Draft Attachment 3 NCCS Labor Category Descriptions.xlsx
XLSX spreadsheet 34 KB Posted
- Attached to
- DHS Network Operations Security Center (NOSC) Network, Cloud, and Cyber Services (NCCS) 2. 0 Federal contract opportunity
- Solicitation number
- 70RTAC26R00000007
About this file
This is a labor category descriptions document for the DHS Network, Cloud, and Cybersecurity Services (NCCS) 2.0 contract. The document outlines detailed descriptions and qualifications for 89 distinct labor categories organized across six primary tasks: Contract Management, Capability Development and Improvement, Network/Cloud/Cybersecurity M&A and Event/Incident Management, HSEN Network Infrastructure Operations and Management Support, Field Engineering Technical Services, and Other Cybersecurity Services.
The labor categories span multiple organizational levels and specializations, including program and project management roles (Program Manager, Deputy Program Manager, Project Manager), business and analysis positions (Business Analyst, Financial Analyst, Management Analyst), cloud and infrastructure roles (Cloud Solutions Architect, Network Administrator, Database Administrator), cybersecurity specialists (Cyber Incident Detection/Response Analyst, Penetration Tester, Malware Reverse Engineer, Threat Hunter), and technical support positions (Computer User Support Specialist, Web Developer, Software Developer). Each category includes specific responsibility descriptions and required competencies. The document establishes three seniority levels—Junior (0-2.5 years), Mid (2.5-7.5 years), and Senior (7.5+ years)—with corresponding certification and education requirements. Senior-level technical roles require a minimum of two relevant technical certifications, with advanced degrees potentially substituting for up to two years of experience. The contract, anticipated for award in late November 2026, will be structured as a Department-wide Single Award IDIQ contract vehicle.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| DRAFT Attachment 4 NCCS Reading Room Instructions.docx | DOCX document | |
| Draft NCCS RFP Questions from Vendors.xlsx | XLSX spreadsheet | |
| DRAFT Attachment 1 NCCS SOW.pdf | ||
| DRAFT Attachment 2_NCCS Pricing Template 07152026 Draft (002) (003).xlsx | XLSX spreadsheet | |
| DRAFT NCCS RFP_9-16-2026.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Labor Category Descriptions
| DHS Labor Category | Labor Category Description |
| Task 1 - Contract Management | |
| Program Manager | 10 years of cybersecurity management experience with managing contracts or programs of similar size, scope, and complexity, with relevant experience overseeing technical and management teams. Certified Information Systems Security Professional (CISSP) certification. |
| Deputy Program Manager | Minimum of 5 years overall cybersecurity management experience. CISSP Certification. |
| Task 2 - Capability Development and Improvement | |
| Business Analyst | Performs research and develops specifications for the completion of projects and or activities. Performs analysis, provides cost estimates, elicits requirements, designs and documents processes and tests applications or services from modifications or enhancements. Works with functional and or product teams in the development of requirements for projects and designs specifications and test plans for enhancements. |
| Business Intelligence Analyst | Plan, direct, or coordinate activities in such fields as electronic data processing, information systems, systems analysis, and computer programming. Design, create, automate, and update metrics and dashboards in PowerBI, Grafana, etc., to provide real-time data and visualizations regarding the health, safety, and resiliency of DHS's information enterprise. |
| Document Management Specialist | Implements and administers enterprise-wide document management systems and related procedures that allow organizations to capture, store, retrieve, share, and destroy electronic records and documents. |
| Financial Analyst | Creates and performs analysis of financial and operational data. Demonstrates an ability to evaluate and maintain the proper level of data integrity within the data warehouses of all relevant financial information systems. Demonstrates computer proficiency with financial information systems including core transaction systems, decision support system, and PC Financial Application tools to complete internal and external work products. Establishes Program Outlooks as well as a Long Range Plan; identifies and manages key financial drivers; coordinates budgeting and collections; develops external & internal financial reports and any other duties as required. |
| Knowledge Management Specialist | Designs, develops, implements, maintains, and continuously improves a knowledge management strategy and repository for all NOSC internal and external stakeholders. |
| Management Analyst | Conducts organizational studies and evaluations, designs systems and procedures, conducts work simplification and measurement studies, and prepare operations and procedures manuals to assist management in operating more efficiently and effectively. Includes program analysts and management consultants. |
| Policy and Planning Specialist | Analyzes federal civilian executive branch, OMB, and DHS information security laws, regulations, and policy guidelines and provides technical support in the review, analysis, and development of processes, policy, doctrine, directives, concepts of operation, and implementation plans for the DHS NOSC. |
| Project Manager | Oversees the execution of single or multiple projects. Responsible for chartering, staffing, project planning, production, quality, project financials, and staff direction and oversight, and providing deliverables. Manages the client interface. Assists the Program Manager as required in managing contract performance. Performs non-routine functional activities of a project by providing management and technical direction to project personnel. Exercises independent judgment, as well as a high level of analytical skill in solving non-routine technical, administrative and managerial problems. Responsible for all aspects of project performance and assists in the overall direction to all project-level activities and personnel. |
| Technical Writer | Writes and edits technical materials, such as equipment manuals, appendices, or operating and maintenance instructions to meet quality requirements. May assist in layout work. |
| Test and Exercise Specialist | In accordance with the Homeland Security Exercise and Evaluation Program, design, develop, implement, and execute all aspects of an information environment and cybersecurity test and exercise program, including the development of tests and drills to test emergency preparedness and tabletop and functional exercises to simulate cybersecurity attacks to drive capability improvement. |
| Training and Development Specialist | Design and conduct training and development programs to improve individual and organizational performance. May analyze training needs. |
| Capability Development Subject Matter Expert (SME) | May be used to fill the following types of subject matter expert roles: |
Capability Development SME; Configuration, Change, and Release Manager; Continuous Service Improvement SME; ITIL v4 Solutions Architect SME; Service Catalog Design SME; Strategic Communications SME: and Cyber Security Services Provider Program Consultant
| Task 3 - Network, Cloud, and Cybersecurity M&A and Event and Incident Management | |
| Cybersecurity Program Manager | Demonstrates overall accountability for Cyber programs. May be responsible for product delivery and financial management of client engagements. A Cybersecurity Program Managers performs independent quality assurance reviews of program performance and deliverables to ensure that contractual obligations are being met. Cybersecurity Program Managers are also recognized experts in the areas of cyber process and the protection of technical architecture. They lend thought leadership to engagement teams in developing creative solutions to client problems. |
| Cybersecurity Project Manager | Manages, plans and coordinates activities of cyber projects. This individual reviews project proposal or plan to determine schedule, funding limitations, procedures for accomplishing projects, staffing requirements and allotment of available resources to various phases of projects. Establishes work plans and coordinates staffing for each phase of project and arranges for recruitment or assignment of project personnel. Identifies functional and cross-functional requirements and resources required for each task. |
| Network and Infrastructure Program Manager | Demonstrates overall accountability for network and infrastructure monitoring and analysis, event and incident management, and relevant operations and maintenance projects under a Task Order. May be responsible for product delivery and financial management of client engagements. A Cybersecurity Program Managers performs independent quality assurance reviews of program performance and deliverables to ensure that contractual obligations are being met. Cybersecurity Program Managers are also recognized experts in the areas of cyber process and the protection of technical architecture. They lend thought leadership to engagement teams in developing creative solutions to client problems. |
| Network and Infrastructure Project Manager | Manages, plans and coordinates activities of network and infrastructure projects. This individual reviews project proposal or plan to determine schedule, funding limitations, procedures for accomplishing projects, staffing requirements and allotment of available resources to various phases of projects. Establishes work plans and coordinates staffing for each phase of project and arranges for recruitment or assignment of project personnel. Identifies functional and cross-functional requirements and resources required for each task. |
| Cloud and Platform Monitoring Project Manager | Manages, plans and coordinates activities of the cloud, platform, system, service, and application monitoring workstream. This individual reviews project proposal or plan to determine schedule, funding limitations, procedures for accomplishing projects, staffing requirements and allotment of available resources to various phases of projects. Establishes work plans and coordinates staffing for each phase of project and arranges for recruitment or assignment of project personnel. Identifies functional and cross-functional requirements and resources required for each task. |
| Service Delivery Program Manager | Oversees the execution of related and overlapping activities under the task order, ensuring proper integration, coordination, sequencing, and execution of activities under all Task Order Tasks. Ensures that resources are optimized across tasks to minimize downtime and improve the resilience of the information enterprise. |
| Service Desk Program Manager | Manages the entire service desk operation for network, cloud/platform/system/application, and cybersecurity M&A and event and incident management, including oversight of the contract Enterprise Watch staff. Direct and supervise staff providing Tier 0 - 2 (and select Tier 3) operations support. Works closely with the staff and customers to help resolve the most difficult and high visibility events. Develop built-in escalation procedures to ensure that problems are resolved effectively to increase productivity and user satisfaction. |
| Cloud Analyst | Provides analyses of specialized applications and operational environments and cloud-based systems, and provides design, integration, documentation and implementation advice on complex problems that require extensive knowledge of the major commercial cloud service providers and DHS's hybrid computing environment. |
| Cloud Cyber Security Analyst | Ensures that the architecture and design of cloud-hosted information systems are functional and secure. Conducts strategic planning and recommends implementation strategies. Advises and assists Government on security and privacy policy, trusted product assessment, enterprise security engineering, secure cloud systems management, penetration and exploitation, insider threat analysis and protection, cyber situation awareness, attack sensing and warning, secure wireless networking and mobile computing, secure operating systems, secure workstation, secure data management, secure web technology, secure protocols, and authentication. |
| Cloud Solutions Architect | Architects (including trouble-shooting, designing, deploying, implementing, and maintaining) enterprise-wide cloud-based and hybrid cloud-based solutions. Requires professional-level cloud service provider-based certification and experience with translating business requirements into cloud and hybrid solutions in computing (i.e., compute); DevSecOps (Development-Security-Operations); Agile and Application Pipeline development; fault tolerance; networking; database and storage offerings (SQL and non-SQL); virtualization technologies; database administration; managed services; cybersecurity; monitoring and alerting; identity, credentialing, and access management; business continuity; disaster recovery; and budgeting. |
| Computer and Information Research Scientist | Conducts research into fundamental computer and information science problems. Develop solutions to specific problems in the field of computer hardware networking and software-defined networking for DHS's information enterprise. |
| Computer Operator | Monitors and controls computer, network device, and peripheral electronic data processing equipment to process enterprise data according to operating instructions. Monitors and responds to operating and error messages. May enter commands at a computer terminal and set controls on computer and peripheral devices. |
| Computer Programmer | Creates, modifies, and tests the code, forms, and scripts that allow computer applications on network devices (to include sensors, feeds, telemetry, etc.) to run. Works from specifications drawn up by software developers or other individuals. May assist software developers by analyzing user needs and designing software solutions. May develop and write computer programs to store, locate, and retrieve specific documents, data, and information. |
| Computer Systems Analyst | Analyzes science, engineering, business, and other data processing problems to implement and improve computer LAN and WAN systems. Analyzes user requirements, procedures, and problems to automate or improve existing systems and review computer system capabilities, workflow, and scheduling limitations. May analyze or recommend commercially available software. |
| Computer Systems Engineer/Architect | Designs and develops solutions to complex networking problems, system administration issues, or network concerns. Performs systems management and integration functions. |
| Computer User Support Specialist | Provides technical assistance to computer users. Answers questions and resolves computer problems for clients in person, or via telephone or electronically. May provide assistance concerning the use of computer hardware and software, including printing, installation, word processing, electronic mail, and operating systems. |
| Network Administrator | Supports the installation, implementation, troubleshooting, and maintenance of agency wide-area networks (WANs) and local-area networks (LANs). Assists in designing and managing the WAN infrastructure and any processes related to the WAN. Provides Production Support of the Network, including day-to-day operations, monitoring and problem resolution. Provides second level problem identification, diagnosis and resolution of problems. Supports the dispatch of circuit and hardware vendors involved in the resolution process. Supports the escalation and communication of status to agency management and internal customers. A working knowledge is desirable in various software systems and architectures, communications protocols: and network hardware devices. |
| Network Operations Center (NOC) Analyst / Engineer | Provides operational support to maintain overall health and performance of DHS's enterprise network components, to include LAN, WAN, firewalls, VPNs, and other network platforms. Monitors and analyzes network performance via dashboards, telemetry, and user tickets to respond to potential network degradation events and outages. Investigates and diagnoses incidents to restore network services as quickly as possible, ensuring all incident details and restoration steps are thoroughly documented in the ServiceNow ticketing platform. |
| Cyber Incident Detection/Response Analyst | Contributes to generating responses to crisis or urgent situations to mitigate immediate and / or potential information security threats and incidents. Duties may include: • Leads shifts and functional IR teams, provides oversight for incident data flow and response, content, and remediation, and partners with other incident response centers in maintaining an understanding of threats, vulnerabilities, and exploits that could impact networks and assets • Performs real-time proactive event investigation on various security enforcement systems, such as SIEM, Anti-virus, Internet content filtering/reporting, malcode prevention, Firewalls, IDS & IPS, Web security, antispam, etc. • Performs the role of Incident Coordinator for IT Security events requiring focused response, containment, investigation, and remediation • Performs forensic analysis on hosts supporting investigations • Conducts malware analysis in out of-band environment (static and dynamic), including complex malware • Coordinates response action to identifies threats and incidents • Analyzes operational anomalies, network behavior and performs mitigation actions derived from cyber threat monitoring and anomaly analysis, and actively monitors the networks for cybersecurity threats and vulnerabilities • Provides oversight and perform quality assurance on Incident Closures • Assists with knowledge management - Standard Operating Procedures and procedural support data. |
| Cyber Security Administrator | Troubleshoots network access problems and implements network security policies and procedures. Ensures network (LAN/WAN, telecommunications, and voice) security access and protects against unauthorized access, modification, or destruction. Familiar with a variety of the field's concepts, practices, and procedures. Relies on extensive experience and judgment to plan and accomplish goals. Performs a variety of tasks. |
| Cyber Security Analyst | Supports development of technical solutions in solving complex network, platform, and system security problems. Assists with the management and administration of enterprise security programs. Responsibilities include supporting: M&A/AS&W, incident response, cyber hunt activities, penetration testing, cyber system engineering, development, and monitoring. |
| Cyber Security AS&W/M&A and SIEM Specialist | Contributes to and executes the design, development, and implementation of the NOSC's enterprise attack sensing and warning (AS&W) security program, providing monitoring and analysis (M&A) capabilities for the enterprise security program. Develops and implements the enterprise Security Information and Event Monitoring (SIEM) strategy and tool implementation via Splunk, designing data flow diagrams and alert feed architectures to ensure seamless alert integration. Monitors security queues and tool alerts to identify issues in advance. Participates in response activities to all major enterprise outages. Configures tools, settings, alerts, and notifications to improve the enterprise security and resilience capabilities, including implementation of Security Orchestration and Automation for Response (SOAR) capabilities. Develops content for, e.g., rule implementation on network border devices (firewalls, routers, switches, IDS/IPS, Taclanes, etc.). |
| Cyber Security Email Expert | Contributes to and executes the design, development, and implementation of the NOSC's portion of the enterprise email security program, including interacting with the Microsoft Office 365 and identity teams, working with external email security vendors (e.g., Proofpoint), and responding to and coordinating responses to email security and availability events. Monitors email queues and tool alerts to identify issues in advance. Participates in response activities to all email outages. Configures tools, settings, alerts, and notifications to improve the enterprise email resilience capabilities. |
| Cyber Security Engineer | Participates in special projects or investigations into specific technology or solution issues and research and piloting of new technologies. Serves as a point of contact for engineering efforts while maintaining compliance with policies and guidelines. Duties may include: configuring and maintaining policies; maintains documentation for exceptions to standards; provides timely and adequate response to threats/alerts; assesses security events to drive to resolution; provides timely and sufficient response to security incidents and assessment services; promotes security awareness. Conducts systems security analysis and implementation, system engineering, electrical design, design assurance, testing, security software engineering, program design, configuration management, integration, and testing of cyber security products and techniques. |
| Cyber Security Forensics Analyst | Performs threat and vulnerability assessments and provides subject matter expertise on appropriate threat mitigation. Performs in-depth analysis in support of network monitoring and incident response operations. Collaborates with other Information Security and IT team members to develop and implement innovative strategies for monitoring and preventing attacks. Supports cyber forensics/incident investigations and analysis. Performs electronic discovery and recovery. |
| Cyber Security Malware Reverse Engineer | Investigates potential intrusions and security events to contain and mitigate incidents. Researches cyber-attacks, malware, and threat actors to determine potential impact and develop remediation guidance; validates, categorizes and investigates escalated cyber security events; profiles and trends events in the environment for potential incidents; collects, assesses and catalogues threat indicators; performs malware analysis. |
| Cyber Security Penetration Tester | Finds security vulnerabilities in target systems, networks, and applications in order to help enterprises improve their security. Identifies which key flaws can be exploited to cause business risk. Provides crucial insights into the most pressing issues and suggests how to prioritize security resources. |
| Cyber Security SOC Analyst | Provides cyber threat analysis and reporting to support SOC and NOSC situational awareness. Actively monitors security threats and risks. Tracks investigation results and report on findings. Monitors security tools to review and analyze pre-defined events indicative of incidents and provides first tier response to security incidents; monitors network traffic for security events and performs triage analysis to identify security incidents; responds to computer security incidents. |
| Cyber Security Threat Hunter | May respond to crisis or urgent situations to mitigate immediate and potential threats. Approaches may include the use information and threat intelligence specifically focused on a proximate incident to identify undiscovered attacks. Investigates and analyzes all relevant response activities. Identifies and assesses the capabilities and activities of cyber criminals or foreign intelligence entities; design and administer procedures in the organization that sustains the security of the organization’s data and access to its technology and communications systems. |
Duties may include
| • | Identifying deters, monitors, and investigates computer and network intrusions | |
| • | Providing computer forensic support to high technology investigations in the form of evidence seizure, computer forensic analysis, and data recovery | |
| • | Monitoring and assess complex security devices for patterns and anomalies from raw events (DNS, DHCP, AD, SE logs), tag events for Tier 1 & 2 monitoring | |
| • | Conducting malware analysis in out-of-band environment (static and dynamic), including complex malware | |
| Cyber Security Threat Intelligence Analyst | Supports the design, development, implementation, and improvement of the enterprise Cybersecurity Threat Intelligence (CTI) program. Duties may include: monitoring open source intelligence feeds, sources, websites, etc., to identify emerging and zero-day threats and potential risks to enterprise security; compiling and synthesizing reports, analyzing, e.g., threat vectors and method of attack via MITRE ATT&CK and the cyber kill chain; composing emails and strategic communications to inform subscribers and stakeholders of emerging risks, etc. | |
| Cybersecurity Subject Matter Expert (SME) | Provides cybersecurity subject matter expertise in any of the above LCATs and any other applicable or necessary area of cybersecurity and information resilience, including development of strategies, approaches, and plans to close enterprise cybersecurity gaps. Areas of expertise may include, e.g., red / blue / purple team development; cyber tool content development, automation, and SOAR capability development; emerging threat identification; vulnerability and patch program management; etc. | |
| Watch Officer | Supports the 24x7x365 monitoring and alerting capabilities for DHS's information infrastructure, especially including for coordinating command and control and response actions to emerging network, cloud/platform/system/application, and cybersecurity events and incidents. Coordinates with all relevant and necessary internal and external event and incident stakeholders to drive a unified response toward event and incident resolution. Coordinates the development of after-action analyses to identify root cause analyses and/or reasons for outage for events and incidents. | |
| Database Administrator | Administers, tests, and implements computer databases, applying knowledge of database management systems. Coordinates changes to computer databases. May plan, coordinate, and implement security measures to safeguard computer databases. | |
| Database Architect | Designs strategies for enterprise database systems and set standards for operations, programming, and security. Designs and constructs large relational databases. Integrates new systems with existing warehouse structure and refine system performance and functionality. | |
| Data Warehousing Specialist | Designs, models, or implements enterprise data warehousing activities. Programs and configures warehouses of database information and provide support to warehouse users. | |
| Software Developer, Applications | Develops, creates, and modifies general computer applications software or specialized utility programs. Analyzes user needs and develop software solutions. Desigsn software or customize software for client use with the aim of optimizing operational efficiency. May analyze and design databases within an application area, working individually or coordinating database development as part of a team. May supervise computer programmers. Examples of applications requiring engineering in clude: ServiceNow, Splunk, Swimlane, Axonius, and ZScaler. | |
| Software Developer, Systems Software | Researches, designs, develops, and tests operating systems-level software, compilers, and network distribution software. Sets operational specifications and formulates and analyzes software requirements. May design embedded systems software. Applies principles and techniques of computer science, engineering, and mathematical analysis to improve enterprise information security and resilience. | |
| Software Quality Assurance Engineer and Tester | Develops and execute software test plans in order to identify software problems and their causes. | |
| Web Administrator | Manages web environment design, deployment, development and maintenance activities. Performs testing and quality assurance of web sites and web applications. | |
| Web Developer | Designs, creates, and modifies Web sites. Analyzes user needs to implement Web site content, graphics, performance, and capacity. May integrate Web sites with other computer applications. May convert written, graphic, audio, and video components to compatible Web formats by using software designed to facilitate the creation of Web and multimedia content. | |
| Task 4 - HSEN Network Infrastructure Operations and Management Support | ||
| Computer and Information Systems Manager | Plans, directs, or coordinates activities in such fields as network design and implementation, network device troubleshooting, data processing, information systems, systems analysis, and computer programming. | |
| Computer Hardware Engineer | Researches, designs, develops, or tests computer or computer-related equipment. Oversees the modification, installation, trouble-shooting, imaging/re-imaging, etc., of computer or computer-related equipment and components. | |
| Information Assurance Engineer | Performs independent assessments (system and software security vulnerability, threat, and risk assessments) and penetration tests on development and large-scale operational environments. Performs full-lifecycle (i.e., Concept to Deployment) Information Assurance (IA) security analyses to ensure the logical and systematic conversion of customer or product requirements into total secure systems solutions that acknowledge technical constraints. | |
| Network Architect / Engineer | Designs and implements computer and information networks, such as local area networks (LAN), wide area networks (WAN), intranets, extranets, and other data communications networks. Performs network modeling, analysis, and planning. May also design network and computer security measures. May research and recommend network and data communications hardware and software. | |
| Network / Systems Security Engineer | Responsible for implementation and administration of network security hardware and software, enforcing the network security policy and complying with requirements of external security audits and recommendations. Designs, configures, tests, implements and maintains telecommunications capabilities, including wide area and local area networks, for compliance with enterprise security policies. Evaluates network changes for cybersecurity impact. Evaluates network performance and resolves network and processor problems for network and cybersecurity events and incidents. Familiar with hardware and software diagnostic tools. | |
| Task 5 - Field Engineering Technical Services | ||
| Field Engineer | Assists in evaluation and solution of potential field problems, referring them to Senior Engineers or Project Managers. Field Engineers provide technical engineering information and interpretation of blue prints, plans, detail sheets, and specifications for contractors. This position finds solutions to conflicts in design drawings and specifications by conferring with the engineering team, then coordinates agreed upon solutions with the various sub-trades. As a member of the Project Site Team, the Field Engineer coordinates inspections with consultants and authorities as required by the contract, inspects for conformance to design drawings, assists Project Managers by enforcing quality control and expediting subcontractors, reviews shop drawings for conformance with the contract, and ensures information is communicated to engineers and project managers. |
| Telecommunications Engineering Specialist | Designs or configures voice, video, and data communications systems. Supervises installation and post-installation service and maintenance. |
| Telecommunications Equipment Installer and Repairer | Installs, sets-up, rearranges, or removes switching, distribution, routing, and dialing equipment used in offices or headend, telecommunications closets, field site points of presence, etc.. Services or repair telephone, cable television, Internet, and other communications equipment on customers' property. May install communications equipment or communications wiring in buildings. |
| Task 6 - Other Cybersecurity Services | |
| Information Security Analyst | Monitors the organization’s networks for security breaches and investigate when one occurs. |
Uses and maintains software, such as firewalls and data encryption programs, to protect sensitive information.
Checks for vulnerabilities in computer and network systems.
Researches the latest information technology (IT) security trends.
Prepares reports that document general metrics, attempted attacks, and security breaches.
Develops security standards and best practices for their organization.
Recommends security enhancements to management or senior IT staff.
Plans, implements, upgrades, or monitors security measures for the protection of computer networks and information. May ensure appropriate security controls are in place that will safeguard digital files and vital electronic infrastructure. May respond to computer security breaches and viruses.
| Information Technology Auditor | Audits information systems, platforms, and operating procedures in accordance with established corporate standards for efficiency, accuracy and security. Evaluates IT infrastructure in terms of risk to the organization and establishes controls to mitigate loss. Determines and recommends improvements in current risk management controls and implementation of system changes or upgrades. Familiar with a variety of the field's concepts, practices, and procedures. Relies on experience and judgment to plan and accomplish goals. Performs a variety of complicated tasks. |
| Information Technology Project Manager | Charters, plans, initiates, and manages information technology (IT) projects. Leads and guides the work of technical staff. Serves as liaison between business and technical aspects of projects. Plans project stages and assess business implications for each stage. Monitors progress to assure deadlines, standards, and cost targets are met. |
| Risk and Vulnerability Threat Analyst | Participates in the conduct of controls and security assessments to assess risk of exposure of proprietary data through weaknesses in platforms, access procedures, or forms of access to the organization’s systems and the data contained in them. Duties may include: • Support engineering design teams by assessing network and system security design features and making recommendations concerning overall security accreditation readiness and compliance and best practices • Support interoperability assessment teams and present written analysis and conclusions in all phases of analysis • Develop and analyze system and security documentation • Follow up with site administrators for status on non-compliant platforms and maintain any necessary exception documentation • Maintain documentation for exceptions to standards • Participate in Security Control Assessments on systems to validate the results of risk assessments and ensure controls in the security plan are present and operating correctly on the system; provides thorough report of the risks to the system and its data • Evaluate system findings, develop PO&AMs, and briefed stakeholders on key findings, recommendations, risk, and impact |
| Vulnerability Assessment Analyst | Contributes to technical vulnerability assessments of applications and infrastructure, vulnerability research, and generation of assessment reports. Duties may include: |
• Contributes to the selection of appropriate technical tests, network or vulnerability scan tools, and/or pen testing tools based on review of requirements and purpose; lists all steps involved for executing selected test(s) and coaches others in the use of advanced research, development, or scan tools and the analysis of comparative findings between proposed and current technologies
• Coordinates or leads teams to conducts ethical tests, network scans, and/or vulnerability scans that support the evaluation of information safeguard effectiveness
• Conduct reconnaissance, target assessment, target selection, and vulnerability research Using COTS tools, conduct or leads teams to conduct vulnerability assessments, analyzes results, identifies exploitable vulnerabilities, and verifies vulnerabilities through manual assessment
• Prepares and reviews documents, validates and communicates key findings to stakeholders Subject Matter Expert (SME) Provides cybersecurity subject matter expertise in any of the above LCATs and any other applicable or necessary area of cybersecurity and information resilience, including development of strategies, approaches, and plans to close enterprise cybersecurity gaps, especially regarding zero trust architectures and implementation approaches.
LCAT Seniority Definitions
| Labor Category Seniority Level | Seniority Level Description |
| Junior Level | 0 - 2.5 years of relevant labor category experience. For technical roles, at least one relevant technical certification or a degree in a related field/major from a two- or four-year undergraduate program is required. Education may not be substituted for experience. |
| Mid Level | 2.5 - 7.5 years of relevant labor category experience required. For technical roles, at least two relevant technical certifications, or one certification plus a degree in a related field/major from a four-year undergraduate program, is required. Education may not be substituted for experience. |
| Senior Level | 7.5+ years of relevant labor category experience required. For technical roles, at least two relevant technical certifications are required. A four-year undergraduate degree in a relevant information security, information systems, or engineering field may substitute for up to one year of experience. A Master's degree may substitute for up to two years of experience. |
File details come from the government source that posted it. Updated .