, collect and review artifacts and evidence for compliance with security controls, and document assessment results in a security assessment report and risk assessment report.
Minimum Education: Bachelor’s Degree
Security Operations Center (SOC) Analyst 3 - Minimum/General Experience: 4 Functional Responsibility: Provide cyber threat analysis and reporting to support SOC and Program’s situational awareness. Actively monitor security threats and risks. Track investigation results and report on findings. Duties may include: support a Security Operations Center and monitors security tools to review and analyze pre-defined events indicative of incidents and provide first tier response to security incidents; lead shifts and functional IR teams, provides oversight and be responsible for event investigation and tracking activities; support Tier 2 operations by monitoring alerts during critical and high volume events; conduct more in-depth analyses of security incidents to identify incidents of compromise; perform intrusion scope and root cause analyses and assist with intrusion remediation, strategy development, and implementation; recommend effective process changes to enhance defense and response procedures;
use SOC monitoring devices to review and analyze pre-defined events indicative of incidents, create and recommend content to detect security events; conduct malware analysis in out-of-band environment (static and dynamic), including complex malware; vet IOCs and intelligence vetting and disposition, assess feed viability; perform network Forensics and deep packet analysis; identify countermeasures to detect and prevent security incidents.; and, support knowledge management and developing procedures and policies for initial stand up of a security operations center (SOC).
Minimum Education: Bachelor’s Degree
Cyber Security Specialist 2 - Minimum/General Experience: 4 Functional Responsibility: The Cyber Security Specialist 2 may identify and resolve highly complex issues to prevent cyber attacks on information systems and to keep computer information systems secure from interruption of service, intellectual property theft, network viruses, data mining, financial theft, and theft of sensitive customer data, allowing business to continue as normal. This is accomplished through the systematic implementation of a cyber framework and process. The Cyber Security Specialist designs, installs, and manages security mechanisms that protect networks and information systems against hackers, breaches, viruses, and spyware. This individual responds to incidents, investigates violations, and recommends enhancements to plug potential security gaps. Level 2 performs more varied and difficult tasks compared to Level 1, yet has less autonomy than Level 3.
Cyber Security Engineer II - Minimum/General Experience: 4 Functional Responsibility: Participate in special projects or investigations into specific technology or solution issues and research and piloting of new technologies. Serve as a point of contact for engineering efforts while maintaining compliance with the customer's policies and guidelines. Duties may include: configure and maintain policies; maintain documentation for exceptions to standards; provides timely and adequate response to threats/alerts; assess security events to drive to a resolution; provides timely and sufficient response to security incidents and assessment services;
and, promotes security awareness. Cyber Security Engineer II develops cyber security systems assurance programs and control guidelines. Capable of performing vulnerability scans of networks, providing technical evaluations, identifying risks and proposing mitigation strategies, conducting system-specific tests and evaluations in realistic network configurations to validate secure operational capabilities and/or discover vulnerabilities, performing residual risk analyses to support system certification and accreditation. Insures that solutions are fully compatible with or engineered into the customer’s network design.
Minimum Education: Bachelor’s Degree
Cyber Application Systems Analyst - Minimum/General Experience: 2 Functional Responsibility: The Cyber Application System Analyst may oversee the implementation of required hardware and software security components for approved applications, coordinates security tests of the application system to ensure proper performance, and develops diagrams and flowcharts for computer programmers to follow.
This individual previews, analyzes, and modifies programming systems, including encoding, debugging, and installing security measures to support an organization's application systems. The Cyber Application System Analyst develops application specifications, identifies the required inputs, and formats the output to meet user's needs.
Minimum Education: Bachelor’s Degree
Cyber Operations Manager - Minimum/General Experience: 4 Functional Responsibility: The Cyber Operation Manager manages, coordinates, or organizes department cyber operation strategies and activities. The Operation Manager may: collaborate in the development and implementation of organization cyber policies, practices, procedures, and attainment of operating goals; review, analyze, and prepare reports, records, and directives, and confers with managers/supervisors to obtain data required for planning activities, such as new commitments, status of work in progress, and problems encountered; and, disseminate policies and objectives to supervisors/staff.
