MAS - Tenica And Associates LLC - GS35F470CA

PDF 519 KB

Attached to
Federal Supply Schedule GS35F470CA Federal contract IDV
Contract number
GS35F470CA
Issued by
GSA Federal Acquisition Service

About this file

This document provides a price list for a multiple award schedule contract held by TENICA and Associates LLC. The contract was awarded on August 21, 2020 and runs through August 20, 2025. It includes special item numbers for highly adaptive cybersecurity services, IT professional services, and order-level materials. Labor categories covered range from program managers and subject matter experts with over 25 years of experience to network engineers and entry-level positions. Products and services offered include cyber hunt activities, high value asset assessments, incident response, penetration testing, and risk and vulnerability assessments. Pricing is provided for the period through August 2022 with additional terms governing order minimums and maximums, payment procedures, and contractor responsibilities.

Tenica And Associates LLC - Information Technology Division - Pricelist and/or Vendor Terms and Conditions for GS35F470CA, a Federal Supply Schedule awarded to Tenica And Associates LLC - Information Technology Division -, under Information Technology Schedule 70 (IT-70)

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

GENERAL SERVICES ADMINISTRATION

Federal Acquisition Service

Authorized Federal Supply Schedule FSS Price List

Online access to contract ordering information, terms and conditions, pricing, and the option to create an electronic delivery order are available through GSA Advantage!®. The website for

GSA Advantage!® is: https://www.GSAAdvantage.gov.

Multiple Award Schedule

FSC Group: Professional Services FSC Class: HighlyAdaptive Cybersecurity Services (HACS): 54151HACS

Information Technology Professional Services: 54151S

Contract number: GS-35F-470CA

Contract period: Option 2 August 21, 2025 through August 20, 2030

TENICA and Associates LLC 4795 Meadow Wood Lane, Suite 200W

Chantilly, VA 20151 Phone: (703) 955-7770

Contracts@TENICA-GS.com www.TENICA-GS.com

Contact for Contract Administration: Michael Rosenberg Mike.Rosenberg@TENICA-GS.com

Business size: Small Business

For more information on ordering, go to the following website:

https://www.gsa.gov/schedules

Price list current as of Modification # PS-0043, effective 23 July 2025

Prices Shown Herein are Net (discount deducted) http://www.gsaadvantage.gov/ mailto:Contracts@TENICA-GS.com http://www.tenica-gs.com/ mailto:Mike.Rosenberg@TENICA-GS.com http://www.gsa.gov/schedules

TABLE OF CONTENTS

1. CUSTOMER INFORMATION

2. TERMS AND CONDITIONS APPLICABLE TO IT PROFESSIONAL SERVICES (SIN 54151S) AND OLM, AND

HIGHLY ADAPTIVE CYBERSECURITY SERVICES (SINS 54151 HACS) ……………………. 6

CUSTOMER INFORMATION

1a. Table of awarded special item number(s) with appropriate cross-reference to item descriptions and awarded price(s).

SINs Recovery SIN Title

54151HACS

Subgroups:

• Cyber Hunt

• High Value Asset (HVA) Assessments

• Incident Response

• Penetration Testing

• Risk and Vulnerability Assessment

(RVA)

Highly Adaptive Cybersecurity Services (HACS)

54151S

54151SRC

Information Technology Professional Services

OLM OLMSTLOC

OLMRC

Order-Level Materials (OLM’s)

1b. Identification of the lowest priced model number and lowest unit price for that model for each special item number awarded in the contract. This price is the Government price based on a unit of one, exclusive of any quantity/dollar volume, prompt payment, or any other concession affecting price. Those contracts that have unit prices based on the geographic location of the customer, should show the range of the lowest price, and cite the areas to which the prices apply. See Rate table

1c. If the Contractor is proposing hourly rates, a description of all corresponding commercial job titles, experience, functional responsibility and education for those types of employees or subcontractors who will perform services shall be provided. If hourly rates are not applicable, indicate “Not applicable” for this item. See Labor category descriptions.

2. Maximum Order:

SINs Maximum Order

54151HACS $ 500,000

54151S $500,000

OLM $250,000

3. Minimum order: $100

4. Geographic coverage (delivery area). The geographic scope of the contract is domestic and overseas delivery.

5. Point(s) of production (city, county, and State or foreign country). Chantilly, Virginia – Fairfax

County

6. Discount from list prices or statement of net price. Government Net Prices (discounts already deducted.)

7. Quantity discounts. None

8. Prompt payment terms. 0% - 10 days; 0% - Net 30.

Information for Ordering Offices: Prompt payment terms cannot be negotiated out of the contractual agreement in exchange for other concessions.

9. Foreign items (list items by country of origin). Not Applicable

10a. Time of delivery. (Contractor insert number of days.) To Be Determined at the Task Order level

10b. Expedited Delivery. Items available for expedited delivery are noted in this price list. To Be Determined at the Task Order level

10c. Overnight and 2-day delivery. To Be Determined at the Task Order level 10d. Urgent Requirements. To Be Determined at the Task Order level. When the Federal Acquisition Schedule contract delivery period does not meet the bona fide urgent delivery requirements of an ordering activity, ordering activities are encouraged, if time permits, to contact the contractor for the purpose of obtaining accelerated delivery.

The contractor shall reply to the inquiry within three workdays after receipt. (Telephonic replies shall be confirmed by the Contractor in writing.) If the contractor offers an accelerated delivery time acceptable to the ordering activity, any order(s) placed pursuant to the agreed upon accelerated delivery time frame shall be delivered within this shorter delivery time and in accordance with all other terms and conditions of the contract.

11. F.O.B. point(s). Destination

12a. Ordering address(es). TENICA and Associates LLC 4795 Meadow Wood Lane, Suite 200W Chantilly, VA 20151

12b. Ordering procedures: See Federal Acquisition Regulation (FAR) 8.405-3.

13. Payment address(es). TENICA and Associates LLC

4795 Meadow Wood Lane, Suite 200W Chantilly, VA 20151

14. Warranty provision. Standard Commercial Warranty Terms & Conditions

15. Export packing charges, if applicable. Not Applicable

16. Terms and conditions of rental, maintenance, and repair (if applicable). Not Applicable

17. Terms and conditions of installation (if applicable). Not Applicable

18a. Terms and conditions of repair parts indicating date of parts price lists and any discounts from list prices (if applicable). Not Applicable

18b. Terms and conditions for any other services (if applicable). Not Applicable

19. List of service and distribution points (if applicable). Not Applicable

20. List of participating dealers (if applicable). Not Applicable

21. Preventive maintenance (if applicable). Not Applicable

22a. Special attributes such as environmental attributes (e.g., recycled content, energy efficiency, and/or reduced pollutants). Not Applicable

22b. If applicable, indicate that Section 508 compliance information is available for the information and communications technology (ICT) products and services and show where full details can be found (e.g.contractor’s website or other location.) ICT accessibility standards can be found at:

TENICA is Section 508 compliant.

Section 508 compliance information on the supplies and services in this contract are available at the following link: GSAContracts@TENICA-GS.com

23. Unique Entity Identifier (UEI) number. GNTSV97RVQM3

24. Notification regarding registration in System for Award Management (SAM) database. Contractor has registered and is active in SAM

Service Contract Labor Standards: The Service Contract Labor Standards (SCLS), formerly known as the Service Contract Act (SCA), is applicable to this contract as it applies to the entire Multiple Award Schedule (MAS) and all services provided. While no specific labor categories have been identified as being subject to SCLS/SCA due to exemptions for professional employees (FAR 22.1101, 22.1102 and 29 CRF 541.300), this contract still maintains the provisions and protections for SCLS eligible labor categories. If and / or when the contractor adds SCLS labor categories to the contract through the modification process, the contractor must inform the Contracting Officer and establish a SCLS matrix identifying the GSA labor category titles, the occupational code, SCLS labor category titles and the applicable WD number. Failure to do so may result in cancellation of the contract.

2) Terms and Conditions Applicable to IT Professional Services (SIN 54151S) and IT Highly Adaptive Cybersecurity Services (SINs 54151HACS)

Scope

i) The prices, terms, and conditions stated under SIN 54151S IT Professional Services apply exclusively to IT Services within the scope of this IT Schedule.

ii) The prices, terms, and conditions stated under SINs 54151S and 54151HACS, Highly

Adaptive Cybersecurity Services apply exclusively to Cyber Services within the scope of this IT Schedule.

iii) The contractor shall provide services at the contractor’s facility and/or at the ordering activity location, as agreed to by the contractor and the ordering activity.

Performance Incentives I-FSS-60 Performance Incentives (April 2000)

i) Performance incentives may be agreed upon between the contractor and the ordering activity on individual fixed price orders or BPAs.

ii) The ordering activity must establish a maximum performance incentive price for these services and/or total solutions on individual orders or BPAs.

iii) Incentives should be designed to relate results achieved by the contractor to specified targets. To the maximum extent practicable, ordering activities shall consider establishing incentives where performance is critical to the ordering activity’s mission and incentives are likely to motivate the contractor. Incentives shall be based on objectively measurable tasks.

Order

i) Agencies may use written orders, Electronic Data Interchange (EDI) orders, BPAs, individual purchase orders, or task orders for ordering services under this contract. BPAs shall not extend beyond the end of the contract period; all services and delivery shall be made and the contract terms and conditions shall continue in effect until the completion of the order. Orders for tasks that extend beyond the fiscal year for which funds are available shall include FAR 52.232-19 (Deviation – May 2003) Availability of Funds for the Next Fiscal Year. The purchase order shall specify the availability of funds and the period for which funds are available.

ii) All task orders are subject to the terms and conditions of the contract. In the event of conflict between a task order and the contract, the contract will take precedence.

Performance of Services

i) The contractor shall commence performance of services on the date agreed to by the contractor and the ordering activity.

ii) The contractor agrees to render services only during normal working hours, unless otherwise agreed to by the contractor and the ordering activity.

iii) The ordering activity should include the criteria for satisfactory completion for each task in the Statement of Work or Delivery Order. Services shall be completed in a good and workmanlike manner.

iv) Any contractor travel required in the performance of IT services must comply with the Federal Travel Regulation or Joint Travel Regulations, as applicable, in effect on the date(s) the travel is performed. Established federal government per diem rates will apply to all contractor travel. Contractors cannot use GSA city pair contracts.

Stop Work Order (FAR 52.232-15) (Aug 1989)

(i) The Contracting Officer may at any time, by written order to the contractor, require the contractor to stop all or any part of the work called for by this contract for a period of 90 days after the order is delivered to the contractor, and for any further period to which the parties may agree. The order shall be specifically identified as a stop-work order issued under this clause. Upon receipt of the order, the contractor shall immediately comply with its terms and take all reasonable steps to minimize the incurrence of costs allocable to the work covered by the order during the period of work stoppage.

Within a period of 90 days after a stop-work order is delivered to the contractor, or within any extension of that period to which the parties shall have agreed, the Contracting Officer shall either

1. Cancel the stop-work order; or

2. Terminate the work covered by the order as provided in the Default or the Termination for

Convenience of the Government clause of this contract.

ii) If a stop-work order is issued order issued under this clause is canceled or the period of the order or any extension thereof expires, the contractor shall resume work. The Contracting Officer shall make an equitable adjustment in the delivery schedule or contract price or both, and the contract shall be modified in writing accordingly if

1. The stop-work order results in an increase in the time required for, or in the contractor’s cost properly allocable to, the performance of any part of this contract; and

2. The contractor asserts its right to the adjustment within 30 days after the end of the period of work stoppage, provided that, if the Contracting Officer decides the facts justify the action, the Contracting Officer may receive and act upon the claim submitted at any time before final payment under this contract.

iii) If a stop-work order is not canceled and the work covered by the order is terminated for the convenience of the government, the Contracting Officer shall allow reasonable costs resulting from the stop-work order in arriving at the termination settlement.

iv) If a stop-work order is not canceled and the work covered by the order is terminated for default, the Contracting Officer shall allow, by equitable adjustment or otherwise, reasonable costs resulting from the stop-work order.

Inspection of Services In accordance with FAR 52.21404 Contract Terms and Conditions Commercial Items (Mar 2009) (Deviation I – Feb 2007) for firm-fixed price orders and FAR 52.212-4 Contract Terms and Conditions Commercial Items (Mar 2009) (Alternate I – Oct 2008) (Deviation I – Feb 2007) applies to time-and-materials and labor-hour contracts orders placed under this

Responsibilities of the Contractor

The contractor shall comply with all laws, ordinances, and regulations (federal, state, city, or otherwise) covering work of this character. If the end product of a task order is software, then FAR 52.227-14 (Deviation – Dec 2007) Rights in Data – General may apply.

Responsibilities of the Ordering Activity Subject to security regulations, the ordering activity shall permit contractor access to all facilities necessary to perform the requisite IT Professional Services.

Independent Contractor All IT Professional Services performed by the contractor under the terms of this contract shall be as an Independent Contractor and not as an agent or employee of the ordering activity.

Organizational Conflicts of Interest

i) Definitions.

“Contractor” means the person, firm, unincorporated association, joint venture, partnership, or corporation that is a party to this contract.

“Contractor and its affiliates” and “Contractor or its affiliates” refers to the contractor, its chief executives, directors, officers, subsidiaries, affiliates, subcontractors at any tier, consultants, any joint venture involving the contractor, any entity into or with which the contractor subsequently merges or affiliates, or any other successor or assignee of the contractor.

An “organizational conflict of interest” exists when the nature of the work to be performed under a proposed ordering activity contract, without some restriction on ordering activities by the contractor and its affiliates, may either (i) result in an unfair competitive advantage to the contractor or its affiliates or (ii) impair the contractor’s or its affiliates’ objectivity in performing contract work.

ii) To avoid an organizational or financial conflict of interest and to avoid prejudicing the best interests of the ordering activity, ordering activities may place restrictions on the contractor, its affiliates, chief executives, directors, subsidiaries, and subcontractors at any tier when placing orders against schedule contracts. Such restrictions shall be consistent with FAR 9.505 and shall be designed to avoid, neutralize, or mitigate organizational conflicts of interest that might otherwise exist in situations related to individual orders placed against the schedule contract. Examples of situations that may require restrictions are provided at FAR 9.508.

Invoices The contractor, upon completion of the work ordered, shall submit invoices for IT Professional Services. Progress payments may be authorized by the ordering activity on individual orders if appropriate. Progress payments shall be based upon completion of defined milestones or interim products. Invoices shall be submitted monthly for recurring services performed during the preceding month.

Payments For firm-fixed price orders, the ordering activity shall pay the contractor, upon submission of proper invoices or vouchers, the prices stipulated in this contract for service rendered and accepted.

Progress payments shall be made only when authorized by the order. For time-and-materials orders, the Payments under Time-and-Materials and Labor-Hour Contracts at FAR 52.212.-4 (Mar 2009) (Alternate I – Oct 2008) (Deviation I – Feb 2007) applies to time-and-materials orders placed under this contract. For labor-hour orders, the Payment under Time-and-Materials and Labor-Hour Contracts at FAR 52.212-4 (Mar 2009) (Alternate I – Oct 2008) (Deviation I – Feb 2007) applies to labor-hour orders placed under this contract. 52.216-31 (Feb 2007) Time-and-Materials/Labor- Hour Proposal Requirements—Commercial Item Acquisition. As prescribed in 16.601(e)(3), insert the following provision:

i) The government contemplates award of a time-and-materials or labor-hour type of contract resulting from this solicitation.

ii) The offeror must specify fixed hourly rates in its offer that include wages, overhead, general and administrative expenses, and profit. The offeror must specify whether the fixed hourly rate for each labor category applies to labor performed by

(1) The offeror;

(2) Subcontractors; and/or

(3) Divisions, subsidiaries, or affiliates of the offeror under a common control.

Résumés Résumés shall be provided to the GSA Contracting Officer or the user ordering activity upon request.

Incidental Support Costs Incidental support costs are available outside the scope of this contract. The costs will be negotiated separately with the ordering activity in accordance with the guidelines set forth in the FAR.

Approval of Subcontracts The ordering activity may require that the contractor receive written consent from the ordering activity’s Contracting Officer before placing any subcontract for furnishing any of the work called for in a task order.

Description of Labor Categories

Job Titles Functional Responsibilities Minimum

Education and Experience

Program Manager 6 Minimum of 25 years’ experience as a program/project manager (or experience in related disciplines) for complex and large-dollar systems. Requires formal government or commercial training and/or certification in program/project management disciplines including cost/budget management, schedule management, meeting system technical performance requirements, and risk management. Requires management of other program/project managers to deliver integrated end solutions.

Bachelor’s degree, 25 years’ experience

Program Manager 5 Minimum of 20 years’ experience as a program/project manager (or experience in related disciplines) for complex and large-dollar systems. Requires some formal government or commercial training and/or certification in program/project management disciplines including cost/budget management, schedule management, meeting system technical performance requirements, and risk management. Typically requires management of other program/project managers to deliver integrated end solutions.

20 years’ experience

Program Manager 4 Minimum of 15 years’ experience as a program/project manager (or experience in related disciplines) for complex and large-dollar systems. Requires some formal government or commercial training and/or certification in program/project management disciplines including cost/budget management, schedule management, meeting system technical performance requirements, and risk management.

15 years’ experience

Program Manager 3 Minimum of 10 years’ experience as a program/project manager (or experience in related disciplines) for complex and large-dollar systems. Disciplines include cost/budget management, schedule management, meeting system technical performance requirements, and risk management.

10 years’ experience

Education and Experience

Telecommunications Subject- Matter Expert (SME)/Scientist 6

Minimum 25 years’ experience as an engineer or scientist in one or more of the disciplines of computer science, computer or electrical engineering or related sub-disciplines. Duties typically involve performing scientific or engineering services that may include but are not limited to: engineering studies and analyses;

technology planning; systems architecture development; requirements development; concept development; systems design; system development and integration; test and evaluation; systems operation; construction; control of systems and components; integrated logistics support; modeling and simulation;

configuration management; and systems acquisition and lifecycle management in compliance with current industry and government practices. Recognized authority within field of expertise and extensive knowledge of related fields.

25 years’ experience

Telecommunications SME/Scientist 5

Minimum 20 years’ experience as an engineer or scientist in one or more of the disciplines of computer science, computer or electrical engineering or related sub-disciplines. Duties typically involve performing scientific or engineering services that may include but are not limited to: engineering studies and analyses;

technology planning; systems architecture development; requirements development; concept development; systems design; system development and integration; test and evaluation; systems operation; construction; control of systems and components; integrated logistics support; modeling and simulation;

configuration management; and systems acquisition and lifecycle management in compliance with current industry and government practices. Recognized authority within field of expertise and extensive knowledge of related fields.

experience

Telecommunications SME/Scientist 4

Minimum 15 years’ experience as an engineer or scientist in telecommunications or one or more of the disciplines of computer science, systems, chemical, civil, electrical, or mechanical engineering or related sub-disciplines. Duties typically involve performing scientific or engineering services that may include but are not limited to: engineering studies and analyses; technology planning; systems architecture development; requirements development; concept development;

systems design; system development and integration; test and evaluation; systems operation; construction; control of systems and components; integrated logistics support; modeling and simulation; configuration management; and systems acquisition and lifecycle management in compliance with current industry and government practices.

experience

Telecommunications SME/Scientist 3

Minimum 10 years’ experience as an engineer or scientist in telecommunications or one or more of the disciplines of computer science, systems, chemical, civil, electrical, or mechanical engineering or related sub-disciplines. Duties typically involve performing scientific or engineering services that may include but are not limited to: engineering studies and analyses; technology planning; systems architecture development; requirements development; concept development;

systems design; system development and integration; test and evaluation; systems operation; construction; control of systems and components; integrated logistics support; modeling and simulation; configuration management; and systems acquisition and lifecycle management in compliance with current industry and government practices.

Education and Experience

Network Engineer 5 Minimum 20 years’ experience in a disciplined branch of engineering. Strong working knowledge in one or more of the following disciplines: systems engineering, electrical engineering, civil engineering/architecture, optical engineering, materials science & engineering, reliability and maintainability (R&M) engineering, quality engineering, and test engineering.

experience

Network Engineer 4 Minimum 15 years’ experience in a disciplined branch of telecommunications or engineering. Strong working knowledge in one or more of the following disciplines: systems engineering, electrical engineering, quality engineering, and test engineering.

experience

Network Engineer 3 Minimum 10 years’ experience in a disciplined branch of engineering. Strong working knowledge in one or more of the following disciplines: systems engineering, electrical engineering, quality engineering, and test engineering.

experience

Network Engineer 2 Minimum 5 years’ experience in a disciplined branch of engineering. Strong working knowledge in one or more of the following disciplines: systems engineering, electrical engineering, quality engineering, and test engineering.

5 years’ experience

Network Engineer 1 New entrant to the area of network engineering. Strong working knowledge in one or more of the following disciplines: systems engineering, electrical engineering, quality engineering, and test engineering.

<5 years’ experience

Network Solutions Architect 5 Minimum 20 years’ experience in a disciplined branch of engineering developing complex system architectures, planning, design, development, evaluation, and operation of IT systems. Duties typically involve performing engineering services that may include but are not limited to: engineering studies and analyses;

technology planning; systems architecture development; requirements development; concept development; systems design; system development and integration; test and evaluation; systems operation; construction; control of systems and components; integrated logistics support; modeling and simulation;

configuration management; and systems acquisition and lifecycle management in compliance with current industry and government practices.

experience

Network Solutions Architect 4 Minimum 15 years’ experience in a disciplined branch of engineering planning, design, development, evaluation, and operation of IT systems. Able to define changes to a complex IT system and provide direct implementation support.

Provides integration support for application deployment of complex, multi-server and distributed systems. Ability to derive requirements from Statements of Objectives and translate them into activities related to the operations of a complex system.

experience

Network Solutions Architect 3 Minimum 10 years’ experience planning, design, development, evaluation, and operation of IT systems. Able to derive requirements from Statements of experience

Network Solutions Architect 2 Minimum 5 years’ experience planning, design, development, evaluation, and operation of IT systems. Able to derive requirements from Statements of

Network Solutions Architect 1 New entrant to the area of planning, design, development, evaluation, and operation of IT systems. Able to derive requirements from Statements of Objectives and translate them into activities related to the operations of a complex system.

Bachelor’s degree, <5 years’

Education and Experience

Systems Architect 5 Minimum 20 years’ experience in managing and implementing large, complex IT systems to meet business objectives. Analyzes, designs, tests, and evaluates new or existing systems. Assesses the feasibility, cost, and practicality of implementing new or converting existing systems against developing new technology. Develops detailed system architecture or conversion plans to define the conversion process, environmental considerations, and system constraints.

Bachelor’s degree, 20 years’ experience

Systems Architect 4 Minimum 15 years’ experience in managing and implementing large, complex IT systems to meet business objectives. Analyzes, designs, tests, and evaluates new or existing systems. Assesses the feasibility, cost, and practicality of implementing new or converting existing systems against developing new technology. Develops detailed system architecture or conversion plans to define the conversion process, environmental considerations, and system constraints.

Bachelor’s degree, 15 years’ experience

Systems Architect 3 Minimum 10 years’ experience in managing and implementing large, complex IT systems to meet business objectives. Analyzes, designs, tests, and evaluates new or existing systems. Assesses the feasibility, cost, and practicality of implementing new or converting existing systems against developing new technology. Develops detailed system architecture or conversion plans to define the conversion process, environmental considerations, and system constraints.

Bachelor’s degree, 10 years’ experience

Systems Architect 2 Minimum 5 years’ experience in managing and implementing large, complex IT systems to meet business objectives. Analyzes, designs, tests, and evaluates new or existing systems. Assesses the feasibility, cost, and practicality of implementing new or converting existing systems against developing new technology. Develops system architecture or conversion plans to define the conversion process, environmental considerations, and system constraints.

Bachelor’s degree, 5 years’ experience

Systems Architect 1 New entrant to the area of implementing IT systems to meet business objectives.

Able to analyze, design, test, and evaluate new or existing systems. Able to assist with developing system architecture or conversion plans to define the conversion process, environmental considerations, and system constraints.

Bachelor’s degree, <5 years’ experience

Systems Engineer 5 Minimum 20 years’ experience in establishing integrated system-level requirements for an overall information, technical, and data architecture in support of multiple software applications. Performs platform capability analyses and evaluations, selects components, and develops system and LAN interfaces to ensure compliance with requirements. Constructs models and simulations of computer systems to demonstrate ability to meet user requirements. Executes system stress tests to identify software performance constraints; tunes application and operating system software to enhance performance accordingly.

experience

Systems Engineer 4 Minimum 15 years’ experience in establishing integrated system-level requirements for an overall information, technical, and data architecture in support of multiple software applications. Performs platform capability analyses and evaluations, selects components, and develops system and LAN interfaces to ensure compliance with requirements. Constructs models and simulations of computer systems to demonstrate ability to meet user requirements. Executes experience

Systems Engineer 3 Minimum 10 years’ experience in establishing integrated system-level requirements for an overall information, technical, and data architecture in support of multiple software applications. Performs platform capability analyses and evaluations, selects components, and develops system and LAN interfaces to ensure compliance with requirements. Constructs models and simulations of computer systems to demonstrate ability to meet user requirements. Executes

Education and Experience

Systems Engineer 2 Minimum 5 years’ experience in establishing integrated system-level requirements for an overall information, technical, and data architecture in support of multiple software applications. Performs platform capability analyses and evaluations, selects components, and develops system and LAN interfaces to ensure compliance with requirements. Constructs models and simulations of computer systems to demonstrate ability to meet user requirements. Executes system stress tests to identify software performance constraints; tunes application and operating system software to enhance performance accordingly.

Bachelor’s degree, 5 years’ experience

Systems Engineer 1 New entrant to the area of establishing integrated system-level requirements for overall information, technical, and data architecture in support of multiple software applications. Performs platform capability analyses and evaluations, selects components, and develops system and LAN interfaces to ensure compliance with requirements. Assists in constructing models and simulations of computer systems to demonstrate ability to meet user requirements. Assists in executing system stress tests to identify software performance constraints; tunes application and operating system software to enhance performance accordingly.

Bachelor’s degree, <5 years’ experience

Systems Integrator 5 Minimum 20 years’ experience managing work for technical program offices that requires integration of program/system information and execution across multiple programs/projects/ systems. Possesses a combination of leadership, management, and technical expertise within the types of programs being integrated. Can manage other systems integrators.

Bachelor’s degree, 20 years’ experience

Systems Integrator 4 Minimum 15 years’ experience managing work for technical program offices that requires integration of program/system information and execution across multiple programs/projects/ systems. Possesses a combination of leadership, management, and technical expertise within the types of programs being integrated. Can manage other systems integrators.

Bachelor’s degree, 15 years’ experience

Systems Integrator 3 Minimum 10 years’ experience managing work for technical program offices that requires integration of program/system information and execution across multiple programs/projects/ systems. Possesses a combination of leadership, management, and technical expertise within the types of programs being integrated.

Bachelor’s degree, 10 years’ experience

Systems Integrator 2 Minimum 5 years’ experience managing work for technical program offices that requires integration of program/system information and execution across multiple programs/projects/ systems.

Bachelor’s degree, 5 years’ experience

Systems Integrator 1 New entrant to the area of managing work for technical program offices that require integration of program/system information and execution across multiple programs/projects/systems.

Bachelor’s degree, <5 years’ experience

BPI / Ops Research SME 5 Minimum 20 years’ experience and acknowledged as a SME within the occupation and/or specific skill. Certified with the specific language, system, process, or technology. For specific computer languages, systems, processes, or technologies, expertise with the subject matter or technology outweighs the number of years of experience.

Bachelor’s degree, 20 years’ experience

BPI / Ops Research SME 4 Minimum 15 years’ experience and acknowledged as a SME within the occupation and/or specific skill. Certified with the specific language, system, process, or technology. For specific computer languages, systems, processes, or technologies, expertise with the subject matter or technology outweighs the number of years of experience.

Bachelor’s degree, 15 years’ experience

BPI / Ops Research SME 3 Minimum 10 years’ experience and acknowledged as a SME within the occupation and/or specific skill. Certified with the specific language, system, process, or technology. For specific computer languages, systems, processes, or technologies, expertise with the subject matter or technology outweighs the number of years of experience.

Bachelor’s degree, 10 years’ experience

Vulnerability Assessment Analyst and Penetration Tester 1

May support in part or in whole technical vulnerability assessments of applications and infrastructure, vulnerability research, and generation of assessment reports. Duties may include:

Bachelor’s degree

Education and Experience

• Executing tests by following the steps and procedures listed in a test plan and documenting results in a standardized format that is appropriate for future analyses

• Assisting in the coordination of technical tests, network scans, and/or vulnerability scans that support the evaluation of information safeguard effectiveness

• Conducting reconnaissance data gathering and vulnerability research

• Assisting in the creation of risk and vulnerability reporting

Vulnerability Assessment Analyst and Penetration Tester 2

May support in part or in whole technical vulnerability assessments of applications and infrastructure, vulnerability research, and generation of assessment reports. Duties may include:

• Supporting development of and following general test and evaluation plans to compare current and proposed technologies; assessing test results to determine whether they match requirements specifications

• Assisting in the coordination of technical tests, network scans, and/or vulnerability scans that support the evaluation of information safeguard effectiveness

• Conducting reconnaissance, target assessment, data gathering, and vulnerability research

• Leveraging COTS tools to conduct vulnerability assessments, analyzing results, identifying exploitable vulnerabilities, and verifying vulnerabilities

• Preparing report documents by tailoring technical information and creating benchmark or security authorization reports; outlining key findings related to speed, risks, results and reliability, and recommending acceptance or rejection of technology for applied use

Bachelor’s degree, 3 years’ experience

Vulnerability Assessment Analyst and Penetration Tester 3

May support in part or in whole technical vulnerability assessments of applications and infrastructure, vulnerability research, and generation of assessment reports. Duties may include:

• Contributing to the selection of appropriate technical tests, network or vulnerability scan tools, and/or pen testing tools based on review of requirements and purpose; listing all steps involved for executing selected test(s) and coaching others in the use of advanced research, development, or scan tools and the analysis of comparative findings between proposed and current technologies

• Coordinating or leading teams to conduct ethical tests, network scans, and/or vulnerability scans that support the evaluation of information safeguard effectiveness

• Conducting reconnaissance, target assessment, target selection, and vulnerability research

• Using COTS tools, conducting or leading teams to conduct vulnerability assessments, analyzing results, identifying exploitable vulnerabilities, and verifying vulnerabilities through manual assessment

• Preparing and reviewing assessment documents, validating and communicating key findings to stakeholders

Bachelor’s degree, 5 years’ experience

Vulnerability Assessment Analyst and Penetration Tester 4

May support in part or in whole technical vulnerability assessments of applications and infrastructure, vulnerability research, and generation of assessment reports. Duties may include:

• Devising and/or selecting appropriate technical tests, network or vulnerability scan tools, and/or pen testing tools based on review of requirements and purpose;

listing all steps involved for executing selected test(s) and coaching others in the use of advanced research, development, or scan tools and the analysis of comparative findings between proposed and current technologies

• Coordinating or leading teams to conduct ethical tests, network scans, and/or vulnerability scans that support the evaluation of information safeguard effectiveness

• Conducting reconnaissance, target assessment, target selection, and vulnerability research

6 years’ experience

Education and Experience

• Creating custom tools and exploits to penetrate various levels of controls including network, operating system, and physical

• Using COTS or custom tools, conducting or leading teams to conduct vulnerability assessments, analyzing results, identifying exploitable vulnerabilities, and verifying vulnerabilities through manual assessment

• Preparing and reviewing assessment documents, validating and communicating key findings to stakeholders

Incident Response Analyst 1 Contributes to generating response to crisis or urgent situations to mitigate immediate or potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security. Duties may include:

• Handling and responding to cyber security incidents through coordination with stakeholders such as internal IT entities, security leadership, legal affairs, internal affairs, law enforcement, and privacy offices

• Receiving incident reporting, conducting ticket updates, and notifying stakeholders of cyber security incidents and forensic investigations in relation to computer security incidents and escalate when necessary as well as coordinating response to computer security incidents

• Recommending a course of action on each incident and creating, managing, and recording all actions taken; serving as initial POC for Events of Interest reported both internally and externally

• Establishing alarm/incident escalation process and tracking, following up, and resolving incidents

• Initiating and maintaining contact with affected parties during incident response lifecycle; investigating potential incidents/intrusions

Incident Response Analyst 2 Contributes to generating responses to crisis or urgent situations to mitigate immediate and / or potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security. Duties may include:

• Providing oversight for incident data flow and response, content, and remediation, and partnering with other incident response centers in maintaining an understanding of threats, vulnerabilities, and exploits that could impact networks and assets

• Performing real-time proactive event investigation on various security enforcement systems, such as SIEM, anti-virus, internet content filtering/reporting, malcode prevention, firewalls, IDS & IPS, web security, anti-spam, etc.

• Performing the role of Incident Coordinator for IT security events requiring focused response, containment, investigation, and remediation

• Performing forensic analysis on hosts supporting investigations

• Conducting malware analysis in out-of-band environment (static and dynamic), including complex malware

2 years’ experience

Incident Response Analyst 3 Contributes to generating responses to crisis or urgent situations to mitigate immediate and / or potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security. Duties may include:

• Leading shifts and functional IR teams, providing oversight for incident data flow and response, content, and remediation, and partnering with other incident response centers in maintaining an understanding of threats, vulnerabilities, and exploits that could impact networks and assets

• Performing real-time proactive event investigation on various security enforcement systems, such as SIEM, anti-virus, internet content filtering/reporting, malcode prevention, firewalls, IDS & IPS, web security, anti-spam, etc.

Education and Experience

• Performing the role of Incident Coordinator for IT security events requiring focused response, containment, investigation, and remediation

• Performing forensic analysis on hosts supporting investigations

• Conducting malware analysis in out-of-band environment (static and dynamic), including complex malware

• Coordinating response action to identifies threats and incidents

• Analyzing operational anomalies and network behavior, performing mitigation cyber threat monitoring and anomaly analysis, and actively monitoring the networks for cybersecurity threats and vulnerabilities

• Providing oversight and perform quality assurance on incident closures

• Assisting with knowledge management - Standard Operating Procedures (SOP) and procedural support data

Incident Response Analyst 4 Contributes to generating responses to crises or urgent situations to mitigate immediate and/or potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security. Duties may include:

• Leading one or more functional security teams (incident response, forensics, cyber intelligence etc.)

• Supporting the development of staff schedules and staffing forecasts for approval

• Ensuring that shift members follow the appropriate incident escalation and reporting procedures

• Providing support promptly and efficiently through front-line telephone and email communications

• Ingesting, triaging, prioritizing, assigning, tracking, documenting, and managing incidents and results

• Providing technical support in response to computer security incidents

• Correlating, mapping, and fusing any and all incident information for the development and distribution of cyber alerts and notices, or other products as required

• Documenting technical details of current or potential intruder threats consistent with environment

• Coordinating, communicating, sharing information, and working closely with organizational stakeholders

• Bearing responsibility for knowledge management of operational procedures and support documentation

Bachelor’s degree, 7 years’ experience

Security Operations Center (SOC) Analyst 1

Provides cyber threat analysis and reporting to support SOC and Program situational awareness. Actively monitors security threats and risks, tracks investigation results, and reports on findings. Duties may include:

• Supporting Security Operations Center, monitoring security tools to review and analyze pre-defined events indicative of incidents, and providing first-tier response to security incidents

• Following SOPs for detecting, classifying, and reporting incidents under the supervision of Tier 2 and Tier 3 staff

• Managing cases within incident management systems

Security Operations Center (SOC) Analyst 2

Provides cyber threat analysis and reporting to support SOC and program situational awareness. Actively monitors security threats and risks. Tracks investigation results and reports on findings. Duties may include:

• Supporting Security Operations Center, monitoring security tools to review and analyze pre-defined events indicative of incidents, and providing first-tier response to security incidents

• Monitoring network traffic for security events and performing triage analysis to identify security incidents

• Responding to computer security incidents by collecting, analyzing, preserving digital evidence, and ensuring that incidents are recorded and tracked in accordance with SOC requirements

Education and Experience

• Working closely with the other teams to assess risk and provide recommendations for improving security posture

• Recommending content to detect security events

• Managing cases within incident management systems

• Performing network forensics and deep packet analysis

• Identifying countermeasures to detect and prevent security incidents

Security Operations Center (SOC) Analyst 3

Provides cyber threat analysis and reporting to support SOC and program situational awareness. Actively monitors security threats and risks. Tracks investigation results and reports on findings. Duties may include:

• Supporting a Security Operations Center, monitoring security tools to review and analyze pre-defined events indicative of incidents, and providing first-tier response to security incidents

• Leading shifts and functional IR teams, providing oversight and bearing responsibility for event investigation and tracking activities

• Supporting Tier 2 operations by monitoring alerts during critical and high-volume events

• Conducting more in-depth analyses of security incidents to identify incidents of compromise

• Performing intrusion scope and root cause analyses and assisting with intrusion remediation, strategy development, and implementation; recommending effective process changes to enhance defense and response procedures

• Using SOC monitoring devices to review and analyze pre-defined events indicative of incidents; creating and recommending content to detect security events

• Conducting malware analysis in out-of-band environments (static and dynamic), including complex malware

• Vetting IOCs and conducting intelligence vetting and disposition, assessing feed viability

• Performing network forensics and deep packet analysis

• Identifying countermeasures to detect and prevent security incidents

• Supporting knowledge management and developing procedures and policies for initial stand-up of a SOC

Security Operations Center (SOC) Analyst 4

Provides cyber threat analysis and reporting to support SOC and program situational awareness. Actively monitors security threats and risks, provides in-depth incident analysis, evaluates security incidents, and provides proactive threat research. Tracks investigation results and reports on findings. Duties may include:

• Leading multiple functional security teams, providing management and leadership of SOC

• Using knowledge of regulatory compliance directives to include various monitoring and reporting requirements and industry best practices; implementing optimal workflows and procedures

• Managing and ensuring the timely response and investigations of security events and incidents by the security operations center

• Creating and maintaining schedules to ensure coverage by operations support personnel

• Coordinating with threat operations and threat intelligence specialists to resolve high or critical severity level incidents

• Bearing responsibility for knowledge management and developing procedures and policies for initial stand-up of a SOC

Bachelor’s degree, 7 years’ experience

Cyber Hunter 1 May respond to crises or urgent situations to mitigate immediate and potential threats. Approaches may include the use of information and threat intelligence specifically focused on a proximate incident to identify undiscovered attacks.

Investigates and analyzes all relevant response activities. May identify and assesses the capabilities and activities of cyber criminals or foreign intelligence entities; designs and administers procedures in the organization that sustain the

Education and Experience security of the organization’s data and access to its technology and communications systems. Duties may include:

• Utilizing various government and commercial resources to research known malware and attacks, define their characteristics, and report findings and mitigation recommendations to appropriate personnel

• Using prescribed methods and materials to review…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .