Enclosure EE CyPrESS Labor Categories.xlsx
XLSX spreadsheet 33 KB Posted
- Attached to
- Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) Federal contract opportunity
- Solicitation number
- 80TECH21R0007
About this file
This pre-solicitation notice describes a forthcoming request for proposal for cybersecurity and privacy enterprise solutions and services. NASA's Office of Chief Information Officer seeks to acquire cybersecurity program management support, oversight assistance, standards and architecture engineering, and security services. The anticipated contract would have a 20-month base period and four one-year option periods. Offerors must hold a Top Secret facility clearance by the proposal due date in the second quarter of 2021. The contract type will be cost-plus-award-fee with both cost reimbursement and firm-fixed price contract line items. The place of performance encompasses all NASA centers and facilities. The NAICS code is 541519 with a size standard of $30 million.
View the file
Other files for this federal contract opportunity
Show all 45
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Sheet1
| Labor Category | NICE Framework Code | Minimum Required LOC | Education | Experience (Years) | Certification | Work Role Description | OPM Code (Fed Use) | Source | BLS Labor Code |
| All-Source Analyst | AN-ASA-001 | OPM Tier 2 or higher | Bachelor's degree | 2 to 5 or more years | CSSP Analyst | Analyzes data/information from one or multiple sources to conduct preparation of the environment, respond to requests for information, and submit intelligence collection and production requirements in support of planning and operations. | 111 | 15-1212 | |
| Analyst Specialist 2/Computer Systems Analyst II | 671 | OPM Tier 2 or higher | Bachelor's degree | 4 yrs. | The Computer Systems Analyst II reviews proposals which consist of objectives, scope, and user expectations; gathers facts, analyzes data, and prepares a project synopsis which compares alternatives in terms of cost, time, availability of equipment and personnel, and recommends a course of action; upon approval of synopsis, prepares specifications for development of computer programs. Duties also include the ability to determine and resolve data processing problems and coordinate the work with program, users, etc. This worker orients user personnel on new or changed procedures, may conduct special projects such as data element and code standardization throughout a broad system, working under specific objectives and bringing to the attention of the supervisor any unusual problems or controversies. | 15-1211 | |||
| Application Programmer 2 | OPM Tier 2 or higher | Bachelor's degree | 2 to 5 years | Applications Programmer II evaluates and modifies moderately complex applications programs working from detailed specifications. Codes, tests, debugs, documents, and maintains applications. | 15-1251 | ||||
| Business Analyst | OPM Tier 1 | Bachelor's degree | 1 to 5 years | Gather and organize information about the problems to be solved or the procedures to be improved. Analyze financial and other data, including revenue, expenditure, and employment reports. Develop solutions or alternative practices. Recommend new systems, procedures, or organizational changes. Make recommendations to management through presentations or written reports | |||||
| 13-1111 | |||||||||
| Business Analyst 2 | OPM Tier 1 | Bachelor's degree | 2 to 5 years | BAs are responsible for creating new models that support business decisions by working closely with financial reporting and IT teams to establish initiatives and strategies to improve importing and to optimize costs. Strong understanding of regulatory and reporting requirements as well as plenty of experience in forecasting, budgeting and financial analysis combined with understanding of key performance indicators | 13-1111 | ||||
| Business Systems Analyst | OPM Tier 1 | Bachelor's degree | 1 to 5 years | Reviews, analyzes, and evaluates user needs to create systems solutions that support overall business strategies. Documents system requirements, defines scope and objectives, and creates system specifications that drive system development and implementation. Incumbents function as a liaison between IT and users and have both business and technical expertise. Typically requires a Bachelor's degree or its equivalent. Typically reports to a manager. Gains exposure to some of the complex tasks within the job function. Occasionally directed in several aspects of the work. | 13-1111 | ||||
| Computer Security System Specialist 2 | OPM Tier 2 or higher | Bachelor's degree | 5 years | Supports Enterprise Security Management through cyber security, privacy, and information assurance activities. Collects, integrates, interprets, and reports using various tools to demonstrate risk, and advise stakeholders on a course of action. Supports program’s Software Assurance, Vulnerability Management, Security Operations, Prevention and Maintenance support. Performs Event Detection and Incident Response efforts through policy and process development and identification of weaknesses in the program. Supports the government customer’s business activities related risk identification and measurement systems within various technical and usage boundaries. Collaborates with user, infrastructure support teams and other Pivot contractors to define and measure security policy and standards across the larger government customer environment. Works with end users, stakeholders, and support teams to define and establish this secure environment | 15-1212 | ||||