Minimum Education: Bachelor’s Degree
Cyber Technical Architect 2 - Minimum/General Experience: 4 Functional Responsibility: The Cyber Technical Architect 2 provides thought leadership related to current and future customer plans with regard to protecting customer information technology from cyber threats. This individual possesses knowledge of the future direction and trends associated with the stated information technology, and is up to date with current threats associated with it. This individual has experience in designing and implementing protections for information architecture. This individual designs secure architecture to include the software, hardware, and communications to support the total requirements as well as provide for present and future cross- functional requirements and interfaces.
Minimum Education: Bachelor’s Degree
Risk and Vulnerability Threat Analyst 3 Minimum/General Experience: 8 Functional Responsibility: Participates in the conduct of controls and security assessments to assess risk of exposure of proprietary data through weaknesses in platforms, access procedures, or forms of access to the organization’s systems and the data contained in them. Duties may include: support engineering design teams by assessing network and system security design features and making recommendations concerning overall security accreditation readiness and compliance and best practices; support interoperability assessment teams and present written analysis and conclusions in all phases of analysis; develop and analyze system and security documentation; follow up with site administrators for status on non-compliant platforms and maintain any necessary exception documentation; maintain documentation for exceptions to standards; participate in Security Control Assessments on systems to validate the results of risk assessments and ensure controls in the security plan are present and operating correctly on the system; provides thorough report of the risks to the system and its data; and, evaluate system findings, develop PO&AMs, and briefed stakeholders on key findings, recommendations, risk, and impact.
Minimum Education: Bachelor’s Degree
Cyber Training Specialist Minimum/General Experience: 4 Functional Responsibility: The Cyber Training Specialist develops teaching outlines and determines instructional methods, using knowledge of specific training needs and effectiveness of such methods as individual training, group instruction, lectures, demonstrations, conferences, meetings, or workshops. This individual prepares, organizes and heads training sessions covering standard training, specialized training or counseling in designated areas.
Minimum Education: Bachelor’s Degree
Incident Response Analyst 3 - Minimum/General Experience: 8 Functional Responsibility: Contributes to generating responses to crisis or urgent situations to mitigate immediate and / or potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security. Duties may include: lead shifts and functional IR teams, provides oversight for incident data flow and response, content, and remediation, and partners with other incident response centers in maintaining an understanding of threats, vulnerabilities, and exploits that could impact networks and assets; performs real-time proactive event investigation on various security enforcement systems, such as SIEM, Anti-virus, Internet content filtering/reporting, malcode prevention, Firewalls, IDS & IPS, Web security, antispam, etc; performs the role of Incident Coordinator for IT Security events requiring focused response, containment, investigation, and remediation; performs forensic analysis on hosts supporting investigations; conducts malware analysis in out-of-band environment (static and dynamic), including complex malware; coordinate response action to identifies threats and incidents; analyze operational anomalies, network behavior and performs mitigation actions derived from cyber threat monitoring and anomaly analysis, and actively monitors the networks for cybersecurity threats and vulnerabilities; provide oversight and perform quality assurance on Incident Closures; assist with knowledge management - Standard Operating Procedures and procedural support data.
Minimum Education: Bachelor’s Degree
Penetration Tester I - Minimum/General Experience: 2 Functional Responsibility: Finds security vulnerabilities in target systems, networks, and applications in order to help enterprises improve their security. Works under immediate supervision and usually reports to a supervisor.
Minimum Education: Bachelor’s Degree
Cyber Enterprise Architect Minimum/General Experience: 4 Functional Responsibility: The Cyber Enterprise Architect works with stakeholders, both leadership and subject matter experts, to build a holistic view of the organization's strategy, processes, information, and information technology assets to ensure that the business and IT are in alignment and protected from cyber threats. The Cyber Enterprise Architect links the business mission, strategy, and processes of an organization to its IT strategy - including security, and documents this using multiple architectural models or views that show how the current and future needs of an organization will be met in an efficient, sustainable, agile, secure, and adaptable manner.
Minimum Education: Bachelor’s Degree
Cyber Security Specialist 3 - Minimum/General Experience: 8 Functional Responsibility: The Cyber Security Specialist 3 may identify and resolve highly complex issues to prevent cyber attacks on information systems and to keep computer information systems secure from interruption of service, intellectual property theft, network viruses, data mining, financial theft, and theft of sensitive customer data, allowing business to continue as normal. This is accomplished through the systematic implementation of a cyber framework and process. The Cyber Security Specialist designs, installs, and manages security mechanisms that protect networks and information systems against hackers, breaches, viruses, and spyware. This individual responds to incidents, investigates violations, and recommends enhancements to plug potential security gaps. Level 3 is competent in subject matter and concepts and generally considered a specialist in area of assignment. May lead individuals assisting in the work.
Minimum Education: Bachelor’s Degree
Cyber Security Analyst III Minimum/General Experience: 8 Functional Responsibility: Cyber Security Analyst III is responsible for providing customer support in solving all phases of complex cyber security related technical problems. Reviews and recommends cyber security solutions to customer problems based on an understanding of systems test results. Conducts security control assessments with cyber security stakeholders, collect and review artifacts and compile a body of evidence for compliance with security controls, and document assessment results in a security assessment report and risk assessment report.
Particular attention placed on Guard, Firewall, host and network Intrusion Detection/Protection Systems, Penetration Testing, Cyber Hunt activities, Risk and Vulnerability Assessments.
Minimum Education: Bachelor’s Degree
Cyber Security Engineer III - Minimum/General Experience: 8 Functional Responsibility: Participate in special projects or investigations into specific technology or solution issues and research and piloting of new technologies. Serve as a point of contact for engineering efforts while maintaining compliance with the customer's policies and guidelines. Duties may include: configure and maintain policies; maintain documentation for exceptions to standards; provides timely and adequate response to threats/alerts; assess security events to drive to a resolution; provides timely and sufficient response to security incidents and assessment services;
and, promotes security awareness. Cyber Security Engineer III conducts systems security analysis and implementation, system engineering, electrical design, design assurance, testing, security software engineering, program design, configuration management, integration, and testing of cyber security products and techniques.
Minimum Education: Bachelor’s Degree
Cyber Malware Reverse Engineer II Minimum/General Experience: 4 Functional Responsibility: Assists in investigating potential intrusions and security events to contain and mitigate incidents. Research cyber-attacks, malware, and threat actors to determine potential impact and develop remediation guidance; validate, categorize and investigate escalated cyber security events; profile and trend events in the environment for potential incidents; collect, assess and catalogue threat indicators; perform malware analysis. Works under general supervision and usually reports to a supervisor, though some ingenuity and flexibility is required.
Minimum Education: Bachelor’s Degree
Cyber Countermeasures Expert II Minimum/General Experience: 4 Functional Responsibility: Assist with the management and administration of enterprise security programs. Help design and develop countermeasures using advanced knowledge of cyber threats tools, techniques, and processes.
Operates with a high level of oversight.
Minimum Education: Bachelor’s Degree
Penetration Tester II - Minimum/General Experience: 4 Functional Responsibility: Finds security vulnerabilities in target systems, networks, and applications in order to help enterprises improve their security; identification of flaws to cause business risk, a successful candidate provides crucial insights into the most pressing issues and suggests how to prioritize security resources. Works under general supervision and usually reports to a supervisor, though some ingenuity and flexibility is required.
Minimum Education: Bachelor’s Degree
Cybersecurity Subject Matter Expert -I Responsibility: Under general direction, provides extremely high-level subject matter proficiency for…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .