The Office of Information Security (OIS) provides information security and privacy infrastructure for the U.S. Department of Veterans Affairs (VA). The primary purpose of the position is to monitor and evaluate Field Operations activities related to IT security. The work involves the planning, installation, configuration, testing implementation and management of the systems environment is support of the VA's IT architecture and business needs.
Major Duties: Plan, develop, implement, and maintain IT operating systems, policies, and procedures to protect the integrity and confidentiality of systems, networks, and data.
Designs, acquires, modifies, evaluates, and uses software intended to ensure that users are trained on security measures necessary to protect automated systems and classified data from misuse or unauthorized disclosure, viral infection, and other problems that would compromise information confidentiality or privacy.
Evaluates new security authentication technologies such as public key infrastructure certificates, secure cards, and biometrics for inclusion in operating systems. Recommends that acquisition, implementation, and dissemination of IT security tools, procedures, and practices to be used by users to protect information assets.
Develops operating system security policy and procedural controls covering physical security, application, and data security, system software security, contingency planning, and compliance with personnel clearance procedures. Establishes risk-management procedures and ensures that risk-management techniques are applied to all new and modified IT training applications.
Identifies and specifies information systems security requirements associated with migrations to new environments and provides guidance in planning and development of migrations to new environments.
Conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST SP 800-37). Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspection, etc.
Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedure that are consistent with organization's mission and goals. Analyze and report organizational security posture trends. Analyze and report system security posture trends. Work with stakeholders to resolve computer security incidents and vulnerability compliance.
Skill in applying total infrastructure protection, systems security certification and accreditation requirements/processes and Federal information systems security protocols. Skill in requirements analysis principles and methods, communications techniques, network operations and protocols, systems security regulations, and policies.
Knowledge of appropriate VA policies, operating procedures, information flow; and of prevailing IT practices in government agencies and the private sector. Discuss timeframes, scope of the assignment including possible stages, and possible approaches.
Plans and carries out projects and analyses of the organization's requirement; interprets policies, procedures, and regulations in conformance with established mission objectives; integrates and coordinates the work of others as necessary; and resolves most conflicts as the arise. Influence and persuade employees and managers to accept and implement findings and recommendations when there are problems in security cooperation.
Meets the needs of customers while supporting missions. Communicates and treats customers in a courteous, tactful, and respectful manner. Provides the customer with consistent information according to established policies and procedures. Handles conflicts and problems in dealing with the customer constructively and appropriately.
Perform other related duties and responsibilities as assigned Work Schedule: M - F, 8 am - 4:30 pm Compressed/Flexible: Compressed/flexible schedule available at the manager's discretion Telework: Ad Hoc/Situational as determined by Agency policy. Virtual: This is not a virtual position. Position Description/PD#: IT Specialist (Infosec)/PD31646A
There is no educational substitution at this grade level.
This position is with Deputy Assistant Secretary for Information and Technology, Department of Veterans Affairs.
The posted pay range is $106437 – $138370/yr.
This position is eligible for telework.
This position requires a Other security clearance.
Applications close on 2026-09-18.
This position is open under the 'Fed Transition' hiring path.
Source: USAJOBS.gov — U.S. Federal Government
Apply on official site →