| Computer Systems Analyst I | 671 | OPM Tier 2 or higher | AA or AS | 2 yrs. | The Computer Systems Analyst I carries out fact finding and analyses as assigned, (usually of a single activity or a routine problem); applies established procedures where the nature of the system, feasibility, computer equipment and programming language have already been decided; may assist a higher level systems analyst by preparing the detailed specifications required by computer programmers from information developed by the higher level analyst, and may research routine user problems and solve them by modifying the existing system when the solutions follow clear precedents. When cost and deadline estimates are required, results receive closer review. | 15-1211 | |||
| Configuration Management Specialist 3 | 632 | OPM Tier 2 or higher | Bachelor's degree | 8 yrs. | Senior-level configuration management support. Applies comprehensive knowledge of concepts, processes, practices, and procedures on technical assignments. Provides configuration management planning. Describes provisions for configuration identification, change control, configuration status accounting, and configuration audits. Regulates the change process so that only approved and validated changes are incorporated into product documents and related software. | 11-3021 | |||
| Cyber Defense Analyst | PR-CDA-001 | OPM Tier 2 or higher | Bachelor's degree | 2 to 5 or more years | CSSP Analyst | Provides entry-level support to the program office in development of budget, schedule and risks. Maintains a detailed knowledge of the required compliance documentation. Maintains and updates electronic files, record and data. Maintains databases current in support of project control and other applicable business activities. Uses data collected from a variety of cyber defense tools (e.g., IDS alerts, firewalls, network traffic logs) to analyze events that occur within their environments for the purposes of mitigating threats. | 511 | 15-1212 | |
| Cyber Defense Forensics Analyst | IN-FOR-002 | OPM Tier 2 or higher | Bachelor's degree | 7 or more years in cybersecurity technology | CSSP Incident Responder | Analyzes digital evidence and investigates computer security incidents to derive useful information in support of system/network vulnerability mitigation. | 212 | 15-1212 | |
| Cyber Defense Incident Responder | PR-CIR-001 | OPM Tier 2 or higher | Bachelor's degree | 2 to 5 or more years | CSSP Incident Responder | • Collect intrusion artifacts (e.g., source code, malware, trojans) and use discovered data to enable mitigation of potential cyber defense incidents within the enterprise. |
• Coordinate and provide expert technical support to enterprise-wide cyber defense technicians to resolve cyber defense incidents.
• Coordinate incident response functions.
• Monitor external data sources (e.g., cyber defense vendor sites, Computer Emergency Response Teams, Security Focus) to maintain currency of cyber defense threat conditions and determine which security issues may have an impact on the enterprise.
• Perform cyber defense trend analysis and reporting.
• Perform initial, forensically sound collection of images and inspect to discern possible mitigation/remediation on enterprise systems.
• Receive and analyze network alerts from various sources within the enterprise and determine possible causes of such alerts.
• Write and publish after-action reviews.
| • Write and publish cyber defense techniques, guidance, and reports on incident findings to appropriate constituencies. | 531 | 15-1212 | |||||||
| Cyber Defense Infrastructure Support Specialist | PR-INF-001 | OPM Tier 2 or higher | Bachelor's degree | 2 to 5 or more years | CSSP Infrastructure Support | Tests, implements, deploys, maintains, and administers the infrastructure hardware and software. | 521 | 15-1212 | |
| Cyber Policy and Strategy Planner | OV-SPP-002 | OPM Tier 2 or higher | Bachelor's degree | 7 or more years in cybersecurity technology | IAM Level I | • Develop policy, programs, and guidelines for implementation. |
• Establish and maintain communication channels with stakeholders.
• Review existing and proposed policies with stakeholders.
• Serve on agency and interagency policy boards.
• Promote awareness of cyber policy and strategy as appropriate among management and ensure sound principles are reflected in the organization's mission, vision, and goals.
• Interpret and apply applicable laws, statutes, and regulatory documents and integrate into policy.
• Analyze organizational cyber policy.
• Assess policy needs and collaborate with stakeholders to develop policies to govern cyber activities.
• Define and integrate current and future mission environments
• Design/integrate a cyber strategy that outlines the vision, mission, and goals that align with the organization’s strategic plan.
• Draft, staff, and publish cyber policy.
• Monitor the rigorous application of cyber policies, principles, and practices in the delivery of planning and management services
• Seek consensus on proposed policy changes from stakeholders.
• Provide policy guidance to cyber management, staff, and users.
• Review, conduct, or participate in audits of cyber programs and projects.
| • Support the CIO in the formulation of cyber-related policies. | 752 | https://www.cisa.gov/cyber-policy-and-strategy-planner | 15-1212 | |||
| Cyber Systems Security Engineer | OPM Tier 2 or higher | Bachelor's degree | 1 to 2 years | • Apply security policies to meet security objectives of the system. |
• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.
• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.
• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.
• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.
• Properly document all systems security implementation, operations and maintenance activities and update as necessary.
• Verify and update security documentation reflecting the application/system security design features.
| • Verify minimum security requirements are in place for all applications. | https://www.cisa.gov/systems-security-analyst | 15-1212 | ||||
| Cyber Systems Security Engineer 2 | OPM Tier 2 or higher | Bachelor's degree | 2 to 5 years | • Analyze and report organizational security posture trends. |
• Analyze and report system security posture trends.
• Apply security policies to meet security objectives of the system.
• Assess adequate access controls based on principles of least privilege and need-to-know.
• Assess all the configuration management (change configuration/release management) processes
• Assess the effectiveness of security controls
• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.
• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.
• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.
• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.
• Plan and recommend modifications or adjustments based on exercise results or system environment.
• Properly document all systems security implementation, operations and maintenance activities and update as necessary.
• Verify and update security documentation reflecting the application/system security design features.
| • Verify minimum security requirements are in place for all applications. | https://www.cisa.gov/systems-security-analyst | 15-1212 | ||||
| Cyber Systems Security Engineer 3 | OPM Tier 2 or higher | Bachelor's degree | 5+ years | • Analyze and report organizational security posture trends. |
• Analyze and report system security posture trends.
• Apply security policies to meet security objectives of the system.
• Assess adequate access controls based on principles of least privilege and need-to-know.
• Assess all the configuration management (change configuration/release management) processes
• Assess the effectiveness of security controls
• Develop procedures and test fail-over for system operations transfer to an alternate site based on system availability requirements.
• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.
• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.
• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.
• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.
• Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative.
• Plan and recommend modifications or adjustments based on exercise results or system environment.
• Properly document all systems security implementation, operations and maintenance activities and update as necessary.
• Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities.
• Verify and update security documentation reflecting the application/system security design features.
| • Verify minimum security requirements are in place for all applications. | https://www.cisa.gov/systems-security-analyst | 15-1212 | |||||
| Cyber Workforce Developer and Manager | Bachelor's degree | 5 to 7 years | This role develops cyberspace workforce plans, strategies, and guidance to support cyberspace workforce manpower, personnel, training and education requirements and to address changes to cyberspace policy, doctrine, materiel, force structure, and education and training requirements. | 13-1151 | |||
| Cybersecurity Analyst | OPM Tier 2 or higher | Bachelor's degree | 2 to 5 years | • Analyze and report organizational security posture trends. |
• Analyze and report system security posture trends.
• Apply security policies to meet security objectives of the system.
• Assess adequate access controls based on principles of least privilege and need-to-know.
• Assess all the configuration management (change configuration/release management) processes
• Assess the effectiveness of security controls
• Develop procedures and test fail-over for system operations transfer to an alternate site based on system availability requirements.
• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.
• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.
• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.
• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.
• Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative.
• Plan and recommend modifications or adjustments based on exercise results or system environment.
• Properly document all systems security implementation, operations and maintenance activities and update as necessary.
• Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities.
• Verify and update security documentation reflecting the application/system security design features.
| • Verify minimum security requirements are in place for all applications. | https://www.cisa.gov/systems-security-analyst | 15-1212 | |||||
| Cybersecurity Lead | 521 | OPM Tier 2 or higher | Bachelor's degree | 10 yrs. | Duties may include a combination of supporting activities in coordination with Government to include continuous security monitoring, vulnerability assessment support, Security Test and Evaluation (ST&E) support and Certification/Accreditation support for the on-going assessment, planning, integration, and recommending enhancement of systems. In addition, duties may include supporting the design, integration and operation of Cybersecurity systems for the protection of networks, systems, and infrastructure. Duties may include: operate, monitor, maintain, and optimize existing monitoring, intrusion detection, and vulnerability identification on systems. Support the program and provide continuous monitoring of systems. Support technical and forensic investigations and provide support to incident response process. Prepare architectural diagrams, technical reports, and/or white papers in support of evolving Architecture requirements. Appropriate industry IT Security certification required. | 15-1212 | |
| Cybersecurity Specialist 1 | 0 | OPM Tier 2 or higher | Bachelor's degree | 2 to 5 years | Entry-level Cybersecurity support. Applies fundamental concepts, processes, practices and procedures on technical assignments. Supports enterprise Cybersecurity standards. Supports the development and implementation of Cybersecurity standards and procedures. Coordinates development and recommends security processes for the organization. Recommends Cybersecurity solutions to support customers’ requirements. Identifies and reports security violations. Recommends and satisfies Cybersecurity requirements based upon the analysis of CSPP, policy, regulatory, and resource demands. Supports customers at the highest levels in the development and implementation of processes and policies. Applies know-how to government and commercial common user systems, as well as to dedicated special purpose systems requiring specialized security features and procedures. Supports analysis, design, and development of security features for system architectures. Analyzes and recommends security requirements for computer systems which may include mainframes, workstations, and personal computers. Supports designing, development, engineering, and implementation of solutions that meet security requirements. Provides integration and implementation of the computer system security solution. Analyzes general cybersecurity-related technical problems and provides basic engineering and technical support in solving these problems. Supports vulnerability/risk analyses and makes recommendations of computer systems and applications during all phases of the system development life cycle. Performs all procedures necessary to ensure the safety of information systems data assets and to protect systems from intentional or inadvertent access or destruction. Ensures that all information systems are functional and secure. | 15-1212 | |
| Cybersecurity Specialist 2 | 521 | OPM Tier 2 or higher | Bachelor's degree | 4 yrs. | Mid-level Cybersecurity support. Applies advanced knowledge of concepts, processes, practices, and procedures on technical assignments. Supports enterprise Cybersecurity standards. Supports the development and implementation of Cybersecurity standards and procedures. Coordinates, development, and makes recommendations of security programs for an organization. Coordinates, development, and makes recommendations of security programs for an organization. Recommends Cybersecurity solutions to support customers’ requirements. Identifies and reports security violations. Recommends and satisfies Cybersecurity requirements based upon the analysis of CSPP, policy, regulatory, and resource demands. Supports customers at the highest levels in the development and implementation of processes and policies. Applies know-how to government and commercial common user systems, as well as to dedicated special purpose systems requiring specialized security features and procedures. Supports analysis, design, and development of security features for system architectures. Analyzes and recommends security requirements for computer systems which may include mainframes, workstations, and personal computers. Support designing, development, engineering, and implementation of solutions that meet security requirements. Supports integration and implementation of the computer system security solution. Analyzes general Cybersecurity-related technical problems and provides basic engineering and technical support in solving these problems. Supports vulnerability/risk analyses and makes recommendations of computer systems and applications during all phases of the system development life cycle. Performs all procedures necessary to ensure the safety of information systems data assets and to protect systems from intentional or inadvertent access or destruction. Ensures that all information systems are functional and secure. | 15-1212 | |
| Cybersecurity Specialist 3 | 521 | OPM Tier 2 or higher | Bachelor's degree | 8 yrs. | Senior-level Cybersecurity support. Applies comprehensive knowledge of concepts, processes, practices, and procedures on technical assignments. Supports enterprise Cybersecurity standards. In coordination with Government develops and implements Cybersecurity standards and procedures. Coordinates, development, and recommends security processes for an organization. Recommends Cybersecurity solutions to support customers’ requirements. Identifies and reports security violations. Recommends and satisfies Cybersecurity requirements based upon the analysis of CSPP, policy, regulatory, and resource demands. Supports customers at the highest levels in the development and implementation of processes and policies. Applies know-how to government and commercial common user systems, as well as to dedicated special purpose systems requiring specialized security features and procedures. Supports analysis, design, and development of security features for system architectures. Analyzes security requirements for computer systems which may include mainframes, workstations, and personal computers. Designs, develops, engineers, and implements solutions that meet CSPP requirements. Provides integration and implementation of the computer system security solution. Analyzes general Cybersecurity-related technical problems and provides basic engineering and technical support in solving these problems. Supports vulnerability/risk analyses and makes recommendations on computer systems and applications during all phases of the system development life cycle. Performs all procedures necessary to ensure the safety of information systems data assets and to protect systems from intentional or inadvertent access or destruction. Ensures that all information systems are functional and secure. | 15-1212 | |
| Data Reporting Analyst | OPM Tier 2 or higher | Bachelor's degree | 2 to 5 years | •Analyze and define data requirements and specifications. |
•Analyze data sources to provide actionable recommendations.
•Assess the validity of source data and subsequent findings.
•Collect metrics and trending data.
•Develop data standards, policies, and procedures.
| •Provide actionable recommendations to critical stakeholders based on data analysis and findings. | https://www.cisa.gov/data-analyst | 15-2031 | |||||||
| Database Administrator | OM-DTA-001 | OPM Tier 2 or higher | Bachelor's degree | 2 to 5 or more years | IAT Level I | Administers databases and/or data management systems that allow for the secure storage, query, protection, and utilization of data. | 421 | 15-1245 | |
| Desktop Support Analyst | Associates to Bachelor's degree | 1 to 5 Years | • Pay attention to customers’ descriptions of their computer problems |
• Ask customers questions to properly diagnose the problem
• Walk customers through the recommended problem-solving steps
• Set up or repair computer equipment and related devices
• Train users to work with new computer hardware or software, such as printers, word-processing software, and email
• Provide other team members and managers in the organization with information about what gives customers the most trouble and about other concerns customers have
| https://www.bls.gov/ooh/computer-and-information-technology/computer-support-specialists.htm | 15-1232 | ||||
| Functional Analyst | OPM Tier 2 or higher | Bachelor's degree | 2 to 5 years | • Conduct risk analysis, feasibility study, and/or trade-off analysis to develop, document, and refine functional requirements and specifications. |
• Consult with customers to evaluate functional requirements.
• Translate functional requirements into technical solutions.
| https://www.cisa.gov/systems-requirements-planner | 13-1111 | ||||
| Functional Expert Consultant Level II | OPM Tier 2 or higher | Bachelor's degree | 5 to 7 years | • Conduct risk analysis, feasibility study, and/or trade-off analysis to develop, document, and refine functional requirements and specifications. |
• Consult with customers to evaluate functional requirements.
• Define project scope and objectives based on customer requirements
• Translate functional requirements into technical solutions.
• Develop and document User Experience (UX) requirements including information architecture and user interface requirements.
| https://www.cisa.gov/systems-requirements-planner | 13-1111 | |||||
| Incident Response | OPM Tier 2 or higher | Bachelor's degree | 1 to 5 years | maintains system cybersecurity monitoring operations. Analyzes, reports, and responds to detected cyber incidents | 15-1212 | |
| Information Assurance/Security Specialist 2 | OPM Tier 2 or higher | Bachelor's degree | 2 yrs. | • Analyze and report organizational security posture trends. |
• Analyze and report system security posture trends.
• Apply security policies to meet security objectives of the system.
• Assess adequate access controls based on principles of least privilege and need-to-know.
• Assess all the configuration management (change configuration/release management) processes
• Assess the effectiveness of security controls
• Develop procedures and test fail-over for system operations transfer to an alternate site based on system availability requirements.
• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.
• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.
• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.
• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.
• Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative.
• Plan and recommend modifications or adjustments based on exercise results or system environment.
• Properly document all systems security implementation, operations and maintenance activities and update as necessary.
• Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities.
• Verify and update security documentation reflecting the application/system security design features.
| • Verify minimum security requirements are in place for all applications. | https://www.cisa.gov/systems-security-analyst | 15-1212 | ||||
| Information Assurance/Security Specialist 3 | OPM Tier 2 or higher | Bachelor's degree | 3 yrs. | • Analyze and report organizational security posture trends. |
• Analyze and report system security posture trends.
• Apply security policies to meet security objectives of the system.
• Assess adequate access controls based on principles of least privilege and need-to-know.
• Assess all the configuration management (change configuration/release management) processes
• Assess the effectiveness of security controls
• Develop procedures and test fail-over for system operations transfer to an alternate site based on system availability requirements.
• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.
• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.
• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.
• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.
• Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative.
• Plan and recommend modifications or adjustments based on exercise results or system environment.
• Properly document all systems security implementation, operations and maintenance activities and update as necessary.
• Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities.
• Verify and update security documentation reflecting the application/system security design features.
| • Verify minimum security requirements are in place for all applications. | https://www.cisa.gov/systems-security-analyst | 15-1212 | ||||
| Information Assurance/Security Specialist 4 | OPM Tier 2 or higher | Bachelor's degree | 5 yrs. | • Analyze and report organizational security posture trends. |
• Analyze and report system security posture trends.
• Apply security policies to meet security objectives of the system.
• Assess adequate access controls based on principles of least privilege and need-to-know.
• Assess all the configuration management (change configuration/release management) processes
• Assess the effectiveness of security controls
• Develop procedures and test fail-over for system operations transfer to an alternate site based on system availability requirements.
• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.
• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.
• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.
• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.
• Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative.
• Plan and recommend modifications or adjustments based on exercise results or system environment.
• Properly document all systems security implementation, operations and maintenance activities and update as necessary.
• Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities.
• Verify and update security documentation reflecting the application/system security design features.
| • Verify minimum security requirements are in place for all applications. | https://www.cisa.gov/systems-security-analyst | 15-1212 | ||||
| Information Assurance/Security Specialist Senior | OPM Tier 2 or higher | Bachelor's degree | 7 yrs. | • Analyze and report organizational security posture trends. |
• Analyze and report system security posture trends.
• Apply security policies to meet security objectives of the system.
• Assess adequate access controls based on principles of least privilege and need-to-know.
• Assess all the configuration management (change configuration/release management) processes
• Assess the effectiveness of security controls
• Develop procedures and test fail-over for system operations transfer to an alternate site based on system availability requirements.
• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.
• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.
• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.
• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.
• Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative.
• Plan and recommend modifications or adjustments based on exercise results or system environment.
• Properly document all systems security implementation, operations and maintenance activities and update as necessary.
• Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities.
• Verify and update security documentation reflecting the application/system security design features.
| • Verify minimum security requirements are in place for all applications. | https://www.cisa.gov/systems-security-analyst | 15-1212 | ||||
| Information Engineer | OPM Tier 2 or higher | Bachelor's degree | 2 to 5 years | • Monitor their organization’s networks for security breaches and investigate a violation when one occurs |
• Prepare reports that document security breaches and the extent of the damage caused by the breaches
• Conduct penetration testing, which is when analysts simulate attacks to look for vulnerabilities in their systems before they can be exploited
• Help computer users when they need to install or learn about new security products and procedures
| https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm | 15-1212 | ||||
| Information Engineer 2 | OPM Tier 2 or higher | Bachelor's degree | 5 to 7 years | • Monitor their organization’s networks for security breaches and investigate a violation when one occurs |
• Install and use software, such as firewalls and data encryption programs, to protect sensitive information
• Prepare reports that document security breaches and the extent of the damage caused by the breaches
• Conduct penetration testing, which is when analysts simulate attacks to look for vulnerabilities in their systems before they can be exploited
• Research the latest information technology (IT) security trends
• Develop security standards and best practices for their organization
• Recommend security enhancements to management or senior IT staff
| • Help computer users when they need to install or learn about new security products and procedures | https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm | 15-1212 | |||||
| Information Security Analysts | OPM Tier 2 or higher | Bachelor's degree | 2 to 7 years | Monitor their organization’s networks for security breaches and investigate a violation when one occurs. Install and use software, such as firewalls and data encryption programs, to protect sensitive information. Prepare reports that document security breaches and the extent of the damage caused by the breaches. Conduct penetration testing, which is when analysts simulate attacks to look for vulnerabilities in their systems before they can be exploited. Research the latest information technology (IT) security trends. Develop security standards and best practices for their organization. Recommend security enhancements to management or senior IT staff | 15-1212 | ||
| Information System Training Specialist | Bachelor's degree | 2 to 5 years | • Assess training needs through surveys, interviews with employees, or consultations with managers or instructors |
• Design and create training manuals, online learning modules, and course materials
• Review training materials from a variety of sources and choose appropriate materials
• Deliver training to employees using a variety of instructional techniques
• Assist in the evaluation of training programs
| • Perform administrative tasks such as monitoring costs, scheduling classes, setting up systems and equipment, and coordinating enrollment | https://www.bls.gov/ooh/business-and-financial/training-and-development-specialists.htm#:~:text=Training%20and%20development%20specialists%20help%20create%2C%20administer%2C%20and%20deliver%20training,in%20classrooms%20or%20training%20facilities. | 13-1151 | ||||
| Information Technologist 3 | OPM Tier 2 or higher | Bachelor's degree | 5 Yrs. | •Provide technical support to a business or an organization's employees |
•Train non-technical workers on the business's information systems •Design systems and assess the effectiveness of technology resources
| •Determine the practicality of changes and modification of systems. | 15-1212 | ||||
| IT Data Analyst | OPM Tier 2 or higher | Bachelor's degree | 2 to 5 years | •Analyze and define data requirements and specifications. |
•Analyze data sources to provide actionable recommendations.
•Assess the validity of source data and subsequent findings.
•Collect metrics and trending data.
•Develop data standards, policies, and procedures.
| •Provide actionable recommendations to critical stakeholders based on data analysis and findings. | https://www.cisa.gov/data-analyst | 15-2031 | |||||||
| IT Investment/Portfolio Manager | OV-PMA-004 | Bachelor's degree | 5 to 7 years | N/A | Manages a portfolio of IT investments that align with the overall needs of mission and enterprise priorities. | 804 | 11-3021 | ||
| IT Auditor | OV-PMA-005 | Bachelor's degree | 7 or more years in cybersecurity technology | CSSP Auditor | Conducts evaluations of an IT program or its individual components to determine compliance with published standards. | 805 | 15-1212 | ||
| IT Security Engineer I | OPM Tier 2 or higher | Bachelor's degree | 2 to 5 years | Entry-Level, Possess basic technical knowledge of Cybersecurity principles. Under general supervision and in coordination with Government, supports integration of new and existing information systems to ensure that appropriate controls exist, that processing is efficient and accurate, and that systems procedures are in compliance with standards, guidelines, and regulations. | 15-1212 | ||||
| IT Security Engineer II | OPM Tier 2 or higher | Bachelor's degree | 6 yrs. | Mid-Level, Possess working technical knowledge of IT Security\Cybersecurity principles. Under general supervision and in coordination with Government, develops Cybersecurity processes and control guidelines, assists in resolving technical problems, priorities, and methods. Possesses experience with vulnerability assessment and intrusion detection tools. Supports the design and deployment of security solutions with complex network architecture. | 15-1212 | ||||
| IT Security Engineer III | 652 | OPM Tier 2 or higher | Bachelor's degree | 8 yrs. | Senior-Level, Possess in-depth technical knowledge of Cybersecurity principles. Under general direction of and in coordination with CSPP, responsible for all activities relating to Cybersecurity procedures and systems. In coordination with Government develops Cybersecurity programs and control guidelines. Confers with and advises subordinates on administrative policies and procedures and resolving technical problems, priorities, and methods. Consults with and advises other areas regarding internal controls and security procedures. Prepares activity and progress reports relating to the information systems audit function. Supports vulnerability assessment and design of intrusion detection tools for complex network architecture. | 15-1212 | |||
| IT Security Lead | OPM Tier 2 or higher | Bachelor's degree | 7 years | • Develop data protection strategies, architectures, and implementation plans. |
• Develop, document, and maintain security policies, processes, procedures, standards, and best practices.
• Ensure the protection of assets by the enforcement of security policies.
• Monitor information security events/alerts respond to, triage, and escalate as needed.
• Analyze event/alert patterns to properly interpret and prioritize threats.
• Identify trends and drive requirements aimed at fine-tuning existing policies.
• Provide technical advice and input for the support of integrated security systems and solutions.
• Maintain up-to-date information protection industry awareness and trends and be able to understand how emerging threats may potentially impact the organization.
• Create, modify, and review various reports and dashboards from our various reporting tools.
• Maintain policies and associated events.
• Make recommendations to strengthen the security posture of a computing environment as well as recommend process and technology improvements.
• Assist with incident investigations.
• Improve and challenge existing processes and procedures.
• Provide high quality, professional day-to-day execution.
| https://www.cisa.gov/systems-security-analyst | 15-1212 | ||||
| IT Security Specialist 2 | OPM Tier 2 or higher | Bachelor's degree | 3 Yrs. | • Analyze and report organizational security posture trends. |
• Analyze and report system security posture trends.
• Apply security policies to meet security objectives of the system.
• Assess adequate access controls based on principles of least privilege and need-to-know.
• Assess all the configuration management (change configuration/release management) processes
• Assess the effectiveness of security controls
• Develop procedures and test fail-over for system operations transfer to an alternate site based on system availability requirements.
• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.
• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.
• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.
• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.
• Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative.
• Plan and recommend modifications or adjustments based on exercise results or system environment.
• Properly document all systems security implementation, operations and maintenance activities and update as necessary.
• Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities.
• Verify and update security documentation reflecting the application/system security design features.
| • Verify minimum security requirements are in place for all applications. | https://www.cisa.gov/systems-security-analyst | 15-1212 | ||||
| IT Security Specialist 3 | OPM Tier 2 or higher | Bachelor's degree | 5 years | • Analyze and report organizational security posture trends. |
• Analyze and report system security posture trends.
• Apply security policies to meet security objectives of the system.
• Assess adequate access controls based on principles of least privilege and need-to-know.
• Assess all the configuration management (change configuration/release management) processes
• Assess the effectiveness of security controls
• Develop procedures and test fail-over for system operations transfer to an alternate site based on system availability requirements.
• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.
• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.
• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.
• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.
• Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative.
• Plan and recommend modifications or adjustments based on exercise results or system environment.
• Properly document all systems security implementation, operations and maintenance activities and update as necessary.
• Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities.
• Verify and update security documentation reflecting the application/system security design features.
| • Verify minimum security requirements are in place for all applications. | https://www.cisa.gov/systems-security-analyst | 15-1212 | ||||
| Lead Engineer | Bachelor's degree | 7 Yrs. | • Analyze and report organizational security posture trends. |
• Analyze and report system security posture trends.
• Apply security policies to meet security objectives of the system.
• Assess adequate access controls based on principles of least privilege and need-to-know.
• Assess all the configuration management (change configuration/release management) processes
• Assess the effectiveness of security controls
• Ensure all systems security operations and maintenance activities are properly documented and updated as necessary.
• Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.
• Implement security measures to resolve vulnerabilities, mitigate risks and recommend security changes to system or system components as needed.
• Implement system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation.
• Plan and recommend modifications or adjustments based on exercise results or system environment.
• Properly document all systems security implementation, operations and maintenance activities and update as necessary.
• Verify and update security documentation reflecting the application/system security design features.
| • Verify minimum security requirements are in place for all applications. | https://www.cisa.gov/systems-security-analyst | 15-1212 | |||||
| Network Engineer I | 652 | OPM Tier 2 or higher | Bachelor's degree | 3 yrs. | Mid-Level, With guidance from more senior engineers and in coordination with Government, perform a variety of network engineering tasks, which are broad in nature and are related to the design and implementation of integrated networks, including labor, hardware, software and support facilities and/or equipment. Plan and perform network engineering research, design development, and other assignments in conformance with network design, engineering and customer specifications. Coordinate the activities of Network Technicians assigned to specific network engineering projects. Perform with some latitude for independent actions and decisions. | 15-1244 | |
| Network Systems Security Engineer | OPM Tier 2 or higher | Bachelor's degree | 2 to 5 years | • Configure and optimize network hubs, routers, and switches (e.g., higher-level protocols, tunneling). |
• Develop and implement network backup and recovery procedures.
• Diagnose network connectivity problems
• Install and maintain network infrastructure device operating system software (e.g., IOS, firmware).
• Install or replace network hubs, routers, and switches.
• Monitor network capacity and performance.
• Patch network vulnerabilities to ensure information is safeguarded against outside parties
• Test and maintain network infrastructure including software and hardware devices.
| https://www.cisa.gov/network-operations-specialist | 15-1244 | ||||
| Product Support Specialist | OPM Tier 2 or higher | Bachelor's degree | 2 to 5 years | •Confer with customers to identify problems, replicate them, and troubleshoot for root cause. |
•Evaluate failures, bugs, systemic problems, and hardware and report on necessary steps.
•Consider site-specific information like hardware, operating system, and user requirements to appropriately resolve problems.
| •Install applications, hardware, parts, and/or equipment. | 13-1198 | ||||
| Program Admin Specialist 2 | OPM Tier 2 or higher | Bachelor's degree | 2 to 5 years | • Conduct risk analysis, feasibility study, and/or trade-off analysis to develop, document, and refine functional requirements and specifications. |
• Consult with customers to evaluate functional requirements.
• Define project scope and objectives based on customer requirements.
• Translate functional requirements into technical solutions.
• Develop and document User Experience (UX) requirements including information architecture and user interface requirements.
| https://www.cisa.gov/systems-requirements-planner | 13-1198 | ||||
| Project Control Specialist | Bachelor's degree | 2 to 5 years | •Lead project scheduling and baselines, and communicate changes and track progress. |
•Coordinate schedule with internal and contractor teams, and control for timely completion.
•Direct teams in data collection, management, and tasks to improve processes.
| •Track and analyze financial data and budgets, and produce reports regularly. | 13-1198 |
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .