Enclosure EE CyPrESS Labor Categories.xlsx

XLSX spreadsheet 33 KB Posted

Attached to
Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) Federal contract opportunity
Solicitation number
80TECH21R0007
Issued by
National Aeronautics and Space Administration

About this file

This pre-solicitation notice describes a forthcoming request for proposal for cybersecurity and privacy enterprise solutions and services. NASA's Office of Chief Information Officer seeks to acquire cybersecurity program management support, oversight assistance, standards and architecture engineering, and security services. The anticipated contract would have a 20-month base period and four one-year option periods. Offerors must hold a Top Secret facility clearance by the proposal due date in the second quarter of 2021. The contract type will be cost-plus-award-fee with both cost reimbursement and firm-fixed price contract line items. The place of performance encompasses all NASA centers and facilities. The NAICS code is 541519 with a size standard of $30 million.

View the file

Other files for this federal contract opportunity

Other files attached to Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS), newest first.
File Type Posted
CyPrESS DRFP Questions and Answers.pdf PDF
NASA Industry Day -Registered CyPrESS Attendees.xlsx XLSX spreadsheet
Industry Day - CyPrESS April 19 2021.pdf PDF
Exhibits 20-22.xlsx XLSX spreadsheet
CyPrESS Industry Day Registration.pdf PDF
Draft Request for Proposals 80TECH21R0007 (CyPrESS).pdf PDF
Historical Data - HQ - HITSS_III_RFP_Attach._A_-PWS Page 295.pdf PDF
Historical Data - GSFC GITISS - NNG16VU01C.pdf PDF
Historical Data - MITS II-pws section 3.pdf PDF
Historical Data - GSFC SES II - NNG15CR67C.pdf PDF
Historical Data - SSC PWS.pdf PDF
Historical Data - Estimated Historical Labor.pdf PDF
Historical Data - NICS Contract - Performance Work Statement.pdf PDF
Historical Data - Historical Metrics.pdf PDF
Exhibits 20-22.pdf PDF
Enclosure BB - CyPrESS CPAF PEP Core Plus IDIQ Services.pdf PDF
Exhibits 1A-1C.xlsx XLSX spreadsheet
Attachment H - Small Business Subcontracting Plan Cover Page.pdf PDF
Attachment E - DD Form 254 Contract Security Classification Specification.pdf PDF
Attachment I - Installation Accountable Government Property (IAGP) Cover Page.pdf PDF
Enclosure CC - IT Security Management Plan Template.pdf PDF
Enclosure AA - Quality Assurance Surveillance Plan (QASP).pdf PDF
Exhibits 2-19.xlsx XLSX spreadsheet
Attachment L - IT Security Management Plan Cover Page.pdf PDF
Attachment K - Contract Management Plan Cover Page - Copy.pdf PDF
Attachment G - Safety and Health Plan Cover Page.pdf PDF
Attachment E - Attachment 1 to DD Form 254_20210125 DRAFT.pdf PDF
Attachment D - Financial Management Reporting.pdf PDF
Attachment C - Data Requirements Descriptions.pdf PDF
80TECH21R0007 (CyPrESS) Draft Request For Proposals.pdf PDF
Enclosure CC - Cover Page.pdf PDF
Attachment P - DIRECT LABOR RATES AND INDIRECT RATES AND FEE MATRICES.pdf PDF
Attachment O - Wage Determinations.pdf PDF
Attachment O - Wage Determinations Cover Page.pdf PDF
Attachment N - Phase-in Plan Cover Page.pdf PDF
Attachment E - Attachment 2 to DD Form 254_SBU_20210125 DRAFT.pdf PDF
Attachment I - IAGP.pdf PDF
Enclosure DD - GPM-Specified Non-Mgmt DL Categories - DL Hours and PDs Enclosure.pdf PDF
Exhibit 23 PastPerfQues.pdf PDF
Attachment Q - Fixed Price Rate Matrix.pdf PDF
Attachment J - OCI Avoidance Plan Cover Page.pdf PDF
Attachment F - Personal Identiy Verification (PIV) Card Issuance Procedures.pdf PDF
Attachment E - DD Form 254 Cover Page.pdf PDF
Attachment B - Applicable Documents List.pdf PDF
Attachment A - Performance Work Statement.pdf PDF
Show all 45

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Sheet1

Labor CategoryNICE Framework CodeMinimum Required LOCEducationExperience (Years)CertificationWork Role DescriptionOPM Code (Fed Use)SourceBLS Labor Code
All-Source AnalystAN-ASA-001OPM Tier 2 or higherBachelor's degree2 to 5 or more yearsCSSP AnalystAnalyzes data/information from one or multiple sources to conduct preparation of the environment, respond to requests for information, and submit intelligence collection and production requirements in support of planning and operations.11115-1212
Analyst Specialist 2/Computer Systems Analyst II671OPM Tier 2 or higherBachelor's degree4 yrs.The Computer Systems Analyst II reviews proposals which consist of objectives, scope, and user expectations; gathers facts, analyzes data, and prepares a project synopsis which compares alternatives in terms of cost, time, availability of equipment and personnel, and recommends a course of action; upon approval of synopsis, prepares specifications for development of computer programs. Duties also include the ability to determine and resolve data processing problems and coordinate the work with program, users, etc. This worker orients user personnel on new or changed procedures, may conduct special projects such as data element and code standardization throughout a broad system, working under specific objectives and bringing to the attention of the supervisor any unusual problems or controversies.15-1211
Application Programmer 2OPM Tier 2 or higherBachelor's degree2 to 5 yearsApplications Programmer II evaluates and modifies moderately complex applications programs working from detailed specifications. Codes, tests, debugs, documents, and maintains applications.15-1251
Business AnalystOPM Tier 1Bachelor's degree1 to 5 yearsGather and organize information about the problems to be solved or the procedures to be improved. Analyze financial and other data, including revenue, expenditure, and employment reports. Develop solutions or alternative practices. Recommend new systems, procedures, or organizational changes. Make recommendations to management through presentations or written reports
13-1111
Business Analyst 2OPM Tier 1Bachelor's degree2 to 5 yearsBAs are responsible for creating new models that support business decisions by working closely with financial reporting and IT teams to establish initiatives and strategies to improve importing and to optimize costs. Strong understanding of regulatory and reporting requirements as well as plenty of experience in forecasting, budgeting and financial analysis combined with understanding of key performance indicators13-1111
Business Systems AnalystOPM Tier 1Bachelor's degree1 to 5 yearsReviews, analyzes, and evaluates user needs to create systems solutions that support overall business strategies. Documents system requirements, defines scope and objectives, and creates system specifications that drive system development and implementation. Incumbents function as a liaison between IT and users and have both business and technical expertise. Typically requires a Bachelor's degree or its equivalent. Typically reports to a manager. Gains exposure to some of the complex tasks within the job function. Occasionally directed in several aspects of the work.13-1111
Computer Security System Specialist 2OPM Tier 2 or higherBachelor's degree5 yearsSupports Enterprise Security Management through cyber security, privacy, and information assurance activities. Collects, integrates, interprets, and reports using various tools to demonstrate risk, and advise stakeholders on a course of action. Supports program’s Software Assurance, Vulnerability Management, Security Operations, Prevention and Maintenance support. Performs Event Detection and Incident Response efforts through policy and process development and identification of weaknesses in the program. Supports the government customer’s business activities related risk identification and measurement systems within various technical and usage boundaries. Collaborates with user, infrastructure support teams and other Pivot contractors to define and measure security policy and standards across the larger government customer environment. Works with end users, stakeholders, and support teams to define and establish this secure environment15-1212
Computer Systems Analyst I671OPM Tier 2 or higherAA or AS2 yrs.The Computer Systems Analyst I carries out fact finding and analyses as assigned, (usually of a single activity or a routine problem); applies established procedures where the nature of the system, feasibility, computer equipment and programming language have already been decided; may assist a higher level systems analyst by preparing the detailed specifications required by computer programmers from information developed by the higher level analyst, and may research routine user problems and solve them by modifying the existing system when the solutions follow clear precedents. When cost and deadline estimates are required, results receive closer review.15-1211
Configuration Management Specialist 3632OPM Tier 2 or higherBachelor's degree8 yrs.Senior-level configuration management support. Applies comprehensive knowledge of concepts, processes, practices, and procedures on technical assignments. Provides configuration management planning. Describes provisions for configuration identification, change control, configuration status accounting, and configuration audits. Regulates the change process so that only approved and validated changes are incorporated into product documents and related software.11-3021
Cyber Defense AnalystPR-CDA-001OPM Tier 2 or higherBachelor's degree2 to 5 or more yearsCSSP AnalystProvides entry-level support to the program office in development of budget, schedule and risks. Maintains a detailed knowledge of the required compliance documentation. Maintains and updates electronic files, record and data. Maintains databases current in support of project control and other applicable business activities. Uses data collected from a variety of cyber defense tools (e.g., IDS alerts, firewalls, network traffic logs) to analyze events that occur within their environments for the purposes of mitigating threats.51115-1212
Cyber Defense Forensics AnalystIN-FOR-002OPM Tier 2 or higherBachelor's degree7 or more years in cybersecurity technologyCSSP Incident ResponderAnalyzes digital evidence and investigates computer security incidents to derive useful information in support of system/network vulnerability mitigation.21215-1212
Cyber Defense Incident ResponderPR-CIR-001OPM Tier 2 or higherBachelor's degree2 to 5 or more yearsCSSP Incident Responder• Collect intrusion artifacts (e.g., source code, malware, trojans) and use discovered data to enable mitigation of potential cyber defense incidents within the enterprise.

• Coordinate and provide expert technical support to enterprise-wide cyber defense technicians to resolve cyber defense incidents.

• Coordinate incident response functions.

• Monitor external data sources (e.g., cyber defense vendor sites, Computer Emergency Response Teams, Security Focus) to maintain currency of cyber defense threat conditions and determine which security issues may have an impact on the enterprise.

• Perform cyber defense trend analysis and reporting.

• Perform initial, forensically sound collection of images and inspect to discern possible mitigation/remediation on enterprise systems.

• Receive and analyze network alerts from various sources within the enterprise and determine possible causes of such alerts.

• Write and publish after-action reviews.

• Write and publish cyber defense techniques, guidance, and reports on incident findings to appropriate constituencies.53115-1212
Cyber Defense Infrastructure Support SpecialistPR-INF-001OPM Tier 2 or higherBachelor's degree2 to 5 or more yearsCSSP Infrastructure SupportTests, implements, deploys, maintains, and administers the infrastructure hardware and software.52115-1212
Cyber Policy and Strategy PlannerOV-SPP-002OPM Tier 2 or higherBachelor's degree7 or more years in cybersecurity technologyIAM Level I• Develop policy, programs, and guidelines for implementation.

• Establish and maintain communication channels with stakeholders.

• Review existing and proposed policies with stakeholders.

• Serve on agency and interagency policy boards.

• Promote awareness of cyber policy and strategy as appropriate among management and ensure sound principles are reflected in the organization's mission, vision, and goals.

• Interpret and apply applicable laws, statutes, and regulatory documents and integrate into policy.

• Analyze organizational cyber policy.

• Assess policy needs and collaborate with stakeholders to develop policies to govern cyber activities.

• Define and integrate current and future mission environments

• Design/integrate a cyber strategy that outlines the vision, mission, and goals that align with the organization’s strategic plan.

• Draft, staff, and publish cyber policy.

• Monitor the rigorous application of cyber policies, principles, and practices in the delivery of planning and management services

• Seek consensus on proposed policy changes from stakeholders.

• Provide policy guidance to cyber management, staff, and users.

• Review, conduct, or participate in audits of cyber programs and projects.

• Support the CIO in the formulation of cyber-related policies.752https://www.cisa.gov/cyber-policy-and-strategy-planner15-1212
Cyber Systems Security EngineerOPM Tier 2 or higherBachelor's degree1 to 2 years• Apply security policies to meet security objectives of the system.

• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.

• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.

• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.

• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.

• Properly document all systems security implementation, operations and maintenance activities and update as necessary.

• Verify and update security documentation reflecting the application/system security design features.

• Verify minimum security requirements are in place for all applications.https://www.cisa.gov/systems-security-analyst15-1212
Cyber Systems Security Engineer 2OPM Tier 2 or higherBachelor's degree2 to 5 years• Analyze and report organizational security posture trends.

• Analyze and report system security posture trends.

• Apply security policies to meet security objectives of the system.

• Assess adequate access controls based on principles of least privilege and need-to-know.

• Assess all the configuration management (change configuration/release management) processes

• Assess the effectiveness of security controls

• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.

• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.

• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.

• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.

• Plan and recommend modifications or adjustments based on exercise results or system environment.

• Properly document all systems security implementation, operations and maintenance activities and update as necessary.

• Verify and update security documentation reflecting the application/system security design features.

• Verify minimum security requirements are in place for all applications.https://www.cisa.gov/systems-security-analyst15-1212
Cyber Systems Security Engineer 3OPM Tier 2 or higherBachelor's degree5+ years• Analyze and report organizational security posture trends.

• Analyze and report system security posture trends.

• Apply security policies to meet security objectives of the system.

• Assess adequate access controls based on principles of least privilege and need-to-know.

• Assess all the configuration management (change configuration/release management) processes

• Assess the effectiveness of security controls

• Develop procedures and test fail-over for system operations transfer to an alternate site based on system availability requirements.

• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.

• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.

• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.

• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.

• Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative.

• Plan and recommend modifications or adjustments based on exercise results or system environment.

• Properly document all systems security implementation, operations and maintenance activities and update as necessary.

• Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities.

• Verify and update security documentation reflecting the application/system security design features.

• Verify minimum security requirements are in place for all applications.https://www.cisa.gov/systems-security-analyst15-1212
Cyber Workforce Developer and ManagerBachelor's degree5 to 7 yearsThis role develops cyberspace workforce plans, strategies, and guidance to support cyberspace workforce manpower, personnel, training and education requirements and to address changes to cyberspace policy, doctrine, materiel, force structure, and education and training requirements.13-1151
Cybersecurity AnalystOPM Tier 2 or higherBachelor's degree2 to 5 years• Analyze and report organizational security posture trends.

• Analyze and report system security posture trends.

• Apply security policies to meet security objectives of the system.

• Assess adequate access controls based on principles of least privilege and need-to-know.

• Assess all the configuration management (change configuration/release management) processes

• Assess the effectiveness of security controls

• Develop procedures and test fail-over for system operations transfer to an alternate site based on system availability requirements.

• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.

• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.

• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.

• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.

• Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative.

• Plan and recommend modifications or adjustments based on exercise results or system environment.

• Properly document all systems security implementation, operations and maintenance activities and update as necessary.

• Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities.

• Verify and update security documentation reflecting the application/system security design features.

• Verify minimum security requirements are in place for all applications.https://www.cisa.gov/systems-security-analyst15-1212
Cybersecurity Lead521OPM Tier 2 or higherBachelor's degree10 yrs.Duties may include a combination of supporting activities in coordination with Government to include continuous security monitoring, vulnerability assessment support, Security Test and Evaluation (ST&E) support and Certification/Accreditation support for the on-going assessment, planning, integration, and recommending enhancement of systems. In addition, duties may include supporting the design, integration and operation of Cybersecurity systems for the protection of networks, systems, and infrastructure. Duties may include: operate, monitor, maintain, and optimize existing monitoring, intrusion detection, and vulnerability identification on systems. Support the program and provide continuous monitoring of systems. Support technical and forensic investigations and provide support to incident response process. Prepare architectural diagrams, technical reports, and/or white papers in support of evolving Architecture requirements. Appropriate industry IT Security certification required.15-1212
Cybersecurity Specialist 10OPM Tier 2 or higherBachelor's degree2 to 5 yearsEntry-level Cybersecurity support. Applies fundamental concepts, processes, practices and procedures on technical assignments. Supports enterprise Cybersecurity standards. Supports the development and implementation of Cybersecurity standards and procedures. Coordinates development and recommends security processes for the organization. Recommends Cybersecurity solutions to support customers’ requirements. Identifies and reports security violations. Recommends and satisfies Cybersecurity requirements based upon the analysis of CSPP, policy, regulatory, and resource demands. Supports customers at the highest levels in the development and implementation of processes and policies. Applies know-how to government and commercial common user systems, as well as to dedicated special purpose systems requiring specialized security features and procedures. Supports analysis, design, and development of security features for system architectures. Analyzes and recommends security requirements for computer systems which may include mainframes, workstations, and personal computers. Supports designing, development, engineering, and implementation of solutions that meet security requirements. Provides integration and implementation of the computer system security solution. Analyzes general cybersecurity-related technical problems and provides basic engineering and technical support in solving these problems. Supports vulnerability/risk analyses and makes recommendations of computer systems and applications during all phases of the system development life cycle. Performs all procedures necessary to ensure the safety of information systems data assets and to protect systems from intentional or inadvertent access or destruction. Ensures that all information systems are functional and secure.15-1212
Cybersecurity Specialist 2521OPM Tier 2 or higherBachelor's degree4 yrs.Mid-level Cybersecurity support. Applies advanced knowledge of concepts, processes, practices, and procedures on technical assignments. Supports enterprise Cybersecurity standards. Supports the development and implementation of Cybersecurity standards and procedures. Coordinates, development, and makes recommendations of security programs for an organization. Coordinates, development, and makes recommendations of security programs for an organization. Recommends Cybersecurity solutions to support customers’ requirements. Identifies and reports security violations. Recommends and satisfies Cybersecurity requirements based upon the analysis of CSPP, policy, regulatory, and resource demands. Supports customers at the highest levels in the development and implementation of processes and policies. Applies know-how to government and commercial common user systems, as well as to dedicated special purpose systems requiring specialized security features and procedures. Supports analysis, design, and development of security features for system architectures. Analyzes and recommends security requirements for computer systems which may include mainframes, workstations, and personal computers. Support designing, development, engineering, and implementation of solutions that meet security requirements. Supports integration and implementation of the computer system security solution. Analyzes general Cybersecurity-related technical problems and provides basic engineering and technical support in solving these problems. Supports vulnerability/risk analyses and makes recommendations of computer systems and applications during all phases of the system development life cycle. Performs all procedures necessary to ensure the safety of information systems data assets and to protect systems from intentional or inadvertent access or destruction. Ensures that all information systems are functional and secure.15-1212
Cybersecurity Specialist 3521OPM Tier 2 or higherBachelor's degree8 yrs.Senior-level Cybersecurity support. Applies comprehensive knowledge of concepts, processes, practices, and procedures on technical assignments. Supports enterprise Cybersecurity standards. In coordination with Government develops and implements Cybersecurity standards and procedures. Coordinates, development, and recommends security processes for an organization. Recommends Cybersecurity solutions to support customers’ requirements. Identifies and reports security violations. Recommends and satisfies Cybersecurity requirements based upon the analysis of CSPP, policy, regulatory, and resource demands. Supports customers at the highest levels in the development and implementation of processes and policies. Applies know-how to government and commercial common user systems, as well as to dedicated special purpose systems requiring specialized security features and procedures. Supports analysis, design, and development of security features for system architectures. Analyzes security requirements for computer systems which may include mainframes, workstations, and personal computers. Designs, develops, engineers, and implements solutions that meet CSPP requirements. Provides integration and implementation of the computer system security solution. Analyzes general Cybersecurity-related technical problems and provides basic engineering and technical support in solving these problems. Supports vulnerability/risk analyses and makes recommendations on computer systems and applications during all phases of the system development life cycle. Performs all procedures necessary to ensure the safety of information systems data assets and to protect systems from intentional or inadvertent access or destruction. Ensures that all information systems are functional and secure.15-1212
Data Reporting AnalystOPM Tier 2 or higherBachelor's degree2 to 5 years•Analyze and define data requirements and specifications.

•Analyze data sources to provide actionable recommendations.

•Assess the validity of source data and subsequent findings.

•Collect metrics and trending data.

•Develop data standards, policies, and procedures.

•Provide actionable recommendations to critical stakeholders based on data analysis and findings.https://www.cisa.gov/data-analyst15-2031
Database AdministratorOM-DTA-001OPM Tier 2 or higherBachelor's degree2 to 5 or more yearsIAT Level IAdministers databases and/or data management systems that allow for the secure storage, query, protection, and utilization of data.42115-1245
Desktop Support AnalystAssociates to Bachelor's degree1 to 5 Years• Pay attention to customers’ descriptions of their computer problems

• Ask customers questions to properly diagnose the problem

• Walk customers through the recommended problem-solving steps

• Set up or repair computer equipment and related devices

• Train users to work with new computer hardware or software, such as printers, word-processing software, and email

• Provide other team members and managers in the organization with information about what gives customers the most trouble and about other concerns customers have

https://www.bls.gov/ooh/computer-and-information-technology/computer-support-specialists.htm15-1232
Functional AnalystOPM Tier 2 or higherBachelor's degree2 to 5 years• Conduct risk analysis, feasibility study, and/or trade-off analysis to develop, document, and refine functional requirements and specifications.

• Consult with customers to evaluate functional requirements.

• Translate functional requirements into technical solutions.

https://www.cisa.gov/systems-requirements-planner13-1111
Functional Expert Consultant Level IIOPM Tier 2 or higherBachelor's degree5 to 7 years• Conduct risk analysis, feasibility study, and/or trade-off analysis to develop, document, and refine functional requirements and specifications.

• Consult with customers to evaluate functional requirements.

• Define project scope and objectives based on customer requirements

• Translate functional requirements into technical solutions.

• Develop and document User Experience (UX) requirements including information architecture and user interface requirements.

https://www.cisa.gov/systems-requirements-planner13-1111
Incident ResponseOPM Tier 2 or higherBachelor's degree1 to 5 yearsmaintains system cybersecurity monitoring operations. Analyzes, reports, and responds to detected cyber incidents15-1212
Information Assurance/Security Specialist 2OPM Tier 2 or higherBachelor's degree2 yrs.• Analyze and report organizational security posture trends.

• Analyze and report system security posture trends.

• Apply security policies to meet security objectives of the system.

• Assess adequate access controls based on principles of least privilege and need-to-know.

• Assess all the configuration management (change configuration/release management) processes

• Assess the effectiveness of security controls

• Develop procedures and test fail-over for system operations transfer to an alternate site based on system availability requirements.

• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.

• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.

• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.

• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.

• Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative.

• Plan and recommend modifications or adjustments based on exercise results or system environment.

• Properly document all systems security implementation, operations and maintenance activities and update as necessary.

• Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities.

• Verify and update security documentation reflecting the application/system security design features.

• Verify minimum security requirements are in place for all applications.https://www.cisa.gov/systems-security-analyst15-1212
Information Assurance/Security Specialist 3OPM Tier 2 or higherBachelor's degree3 yrs.• Analyze and report organizational security posture trends.

• Analyze and report system security posture trends.

• Apply security policies to meet security objectives of the system.

• Assess adequate access controls based on principles of least privilege and need-to-know.

• Assess all the configuration management (change configuration/release management) processes

• Assess the effectiveness of security controls

• Develop procedures and test fail-over for system operations transfer to an alternate site based on system availability requirements.

• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.

• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.

• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.

• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.

• Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative.

• Plan and recommend modifications or adjustments based on exercise results or system environment.

• Properly document all systems security implementation, operations and maintenance activities and update as necessary.

• Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities.

• Verify and update security documentation reflecting the application/system security design features.

• Verify minimum security requirements are in place for all applications.https://www.cisa.gov/systems-security-analyst15-1212
Information Assurance/Security Specialist 4OPM Tier 2 or higherBachelor's degree5 yrs.• Analyze and report organizational security posture trends.

• Analyze and report system security posture trends.

• Apply security policies to meet security objectives of the system.

• Assess adequate access controls based on principles of least privilege and need-to-know.

• Assess all the configuration management (change configuration/release management) processes

• Assess the effectiveness of security controls

• Develop procedures and test fail-over for system operations transfer to an alternate site based on system availability requirements.

• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.

• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.

• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.

• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.

• Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative.

• Plan and recommend modifications or adjustments based on exercise results or system environment.

• Properly document all systems security implementation, operations and maintenance activities and update as necessary.

• Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities.

• Verify and update security documentation reflecting the application/system security design features.

• Verify minimum security requirements are in place for all applications.https://www.cisa.gov/systems-security-analyst15-1212
Information Assurance/Security Specialist SeniorOPM Tier 2 or higherBachelor's degree7 yrs.• Analyze and report organizational security posture trends.

• Analyze and report system security posture trends.

• Apply security policies to meet security objectives of the system.

• Assess adequate access controls based on principles of least privilege and need-to-know.

• Assess all the configuration management (change configuration/release management) processes

• Assess the effectiveness of security controls

• Develop procedures and test fail-over for system operations transfer to an alternate site based on system availability requirements.

• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.

• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.

• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.

• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.

• Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative.

• Plan and recommend modifications or adjustments based on exercise results or system environment.

• Properly document all systems security implementation, operations and maintenance activities and update as necessary.

• Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities.

• Verify and update security documentation reflecting the application/system security design features.

• Verify minimum security requirements are in place for all applications.https://www.cisa.gov/systems-security-analyst15-1212
Information EngineerOPM Tier 2 or higherBachelor's degree2 to 5 years• Monitor their organization’s networks for security breaches and investigate a violation when one occurs

• Prepare reports that document security breaches and the extent of the damage caused by the breaches

• Conduct penetration testing, which is when analysts simulate attacks to look for vulnerabilities in their systems before they can be exploited

• Help computer users when they need to install or learn about new security products and procedures

https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm15-1212
Information Engineer 2OPM Tier 2 or higherBachelor's degree5 to 7 years• Monitor their organization’s networks for security breaches and investigate a violation when one occurs

• Install and use software, such as firewalls and data encryption programs, to protect sensitive information

• Prepare reports that document security breaches and the extent of the damage caused by the breaches

• Conduct penetration testing, which is when analysts simulate attacks to look for vulnerabilities in their systems before they can be exploited

• Research the latest information technology (IT) security trends

• Develop security standards and best practices for their organization

• Recommend security enhancements to management or senior IT staff

• Help computer users when they need to install or learn about new security products and procedureshttps://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm15-1212
Information Security AnalystsOPM Tier 2 or higherBachelor's degree2 to 7 yearsMonitor their organization’s networks for security breaches and investigate a violation when one occurs. Install and use software, such as firewalls and data encryption programs, to protect sensitive information. Prepare reports that document security breaches and the extent of the damage caused by the breaches. Conduct penetration testing, which is when analysts simulate attacks to look for vulnerabilities in their systems before they can be exploited. Research the latest information technology (IT) security trends. Develop security standards and best practices for their organization. Recommend security enhancements to management or senior IT staff15-1212
Information System Training SpecialistBachelor's degree2 to 5 years• Assess training needs through surveys, interviews with employees, or consultations with managers or instructors

• Design and create training manuals, online learning modules, and course materials

• Review training materials from a variety of sources and choose appropriate materials

• Deliver training to employees using a variety of instructional techniques

• Assist in the evaluation of training programs

• Perform administrative tasks such as monitoring costs, scheduling classes, setting up systems and equipment, and coordinating enrollmenthttps://www.bls.gov/ooh/business-and-financial/training-and-development-specialists.htm#:~:text=Training%20and%20development%20specialists%20help%20create%2C%20administer%2C%20and%20deliver%20training,in%20classrooms%20or%20training%20facilities.13-1151
Information Technologist 3OPM Tier 2 or higherBachelor's degree5 Yrs.•Provide technical support to a business or an organization's employees

•Train non-technical workers on the business's information systems •Design systems and assess the effectiveness of technology resources

•Determine the practicality of changes and modification of systems.15-1212
IT Data AnalystOPM Tier 2 or higherBachelor's degree2 to 5 years•Analyze and define data requirements and specifications.

•Analyze data sources to provide actionable recommendations.

•Assess the validity of source data and subsequent findings.

•Collect metrics and trending data.

•Develop data standards, policies, and procedures.

•Provide actionable recommendations to critical stakeholders based on data analysis and findings.https://www.cisa.gov/data-analyst15-2031
IT Investment/Portfolio ManagerOV-PMA-004Bachelor's degree5 to 7 yearsN/AManages a portfolio of IT investments that align with the overall needs of mission and enterprise priorities.80411-3021
IT AuditorOV-PMA-005Bachelor's degree7 or more years in cybersecurity technologyCSSP AuditorConducts evaluations of an IT program or its individual components to determine compliance with published standards.80515-1212
IT Security Engineer IOPM Tier 2 or higherBachelor's degree2 to 5 yearsEntry-Level, Possess basic technical knowledge of Cybersecurity principles. Under general supervision and in coordination with Government, supports integration of new and existing information systems to ensure that appropriate controls exist, that processing is efficient and accurate, and that systems procedures are in compliance with standards, guidelines, and regulations.15-1212
IT Security Engineer IIOPM Tier 2 or higherBachelor's degree6 yrs.Mid-Level, Possess working technical knowledge of IT Security\Cybersecurity principles. Under general supervision and in coordination with Government, develops Cybersecurity processes and control guidelines, assists in resolving technical problems, priorities, and methods. Possesses experience with vulnerability assessment and intrusion detection tools. Supports the design and deployment of security solutions with complex network architecture.15-1212
IT Security Engineer III652OPM Tier 2 or higherBachelor's degree8 yrs.Senior-Level, Possess in-depth technical knowledge of Cybersecurity principles. Under general direction of and in coordination with CSPP, responsible for all activities relating to Cybersecurity procedures and systems. In coordination with Government develops Cybersecurity programs and control guidelines. Confers with and advises subordinates on administrative policies and procedures and resolving technical problems, priorities, and methods. Consults with and advises other areas regarding internal controls and security procedures. Prepares activity and progress reports relating to the information systems audit function. Supports vulnerability assessment and design of intrusion detection tools for complex network architecture.15-1212
IT Security LeadOPM Tier 2 or higherBachelor's degree7 years• Develop data protection strategies, architectures, and implementation plans.

• Develop, document, and maintain security policies, processes, procedures, standards, and best practices.

• Ensure the protection of assets by the enforcement of security policies.

• Monitor information security events/alerts respond to, triage, and escalate as needed.

• Analyze event/alert patterns to properly interpret and prioritize threats.

• Identify trends and drive requirements aimed at fine-tuning existing policies.

• Provide technical advice and input for the support of integrated security systems and solutions.

• Maintain up-to-date information protection industry awareness and trends and be able to understand how emerging threats may potentially impact the organization.

• Create, modify, and review various reports and dashboards from our various reporting tools.

• Maintain policies and associated events.

• Make recommendations to strengthen the security posture of a computing environment as well as recommend process and technology improvements.

• Assist with incident investigations.

• Improve and challenge existing processes and procedures.

• Provide high quality, professional day-to-day execution.

https://www.cisa.gov/systems-security-analyst15-1212
IT Security Specialist 2OPM Tier 2 or higherBachelor's degree3 Yrs.• Analyze and report organizational security posture trends.

• Analyze and report system security posture trends.

• Apply security policies to meet security objectives of the system.

• Assess adequate access controls based on principles of least privilege and need-to-know.

• Assess all the configuration management (change configuration/release management) processes

• Assess the effectiveness of security controls

• Develop procedures and test fail-over for system operations transfer to an alternate site based on system availability requirements.

• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.

• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.

• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.

• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.

• Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative.

• Plan and recommend modifications or adjustments based on exercise results or system environment.

• Properly document all systems security implementation, operations and maintenance activities and update as necessary.

• Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities.

• Verify and update security documentation reflecting the application/system security design features.

• Verify minimum security requirements are in place for all applications.https://www.cisa.gov/systems-security-analyst15-1212
IT Security Specialist 3OPM Tier 2 or higherBachelor's degree5 years• Analyze and report organizational security posture trends.

• Analyze and report system security posture trends.

• Apply security policies to meet security objectives of the system.

• Assess adequate access controls based on principles of least privilege and need-to-know.

• Assess all the configuration management (change configuration/release management) processes

• Assess the effectiveness of security controls

• Develop procedures and test fail-over for system operations transfer to an alternate site based on system availability requirements.

• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.

• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.

• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.

• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.

• Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative.

• Plan and recommend modifications or adjustments based on exercise results or system environment.

• Properly document all systems security implementation, operations and maintenance activities and update as necessary.

• Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities.

• Verify and update security documentation reflecting the application/system security design features.

• Verify minimum security requirements are in place for all applications.https://www.cisa.gov/systems-security-analyst15-1212
Lead EngineerBachelor's degree7 Yrs.• Analyze and report organizational security posture trends.

• Analyze and report system security posture trends.

• Apply security policies to meet security objectives of the system.

• Assess adequate access controls based on principles of least privilege and need-to-know.

• Assess all the configuration management (change configuration/release management) processes

• Assess the effectiveness of security controls

• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.

• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.

• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.

• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.

• Plan and recommend modifications or adjustments based on exercise results or system environment.

• Properly document all systems security implementation, operations and maintenance activities and update as necessary.

• Verify and update security documentation reflecting the application/system security design features.

• Verify minimum security requirements are in place for all applications.https://www.cisa.gov/systems-security-analyst15-1212
Network Engineer I652OPM Tier 2 or higherBachelor's degree3 yrs.Mid-Level, With guidance from more senior engineers and in coordination with Government, perform a variety of network engineering tasks, which are broad in nature and are related to the design and implementation of integrated networks, including labor, hardware, software and support facilities and/or equipment. Plan and perform network engineering research, design development, and other assignments in conformance with network design, engineering and customer specifications. Coordinate the activities of Network Technicians assigned to specific network engineering projects. Perform with some latitude for independent actions and decisions.15-1244
Network Systems Security EngineerOPM Tier 2 or higherBachelor's degree2 to 5 years• Configure and optimize network hubs, routers, and switches (e.g., higher-level protocols, tunneling).

• Develop and implement network backup and recovery procedures.

• Diagnose network connectivity problems

• Install and maintain network infrastructure device operating system software (e.g., IOS, firmware).

• Install or replace network hubs, routers, and switches.

• Monitor network capacity and performance.

• Patch network vulnerabilities to ensure information is safeguarded against outside parties

• Test and maintain network infrastructure including software and hardware devices.

https://www.cisa.gov/network-operations-specialist15-1244
Product Support SpecialistOPM Tier 2 or higherBachelor's degree2 to 5 years•Confer with customers to identify problems, replicate them, and troubleshoot for root cause.

•Evaluate failures, bugs, systemic problems, and hardware and report on necessary steps.

•Consider site-specific information like hardware, operating system, and user requirements to appropriately resolve problems.

•Install applications, hardware, parts, and/or equipment.13-1198
Program Admin Specialist 2OPM Tier 2 or higherBachelor's degree2 to 5 years• Conduct risk analysis, feasibility study, and/or trade-off analysis to develop, document, and refine functional requirements and specifications.

• Consult with customers to evaluate functional requirements.

• Define project scope and objectives based on customer requirements.

• Translate functional requirements into technical solutions.

• Develop and document User Experience (UX) requirements including information architecture and user interface requirements.

https://www.cisa.gov/systems-requirements-planner13-1198
Project Control SpecialistBachelor's degree2 to 5 years•Lead project scheduling and baselines, and communicate changes and track progress.

•Coordinate schedule with internal and contractor teams, and control for timely completion.

•Direct teams in data collection, management, and tasks to improve processes.

•Track and analyze financial data and budgets, and produce reports regularly.13-1198

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .