The Office of Information Security (OIS) provides information security and privacy infrastructure for the U.S. Department of Veterans Affairs (VA). The office assures the confidentiality, integrity, and risk management, record management, Freedom of Information Act (FOIA) requests.
In addition, the OIS team develops, implements, and oversees the training, communication how VA and its partners safeguard the personally identifiable information (PII) of Veterans and VA employees.
Major Duties: Conduct risk and vulnerability assessments of planned and installed information systems to identify vulnerabilities, risks, and protection needs. Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials).
Interpret patterns of non-compliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program. Provide input in drafting information systems security documentation (e.g., systems security plans, risk assessments, disaster recovery plans, business continuity plans, and user security guides).
Develop, maintain, and administer a highly complex information security program which involves security program issues and develop VA security program objectives and plans that respond to current and future VA information technology and information security program requirements.
Mastery knowledge of contemporary information technology including hardware, software, communications, networking, data management and administration, higher order computer languages, and expert knowledge of information security and VA's Information Security Program. Mastery knowledge of regulations, federal-wide laws, policies and standards related to CFO and CIO programs generally, and to information security, in particular.
Incumbent has the ability to complete fact gathering, organizing, and presentations inherent in requirements analysis, alternatives analysis, technical project proposals, project plans, and overall program coordination. Evaluate security architectures and designs to determine the adequacy of security design and architecture proposed or provided in response to requirements contained in acquisition documents.
Ensure that protection and detection capabilities are acquired or developed using the IS security engineering approach and are consistent with organization-level cybersecurity architecture. Participate in the development or modification of the computer environment cybersecurity program plans and requirements. Collaborate with stakeholders to establish the enterprise continuity of operations program, strategy, and mission assurance.
The incumbent works under the administrative supervision of the Risk Management Framework Director. Supervisor provides administrative direction, making assignments in terms of broadly defined missions, functions, or team goals. As a recognized authority, the incumbent is delegated complete responsibility to independently organize, plan, carry out assignments, and coordinate as a peer with experts within and across VA.
Work Schedule: Monday - Friday, 8:00am - 4:30pm Compressed/Flexible: Compressed/flexible schedule available at the manager's discretion Telework: This position may be authorized for telework. Virtual: This is not a virtual position. Position Description/PD#: IT Specialist (Infosec)/PD17190A Relocation/Recruitment Incentives: Not Authorized Permanent Change of Station (PCS): Not Authorized PCS Appraised Value Offer (AVO): Not Authorized
There is no educational substitution at this grade level.
This position is with Deputy Assistant Secretary for Information and Technology, Department of Veterans Affairs.
The posted pay range is $125776 – $163514/yr.
This position is eligible for telework.
This position requires a Other security clearance.
Applications close on 2026-10-02.
This position is open under the 'Fed Transition' hiring path.
Source: USAJOBS.gov — U.S. Federal Government
Apply on official site →