MAS - Digital Forensic Services, LLC - GS35F214DA

PDF 394 KB

Attached to
Federal Supply Schedule GS35F214DA Federal contract IDV
Contract number
GS35F214DA
Issued by
GSA Federal Acquisition Service

About this file

This document outlines a federal supply schedule for information technology professional services. The contract was awarded on March 7, 2021 to Digital Forensic Services, LLC through the GSA Federal Acquisition Service, with an expiration date of March 6, 2026. It establishes labor rates for 27 labor categories providing IT services, including program and project management, cybersecurity specialists, analysts, engineers and writers. Key services involve network installation, help desk support, training, documentation, research, and vulnerability assessment. Labor rates range from $83.02 per hour for a Research Analyst to $248.17 per hour for the highest level Subject Matter Expert. The contract utilizes SIN 54151S for IT professional services and 54151HACS for highly adaptive cybersecurity services.

Digital Forensic Services, LLC Pricelist and/or Vendor Terms and Conditions for GS35F214DA, a Federal Supply Schedule awarded to Digital Forensic Services, LLC, under Information Technology Schedule 70 (IT-70)

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

General Services Administration

FEDERAL ACQUISITION SERVICE AUTHORIZED FEDERAL SUPPLY

SCHEDULE PRICE LIST

On-line access to contract ordering information, terms and conditions, up-to-date pricing, and the option to create an electronic delivery order is available through GSA Advantage!, a menu-driven database system.

The INTERNET address for GSA Advantage! is http://www.gsaadvantage.gov

Digital Forensic Services, LLC 9111 Edmonston Road, Suite 205

Greenbelt, MD 20770

PHONE # 410-963-0674

FAX # 301-262-4051

http://www.digitalforensics-usa.com

Contract Number: GS-35F-214DA Period Covered by Contract: March 7, 2021 through March 6, 2026

General Services Administration

Federal Acquisition Service http://www.gsaadvantage.gov/ http://www.digitalforensics-usa.com/

1. Awarded Special Item Number:

Special Item Number 54151S - INFORMATION TECHNOLOGY (IT) PROFESSIONAL SERVICES

FPDS Code D301 IT and Telecom -- Facility Operation and Maintenance

FPDS Code D302 IT and Telecom -- Systems Development

FPDS Code D306 IT and Telecom -- Systems Analysis

FPDS Code D307 IT and Telecom -- IT Strategy and Architecture

FPDS Code D308 IT and Telecom -- Programming

FPDS Code D310 IT and Telecom -- Cyber Security and Data Backup

FPDS Code D311 IT and Telecom -- Data Conversion Services

FPDS Code D316 IT and Telecom -- Telecommunications Network Management

SIN FSC/PSC Code Description

SIN 54151S Professional IT Services

FPDS Code D301 IT and Telecom -- Facility Operation and Maintenance

FPDS Code D302 IT and Telecom -- Systems Development

FPDS Code D306 IT and Telecom -- Systems Analysis

FPDS Code D307 IT and Telecom -- IT Strategy and Architecture

FPDS Code D308 IT and Telecom -- Programming

FPDS Code D310 IT and Telecom -- Cyber Security and Data Backup

FPDS Code D311 IT and Telecom -- Data Conversion Services

FPDS Code D316 IT and Telecom -- Telecommunications Network Management

b. Identification of the lowest priced labor category title and hourly rate awarded under the contract is:

Labor Category Title GSA Hourly Rate/Includes IFF

Research Analyst $83.02

c. Labor Category Descriptions of all corresponding labor category titles, general experience, functional responsibility and education are outlined on Pages 14-30 within this pricelist.

CUSTOMER INFORMATION:

2. Maximum Order: $500,000 per SIN – For SINs 54151S.

3. Minimum Order: $100.00

4. Geographic Scope of Coverage: The Geographic Scope of Coverage is Domestic Delivery. This is delivery within the 48 contiguous states, Alaska, Hawaii, Puerto Rico, Washington, DC, and U.S.

Territories. Domestic delivery also includes a port or consolidation point, within the aforementioned areas, for orders received from overseas activities.

5. Quantity Discounts: None

6. Volume Discounts: Additional 1.5% discount for a single task order of $300,000 and over.

7. Prompt Payment Terms: 1%-10 days

8. Government Purchase Cards: Government Purchase Cards will be accepted however no additional discounts will apply under the contract.

9. Government Educational Institutional Discounts: The Government Educational Institutions are offered the same types of discounts and concessions under this contract as all other Government customers.

