Job description
This position is located in the Department of Health & Human Services (HHS), Centers for Medicare & Medicaid Services (CMS), Office of Information Technology (OIT), Information Security and Privacy Group (ISPG), Division of Security and Privacy Compliance (DSPC). As a IT Cybersecurity Specialist (Security), GS-2210-13, you will secure Software-as-a-Service (SaaS) platforms and cloud-hosted business applications utilized throughout CMS. Plan, develop, and implement enterprise-wide SaaS security governance frameworks, policies, standards, and baselines to ensure the secure acquisition, adoption, operation, and continuous monitoring of cloud-hosted applications across CMS. Design and implement automated security workflows, scripts, and integration pipelines connecting SaaS security tools to enterprise monitoring and ticketing systems to streamline detection, tracking, remediation, and validation of security findings. Provide technical consultation, recommendations, and briefings to CMS senior leadership, application owners, cybersecurity personnel, vendors, and Federal partners on SaaS security risks, compliance posture, and remediation strategies. Conduct security posture, vulnerability, and configuration assessments of SaaS platforms, prioritize findings by risk; and coordinate remediation…