10. Foreign Items: No foreign items are awarded under this contract.

11. Normal Delivery Terms – As negotiated between Digital Forensic Services, LLC and the Ordering Activity

a. Expedited Delivery Terms: As Negotiated between Digital Forensic Services, LLC and the Ordering Activity

b. Overnight/2-Day Delivery Terms: As negotiated between Digital Forensic Services, LLC and the Ordering Activity

c. Urgent Requirements: When the Federal Supply Schedule contract delivery period does not meet the bona fide urgent delivery requirements of an ordering activity, ordering activities are encouraged, if time permits, to contact the Contractor for the purpose of obtaining accelerated delivery. The Contractor shall reply to the inquiry within 3 workdays after receipt. (Telephonic replies shall be confirmed by the Contractor in writing.) If the Contractor offers an accelerated delivery time acceptable to the ordering activity, any order(s) placed pursuant to the agreed upon accelerated delivery time frame shall be delivered within this shorter delivery time and in accordance with all other terms and conditions of the contract.

12. FOB Point: Destination

13. Ordering Address: Digital Forensic Services, LLC

Greenbelt, MD 20770-1546

14. Payment Address: Digital Forensic Services, LLC

Greenbelt, MD 20770-1546

15. Warranty/Guarantee Provisions: All services performed under this contract will be guaranteed to completed in a satisfactory workmanlike manner as delineated with this GSA Schedule 70 Schedule Pricelist.

16. Export Packing Charges: Export Packing is not offered under this contract.

List of Participating Dealers: Digital Forensic Services, LLC does not authorize any participating dealers under this contract.

17. Terms and conditions of Government purchase card acceptance (any thresholds above the micro-purchase level): Accept any above micro-purchase threshold.

18. Terms and conditions of rental, maintenance, and repair (if applicable): N/A

19. Terms and conditions of repair parts indicating date of parts price lists and any discounts from list prices (if applicable): N/A

20. Terms and conditions for any other services (if applicable): N/A

21. List of service and distribution points (if applicable): N/A

22. List of participating dealers (if applicable): N/A

23. Preventive maintenance (if applicable): N/A

24. Environmental attributes, e.g., recycled content, energy efficiency, and/or reduced pollutants:

N/A.

25. Section 508 Compliance: Contact Digital Forensic Services, LLC for Section 508 compliance information. The EIT standards can be found at: http://www.section508.gov

26. Unique Entity Identifier (UEI) number: W2T9Y62FP6G6

27. Final Pricing:

The rates shown below includes the Industrial Funding Fee (IFF) of 0.75%.

http://www.section508.gov/

DESCRIPTION OF IT PROFESSIONAL SERVICES AND PRICING:

54151S – IT PROFESSIONAL SERVICE RATES

LABOR CATEGORIES

1 Program Manager - III $240.78 2 Program Manager - II $215.04 3 Program Manager - I $189.31 4 Project Manager $178.98 5 Subject Matter Expert - III $248.17 6 Subject Matter Expert - II $240.78 7 Database Manager $129.07 8 Database Management Specialist $121.60 9 Network Installation Technician $115.97

10 Help Desk Manager $124.96 11 Help Desk Specialist $110.18 12 Training Specialist - III $112.91 13 Training Specialist - II $94.00 14 Documentation Specialist $88.20 15 Research Analyst $83.02 16 Technical Writer $96.76 17 Network Security Specialist - III $177.30 18 Network Security Specialist - II $152.61 19 Information Assurance Analyst - III $177.23 20 Information Assurance Analyst - II $152.33 21 System Design and Development Engineer $122.00 22 Master Scheduler - II $102.38

54151HACS – HIGHLY ADAPTIVE CYBERSECURITY SERVICES

LABOR CATEGORIES

23 Vulnerability Assessment Analyst and Penetration Tester - IV

$248.17

24 Vulnerability Assessment Analyst and Penetration Tester - III

$210.78

25 Vulnerability Assessment Analyst and Penetration Tester - II

$160.56

26 Vulnerability Assessment Analyst and Penetration Tester - I

$128.64

27 Incident Response Analyst - IV $248.17 28 Incident Response Analyst - III $193.63 29 Incident Response Analyst - II $152.16 30 Incident Response Analyst - I $103.36 31 Security Operations Center (SOC) Analyst - IV $231.11 32 Security Operations Center (SOC) Analyst - III $191.40 33 Security Operations Center (SOC) Analyst - II $149.87 34 Security Operations Center (SOC) Analyst - I $103.50 35 Cyber Hunter - IV $314.20 36 Cyber Hunter - III $218.66 37 Cyber Hunter - II $182.82 38 Cyber Hunter - I $108.18 39 Risk and Vulnerability Threat Analyst - IV $223.52 40 Risk and Vulnerability Threat Analyst - III $178.29 41 Risk and Vulnerability Threat Analyst - II $133.05 42 Risk and Vulnerability Threat Analyst - I $107.46

LABOR CATEGORY DESCRIPTIONS

1. Program Manager – III

Functional Responsibility: Performs day to day management of overall contract support operations, involving multiple projects and groups of personnel at multiple locations. Organizes, directs, and coordinates the planning and production of all contract support activities. Demonstrates superior written and oral communications skills. Establishes and alters (as necessary) corporate management structure to direct effective contract support activities. Capable of leading multiple projects that involve the successful management of teams composed of data processing and other information management professionals who have been involved in analysis, design, integration, testing, documenting, converting, extending, and implementing automated information and/or telecommunication systems.

Required Experience: Minimum of fifteen (15) years of IT experience, including at least 8 years of IT and/or telecommunications system management experience. Advanced degree can substitute for years of experience.

Required Education: B.A. or B.S. in relevant field.

2. Program Manager - II

Functional Responsibility: Performs day to day management of overall contract support operations, involving multiple projects and groups of personnel at multiple locations. Organizes, directs, and coordinates the planning and production of all contract support activities. Demonstrates superior written and oral communications skills. Establishes and alters (as necessary) corporate management structure to direct effective contract support activities. Capable of leading multiple projects that involve the successful management of teams composed of data processing and other information management professionals who have been involved in analysis, design, integration, testing, documenting, converting, extending, and implementing automated information and/or telecommunication systems.

Required Experience: Minimum of twelve (12) years of IT experience, including at least 8 years of IT and/or telecommunications system management experience. Advanced degree can substitute for years of experience.

3. Program Manager - I

Functional Responsibility: Performs day to day management of overall contract support operations, involving multiple projects and groups of personnel at multiple locations. Organizes, directs, and coordinates the planning and production of all contract support activities. Demonstrates superior written and oral communications skills. Establishes and alters (as necessary) corporate management structure to direct effective contract support activities. Capable of leading multiple projects that involve the successful management of teams composed of data processing and other information management professionals who have been involved in analysis, design, integration, testing, documenting, converting, extending, and implementing automated information and/or telecommunication systems.

Required Experience: Minimum of eight (8) years of IT experience, including at least 8 years of IT and/or telecommunications system management experience. Advanced degree can substitute for years of experience.

4. Project Manager

Functional Responsibility: Performs day-to-day management of assigned delivery order projects that involve teams of data processing and other information system and management professionals who have previously been involved in analyzing, designing, integrating, testing, documenting, converting, extending, and implementing automated information and telecommunications systems. Demonstrates proven skills in those technical areas addressed by the delivery order to be managed. Organizes, directs, and coordinates the planning and production of all activities associated with assigned delivery order projects. Demonstrates excellent written and oral communication skills.

Required Experience: Minimum of ten (10) years of IT or telecommunications experience, including at least 5 years of IT software management. Advanced degree may substitute for years of experience.

5. Subject Matter Expert – III

Functional Responsibility: Provides technical, managerial, and administrative direction for problem definition, analysis, requirements development, and implementation for complex to extremely complex systems in the subject matter area.

Makes recommendations and advises organization wide improvements, optimization or maintenance efforts in the following specialties: information systems architecture, networking, telecommunications, automation, communications protocols, risk management/electronic analysis, software lifecycle management, software development methodologies, and modeling and simulation.

Required Experience: Minimum fifteen (15) years of experience in the IT field with at least ten (10) years of combined new and related older technical experience in the IT field directly related to the required area of expertise. Advanced degree may substitute for years of experience.

Required Education: M.A. or M.S. in relevant field. Years of experience may substitute for advanced degree.

6. Subject Matter Expert – II

Functional Responsibility: Shall possess senior level skills for Information technology cyber security operations. This individual will provide thought leadership and will have industry experience. SME 2 will utilize expertise with information technology and cyber security when fulfilling customers specifications.

SME 2 shall be knowledgeable handling and tracking security events from start to closure; ability to perform analysis, correlate and investigate events to determine their impact on the Enterprise. SME 2 provides support for computer network exploitation and defense techniques to include deterring, identifying and investigating computer and network intrusions; providing incident response and remediation support; performing computer surveillance/monitoring, identifying vulnerabilities; Provides technical support for continuous monitoring, computer exploitation and reconnaissance; Provides technical support for forensics services to include evidence seizure, computer forensic analysis and data recovery, in support of computer crime investigation. Researches and maintains proficiency in open and closed source computer exploitation tools, attack techniques, procedures and trends. Performs research into emerging threat sources and develops threat profiles.

Required Experience: Minimum ten (10) years of experience in the IT field with at least ten (10) years of combined new and related older technical experience in the IT field directly related to the required area of expertise. Advanced degree may substitute for years of experience.

Required Education: B.A. or B.S. in relevant field. Years of experience may substitute for advanced degree.

7. Database Manager

Functional Responsibility: Capable of managing the development of database projects. Plans and budgets staff and date resources. Supports application developers in planning, preparation, load analysis, and backup of recovery data. When necessary, responsible for reallocating resources to maximize benefits. Prepares and delivers presentations on DBMS concepts. Provides daily supervision and direction to support staff. Monitors performance and evaluates areas to improve efficiency.

Required Experience: Minimum seven (7) years of experience in the development and maintenance of database systems with at least five (5) years of experience with database management systems, system design and analysis, operating systems software, and internal and data manipulation languages.

Advanced degree may substitute for years of experience.

Required Education: B.A. or B.S. degree in relevant field. Years of experience may substitute for advanced degree.

8. Database Management Specialist

Functional Responsibility: Provides highly technical expertise and support in the use of DBMSs. Evaluates and recommends available DBMS products to support validated user requirements. Defines file organization, indexing methods, and security procedures for specific user applications. Develops, implements, and maintains database backup and recovery procedures for the environments and ensures that data integrity, security, and recoverability are built into the DBMS applications.

Required Experience: Minimum six (6) years of experience in DBMS analysis and programming with at least three (3) years specialized experience in using current DBMS technologies and application design using various database management systems. Advanced degree may substitute for years of experience.

Required Education: B.A. or B.S. degree in relevant field. Years of experience may substitute for advanced

9. Network Installation Technician

Functional Responsibility: Organizes and directs network installation on site surveys. Assesses and documents current site network configurations. Directs and leads preparation of engineering plans and site installation technical design packages. Develops installation schedules. Mobilizes network installation team. Directs and leads preparation of drawings documenting configuration changes at each site. Prepares site installation test reports. Coordinates post-installation operations and maintenance support.

Required Experience: Minimum of eight (8) years of experience with at least five (5) specialized experience including supervision of installation technicians, analysis, design and installation of local and wide area networks and analysis and installation of communications skills. Advanced degree may substitute for years of experience.

Required Education: B.A. or B.S. degree in relevant field. Years of experience may substitute for advanced

10. Help Desk Manager

Functional Responsibility: Provides daily supervision and direction to support staff who are responsible for telephone and in-person support to users in the areas of e-mail, directories, standard Windows desktop applications, and other network services. Manages personnel who serve as the first point of contact for troubleshooting hardware and software PC and printer problems. Excellent written and oral communications skills required.

Required Experience: Minimum seven (7) years of experience with at least five (5) years specialized experience including management of help desks in a multi-server environment; comprehensive knowledge of PC operating systems (e.g.DOS, Windows), networking, and mail standards; and supervision of help desk employees. Advanced degree may substitute for years of experience.

Required Education: B.A. or B.S. degree in relevant field. Years of experience may substitute for advanced

11. Help Desk Specialist

Functional Responsibility: Provides telephone and in-person support to users in the areas of email, directories, standard Windows desktop applications, and applications developed under this contract or predecessors. Serves as the initial point of contact for troubleshooting network and hardware and software PC and printer problems.

Required Experience: At least five (5) years of experience with a minimum three (3) years of specialized experience including knowledge of PC operating systems (e.g. DOS, Windows) networking and mail standards, and work on a help desk. Advanced degree may substitute for years of experience.

Required Education: B.A. or B.S. degree in relevant field. Years of experience may substitute for advanced

12. Training Specialist - II

Functional Responsibility: Conducts research necessary to develop and revise training courses and prepares appropriate training catalogs. Prepares all instructor materials (course outline, background materials, and training aids). Prepares all student materials (course manuals, workbooks, handouts, completion certificates, and course critique forms). Trains personnel by conducting formal classroom courses, workshops, and seminars. Provides daily supervision of and direction to staff.

Required Experience: Minimum of six (6) years of experience in information system development, training or related fields with at least three (3) years of experience in developing and providing IT and end user training on computer hardware and application software. Advanced degree may substitute for years of experience.

Required Education: B.A. or B.S. degree in relevant field. Years of experience may substitute for advanced

13. Training Specialist - I

Functional Responsibility: Conducts research necessary to develop and revise training courses and prepares appropriate training catalogs. Prepares all instructor materials (course outline, background material, and training aids). Prepares student materials (course manuals, workbooks handouts, completion certificates, and course critique forms). Trains personnel by conducting formal classroom courses, workshops, seminars. This labor category is offered only in conjunction with IT Professional labor categories.

Required Experience: At least two (2) years of experience in developing and providing IT and end user training on computer hardware and application software. Advanced degree may be substituted for years of experience.

Required Education: Associates Degree in related field. Years of experience may substitute for advanced degree.

14. Documentation Specialist

Functional Responsibility: Gathers, analyzes, and composes technical information. Conducts research and ensures the use of proper technical terminology. Translates technical information into clear, readable documents to be used by technical and nontechnical personnel. For applications built to run in a Windows environment, uses the standard help compiler to prepare all online documentation.

Required Experience: Minimum of two (2) years’ experience in preparing technical documentation, including conducting research on applicable standards.

Required Education: Associates degree in related field.

15. Research Analyst

Functional Responsibility: Analyzes existing and potential product and service information and prospective customers and markets. Collates information into meaningful reports and presentation material. Maintains any technical information in a systems library. Performs work through word processing, using electronic spreadsheets and other administrative software products.

Required Experience: Minimum of one (1) year of work experience in a business environment. General knowledge of government documents.

Required Education: High School Diploma.

16. Technical Writer

Functional Responsibility: Assists in collecting and organizing information for preparation of user manuals, training materials, installation guides, proposals, and reports. Edits functional descriptions, system specifications, user manuals, special reports, and any other customer deliverables and documents.

Assists in performing financial and administrative functions. Demonstrates the ability to work independently or under only general direction.

Required Experience: Minimum of five (5) years of technical writing experience. Advanced degree may be substituted for years of experience.

Required Education: Associates degree in related field. Years of experience may substitute for

17. Network Security Specialist - III

Functional Experience: Analyzes and defines security requirements for local and wide area networks.

Designs, develops, engineers, and implements solutions that meet network security requirements.

Responsible for integration and implementation of the network security solution. Performs vulnerability/risk analyses of computer systems and applications during all phases of the system development lifecycle.

Required Experience: Minimum of eight (8) years of experience five (5) of which is defining network security requirements for local and wide area networks, evaluation of approved network security product capabilities, configuring standard communications protocols, detecting and analyzing network vulnerabilities, and developing proper computer system security solutions. Advanced degree may be substituted for years of experience.

Required Education: B.A. or B.S. degree in related field. Years of experience may substitute for

18. Network Security Specialist - II

Functional Experience: Analyzes and defines security requirements for local and wide area networks.

Designs, develops, engineers and implements solutions that meet network security requirements.

Responsible for integration and implementation of the network security solution. Performs vulnerability and risk analyses of computer systems and applications during all phases of the system development lifecycle.

Required Experience: Minimum of four (4) years of experience, two of which is specialized in defining network security requirements for local and wide area networks, evaluating approved network security requirements, configuring standard communication protocols, detecting and analyzing network vulnerabilities and developing proper computer system security solutions. Advanced degree may be substituted for years of experience.

Required Education: B.A. or B.S. in relevant field. Years of experience may substitute for advanced degree.

19. Information Assurance Specialist - III

Functional Experience: Services performed include, but are not limited to, designing, developing, engineering, and implementing integrated security system solutions that will ensure proprietary/confidential data and systems are protected. Gathers and organizes technical information about an organization's mission goals and needs, existing security products, and ongoing programs in computer security in the strategic design process to translate security and business requirements into technical designs. Configures and validates secure systems; tests security products and systems to detect security weakness. Conducts regular audits to ensure that systems are being operated securely, and computer security policies and procedures are being implemented as defined in security plans. Duties include architecture design, system/network analysis, vulnerability and risk assessments, and security assessment of hardware and software. Performs duties on tasks that require expertise in firewall, cyber, cloud computing, implementation/configuration, physical security analysis of facilities, security assessment/risk analysis, security design of local area networks and wide area networks, security analysis of network operating systems and applications, continuity of operations, planning, policy development and disaster recovery.

Required Experience: Must have a minimum of seven (7) years of experience. At least 5years of specialized experience in information assurance and demonstrated ability to communicate orally and in writing and a positive customer service attitude.

Required Education: B.A. or B.S. degree.

20. Information Assurance Specialist – III

Functional Experience: Services performed include, but are not limited to, designing, developing, engineering, and implementing integrated security system solutions that will ensure proprietary/confidential data and systems are protected. Gathers and organizes technical information about an organization's mission goals and needs, existing security products, and ongoing programs in computer security in the strategic design process to translate security and business requirements into technical designs. Configures and validates secure systems; tests security products and systems to detect security weakness. Conducts regular audits to ensure that systems are being operated securely, and computer security policies and procedures are being implemented as defined in security plans. Duties include architecture design, system/network analysis, vulnerability and risk assessments, and security assessment of hardware and software. Performs duties on tasks that require expertise in firewall, cyber, cloud computing, implementation/configuration, physical security analysis of facilities, security assessment/risk analysis, security design of local area networks and wide area networks, security analysis of network operating systems and applications, continuity of operations, planning, policy development and disaster recovery.

Required Experience: Must have a minimum of four (4) years of experience. At least 3 years of specialized experience in information assurance and demonstrated ability to communicate orally and in writing and a positive customer service attitude.

Required Education: B.A. or B.S. degree

21. System Design and Development Engineer

Functional Experience: Services performed include, but are not limited to, contributing to overall strategic vision and integrates a broad range of solutions in support of client requirements for IT projects. Formulates and defines system scope and objectives, develops or modifies processes to solve complex problems for computer systems and business and electronic interfaces to achieve desired results through the use of innovative technologies. Develops and applies advanced engineering and design methods, theories, and research techniques in the investigation and solution of complex and advanced system requirements, hardware/software interfaces and applications, and solutions. Responsible for design, development, engineering, integration, and architecture. Senior staff manages, plans, and conducts major phases of significant projects. In general, work complexity and responsibility will be greater at higher levels.

Required Experience: At least five (5) years of specialized experience in system design.

22. Master Scheduler - II

Functional Experience: Responsible for planning, scheduling, coordinating, and monitoring systems/products through the complete system life cycle. Utilizing Gantt, PERT, milestone charts, earned value management and other project management techniques to gauge progress and performance variances to facilitate focus and intervention in critical areas, managing scheduling statement of work (SOW) working with associated project controllers to ensure schedule and budget/forecast are consistent, analyzing schedule for critical path, recognizing implications of changes and assisting in the development and incorporation of work-around plans into the schedule when change is required. Developing necessary reports and metrics to enable management decisions, Utilizing the Earned Value Management (EVM) system to analyze schedules to ensure they are consistent with budgets and forecast and providing integrated scheduling from proposal through execution phase of contract.

Required Experience: Must have a minimum of eight (8) years of experience. At least 2 years of experience in information technology.

23. Vulnerability Assessment Analyst and Penetration Tester – IV

Functional Experience: May support in part or in whole technical vulnerability assessments of applications and infrastructure, vulnerability research, and generation of assessment reports. Duties may include: Devising and/or selecting appropriate technical tests, network or vulnerability scan tools, and/or pen testing tools based on review of requirements and purpose; listing all steps involved for executing selected test(s) and coaching others in the use of advanced research, development, or scan tools and the analysis of comparative findings between proposed and current technologies. Coordinating or leading teams to conduct ethical tests, network scans, and/or vulnerability scans that support the evaluation of information safeguard effectiveness. Conducting reconnaissance, target assessment, target selection, and vulnerability research. Creating custom tools and exploits to penetrate various levels of controls including network, operating system, and physical. Using COTS or custom tools, conducting or leading teams to conduct vulnerability assessments, analyzing results, identifying exploitable vulnerabilities, and verifying vulnerabilities through manual assessment. Preparing and reviewing assessment documents, validating and communicating key findings to stakeholders.

Required Experience: Must have a minimum of 6 years of experience. Demonstrate the ability to communicate orally and in writing and a positive customer service attitude.

Required Education: Bachelor’s degree

24. Vulnerability Assessment Analyst and Penetration Tester – III applications and infrastructure, vulnerability research, and generation of assessment reports. Duties may include: Contributing to the selection of appropriate technical tests, network or vulnerability scan tools, and/or pen testing tools based on review of requirements and purpose; listing all steps involved for executing selected test(s) and coaching others in the use of advanced research, development, or scan tools and the analysis of comparative findings between proposed and current technologies. Coordinating or leading teams to conduct ethical tests, network scans, and/or vulnerability scans that support the evaluation of information safeguard effectiveness. Conducting reconnaissance, target assessment, target selection, and vulnerability research. Using COTS tools, conducting or leading teams to conduct vulnerability assessments, analyzing results, identifying exploitable, vulnerabilities, and verifying vulnerabilities through manual assessment. Preparing and reviewing assessment documents, validating and communicating key findings to stakeholders.

Required Experience: Must have a minimum of 5 years of experience. Demonstrate the ability to

25. Vulnerability Assessment Analyst and Penetration Tester - II applications and infrastructure, vulnerability research, and generation of assessment reports. Duties may include: Supporting development of and following general test and evaluation plans to compare current and proposed technologies; assessing test results to determine whether they match requirements specifications. Assisting in the coordination of technical tests, network scans, and/or vulnerability scans that support the evaluation of information safeguard effectiveness. Conducting reconnaissance, target assessment, data gathering, and vulnerability research. Leveraging COTS tools to conduct vulnerability assessments, analyzing results, identifying exploitable vulnerabilities, and verifying vulnerabilities.

Preparing report documents by tailoring technical information and creating benchmark or security authorization reports; outlining key findings related to speed, risks, results and reliability, and recommending acceptance or rejection of technology for applied use.

Required Experience: Must have a minimum of 3 years of experience. Demonstrate the ability to

26. Vulnerability Assessment Analyst and Penetration Tester - I applications and infrastructure, vulnerability research, and generation of assessment reports. Duties may include: Executing tests by following the steps and procedures listed in a test plan and documenting results in a standardized format that is appropriate for future analyses. Assisting in the coordination of technical tests, network scans, and/or vulnerability scans that support the evaluation of information safeguard effectiveness. Conducting reconnaissance data gathering and vulnerability research. Assisting in the creation of risk and vulnerability reporting.

Required Experience: Demonstrate the ability to communicate orally and in writing and a positive customer service attitude.

27. Risk and Vulnerability Threat Analyst - IV

Functional Experience: Participates in the conduct of controls and security assessments to assess risk of exposure of proprietary data through weaknesses in platforms, access procedures, or forms of access to the organization’s systems and the data contained in them. Duties may include: Being able to actively lead and manage project update briefings, working sessions, and stakeholder meetings. Applying strong analytical/assessment to security systems and enterprise architecture (e.g., conducting gap analyses, risk assessments.) Participating in Security Control Assessments on systems to validate the results of risk assessments and ensure that controls in the security plan are present and operating correctly on the system; providing thorough reports of the risks to the system and its data. Evaluating system findings, developing PO&AMs, and briefing stakeholders on key findings, recommendations, risk, and impact.

Required Experience: Must have a minimum of 10 years of experience. Demonstrate the ability to

28. Risk and Vulnerability Threat Analyst - III

Functional Experience: Participates in the conduct of controls and security assessments to assess risk of exposure of proprietary data through weaknesses in platforms, access procedures, or forms of access to the organization’s systems and the data contained in them. Duties may include: Supporting engineering design teams by assessing network and system security design features and making recommendations concerning overall security accreditation readiness and compliance and best practices. Supporting interoperability assessment teams and presenting written analyses and conclusions in all phases of analysis. Developing and analyzing system and security documentation. Following up with site administrators for status on non-compliant platforms and maintaining any necessary exception documentation. Maintaining documentation for exceptions to standards. Participating in Security Control Assessments on systems to validate the results of risk assessments and ensure that controls in the security plan are present and operating correctly on the system; providing thorough reports of the risks to the system and its data. Evaluating system findings, developing PO&AMs, and briefing stakeholders on key findings, recommendations, risk, and impact.

Required Experience: Must have a minimum of 7 years of experience. Demonstrate the ability to

29. Risk and Vulnerability Threat Analyst - II

Functional Experience: Participates in the conduct of controls and security assessments to assess risk of exposure of proprietary data through weaknesses in platforms, access procedures, or forms of access to the organization’s systems and the data contained in them. Duties may include: Developing, documenting, and executing containment strategies. Documenting and briefing the business on remediation options and executing the plan with stakeholders. Producing final reports and recommendations. Coordinating efforts of—and providing timely updates to—multiple business units during response. Performing in-depth analysis in support of incident response operations. Developing requirements for technical capabilities for cyber incident management. Investigating major breaches of security and recommending appropriate control improvements. Working with infrastructure and application support teams to drive closure of follow up actions identified through incident and problem management. Performing Security Control Assessments on systems to validate the results of risk assessments and ensure that controls in the security plan are present and operating correctly on the 25 system; providing thorough report of the risks to the system and its data. Developing and analyzing system and security documentation.

Required Experience: Must have a minimum of 4 years of experience. Demonstrate the ability to

30. Risk and Vulnerability Threat Analyst - I

Functional Experience: Participates in conduct of controls and security assessments to assess risk of exposure of proprietary data through weaknesses in platforms, access procedures, or forms of access to the organization’s systems and the data contained in them. Duties may include: Providing technical support on post-event network security logs and trend analysis. Uncovering security and compliance violations. Associating and correlating IP address-related events with specific systems or devices in the IT infrastructure. Supporting development and analysis of system and security documentation. Maintaining documentation for exceptions to standards.

Required Experience: Demonstrate the ability to communicate orally and in writing and a positive

31. Cyber Hunter - IV

Functional Experience: May respond to crises or urgent situations to mitigate immediate and potential threats. Approaches may include the use of information and threat intelligence specifically focused on a proximate incident to identify undiscovered attacks. Investigates and analyzes all relevant response activities. Identifies and assesses the capabilities and activities of cyber criminals or foreign intelligence entities; designs and administers procedures in the organization that sustain the security of the organization’s data and access to its technology and communications systems. Duties may include:

Leading Cyber Hunt team, providing oversight, and bearing responsibility for event investigation and tracking activities. Identifying, deterring, monitoring, and investigating computer and network intrusions.

Providing computer forensic support to high technology investigations in the form of evidence seizure, computer forensic analysis, and data recovery. Monitoring and assessing complex security devices for patterns and anomalies from raw events (DNS, DHCP, AD, SE logs); tagging events for Tier 1 and 2 monitoring. Conducting malware analysis in out-of-band environments (static and dynamic), including complex malware.

Required Experience: Demonstrate the ability to communicate orally and in writing and a positive

32. Cyber Hunter - III

Functional Experience: May respond to crises or urgent situations to mitigate immediate and potential threats. Approaches may include the use of information and threat intelligence specifically focused on a proximate incident to identify undiscovered attacks. Investigates and analyzes all relevant response activities. Identifies and assesses the capabilities and activities of cyber criminals or foreign intelligence entities; designs and administers procedures in the organization that sustain the security of the organization’s data and access to its technology and communications systems. Duties may include:

Identifying, deterring, monitoring, and investigating computer and network intrusions. Providing computer forensic support to high technology investigations in the form of evidence seizure, computer 26 forensic analysis, and data recovery. Monitoring and assessing complex security devices for patterns and anomalies from raw events (DNS, DHCP, AD, SE logs); tagging events for Tier 1 and 2 monitoring.

Conducting malware analysis in out-of-band environments (static and dynamic), including complex malware.

Required Experience: Must have a minimum of 7 years of experience. Demonstrate the ability to

33. Cyber Hunter - II

Functional Experience: May respond to crises or urgent situations to mitigate immediate and potential threats. Approaches may include the use of information and threat intelligence specifically focused on a proximate incident to identify undiscovered attacks. Investigates and analyzes all relevant response activities. Identifies and assesses the capabilities and activities of cyber criminals or foreign intelligence entities; designs and administers procedures in the organization that sustain the security of the organization’s data and access to its technology and communications systems. Duties may include: Using current hashing algorithms to validate forensic images; diagramming networks and imaging servers to support digital forensics operations. Utilizing a variety of industry-standard tools and techniques to collect a system’s current-state data and catalog, document, extract, collect, and preserve information. Using dynamic analysis to identify network intrusions and network monitoring tools to capture real-time traffic spawned by any running malicious code; identifying internet activity that is triggered by malware;

identifying network/host-based characteristics and assisting in drafting recommendations to detect and prevent malware infections in the future. Monitoring and assessing complex security devices for patterns and anomalies (IDS, DLP); tagging events for Tier 1 monitoring. Pinpointing location of compromised systems and devices; correlating events from the various components in the IT security infrastructure and identifying attacks and breaches.

Required Experience: Must have a minimum of 4 years of experience. Demonstrate the ability to

34. Cyber Hunter - I

Functional Experience: May respond to crises or urgent situations to mitigate immediate and potential threats. Approaches may include the use of information and threat intelligence specifically focused on a proximate incident to identify undiscovered attacks. Investigates and analyzes all relevant response activities. May identify and assesses the capabilities and activities of cyber criminals or foreign intelligence entities; designs and administers procedures in the organization that sustain the security of the organization’s data and access to its technology and communications systems. Duties may include:

Utilizing various government and commercial resources to research known malware and attacks, define their characteristics, and report findings and mitigation recommendations to appropriate personnel.

Using prescribed methods and materials to review and analyze events indicative of incidents. Attempting to detect the full spectrum of known cyber-attacks (e.g., DDoS, malware, phishing.) Pinpointing location of compromised systems and devices; correlating events from the various components in the IT security infrastructure and identifying attacks and breaches.

Required Experience: Demonstrate the ability to communicate orally and in writing and a positive

35. Incident Response Analyst - IV

Functional Experience: Contributes to generating responses to crises or urgent situations to mitigate immediate and/or potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security.

Duties may include: Leading one or more functional security teams (incident response, forensics, cyber intelligence etc.) Supporting the development of staff schedules and staffing forecasts for approval.

Ensuring that shift members follow the appropriate incident escalation and reporting procedures.

Providing support promptly and efficiently through front-line telephone and email communications.

Ingesting, triaging, prioritizing, assigning, tracking, documenting, and managing incidents and results.

Providing technical support in response to computer security incidents. Correlating, mapping, and fusing any and all incident information for the development and distribution of cyber alerts and notices, or other products as required. Documenting technical details of current or potential intruder threats consistent with environment. Coordinating, communicating, sharing information, and working closely with organizational stakeholders. Bearing responsibility for knowledge management of operational procedures and support documentation.

Required Experience: Must have a minimum of 7 years of experience. Demonstrate the ability to

36. Incident Response Analyst - III

Functional Experience: Contributes to generating responses to crisis or urgent situations to mitigate immediate and / or potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security.

Duties may include: Leading shifts and functional IR teams, providing oversight for incident data flow and response, content, and remediation, and partnering with other incident response centers in maintaining an understanding of threats, vulnerabilities, and exploits that could impact networks and assets.

Performing real-time proactive event investigation on various security enforcement systems, such as SIEM, anti-virus, internet content filtering/reporting, malcode prevention, firewalls, IDS & IPS, web security, anti-spam, etc. Performing the role of Incident Coordinator for IT security events requiring focused response, containment, investigation, and remediation. Performing forensic analysis on hosts supporting investigations. Conducting malware analysis in out-of-band environment (static and dynamic), including complex malware. Coordinating response action to identifies threats and incidents. Analyzing operational anomalies and network behavior, performing mitigation cyber threat monitoring and anomaly analysis, and actively monitoring the networks for cybersecurity threats and vulnerabilities.

Providing oversight and perform quality assurance on incident closures. Assisting with knowledge management - Standard Operating Procedures (SOP) and procedural support data

Required Experience: Must have a minimum of 5 years of experience. Demonstrate the ability to

37. Incident Response Analyst - II

Functional Experience: Contributes to generating responses to crisis or urgent situations to mitigate immediate and / or potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security.

Duties may include: Providing oversight for incident data flow and response, content, and remediation, 28 and partnering with other incident response centers in maintaining an understanding of threats, vulnerabilities, and exploits that could impact networks and assets. Performing real-time proactive event investigation on various security enforcement systems, such as SIEM, anti-virus, internet content filtering/reporting, malcode prevention, firewalls, IDS & IPS, web security, anti-spam, etc. Performing the role of Incident Coordinator for IT security events requiring focused response, containment, investigation, and remediation. Performing forensic analysis on hosts supporting investigations. Conducting malware analysis in out-of-band environment (static and dynamic), including complex malware.

Required Experience: Must have a minimum of 2 years of experience. Demonstrate the ability to

38. Incident Response Analyst - I

Functional Experience: Contributes to generating response to crisis or urgent situations to mitigate immediate or potential threats.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .