Summary The Office of the Chief Information Officer (OCIO) serves as the IT hub of the U.S. Department of Labor. We develop, maintain and protect IT solutions and data across our 27 agencies to enable mission outcomes through technology and service. OCIO continually enhances federal IT and digital capability with a focus on cybersecurity and customer experience to serve America's wage earners, job seekers and retirees. Responsibilities The Department of Labor may use certain incentives and hiring flexibilities, currently offered by the Federal government to attract highly qualified candidates. Relocation Expenses, Recruitment Incentives, Superior Qualifications and Special Needs Pay-Setting Authority may be negotiable. Click here for Additional Information. The position may be located at any of the DOL office locations, if available. The advertised salary range reflects the minimum and maximum pay for all locations. Final salary will be determined based on the selectee's assigned duty station in accordance with applicable locality pay tables. The role supports the Chief Information Officer (OCIO) and its Directorate of Cybersecurity, which consists of the following divisions: Cybersecurity Governance, Cybersecurity Authorization, and Security Operations Center. Under the direction of the Department's Chief Information Security Officer(CISO), the Directorate manages the enterprise-wide organizational risk associated with the operation of unclassified and classified information systems through a distribution model that provides resiliency in the face of evolving threats. Major duties include, but are not limited to: Review and evaluate security control assessment findings to determine risk significance, recommend appropriate responses, and align remediation actions with organizational risk tolerance and priorities. Consult with authorizing officials. Advises on whether findings represent significant risk and require immediate remediation. Develop informed recommendations for initiating immediate remediation activities where findings can be easily remediated. Update assessment reports with results from reassessments while preserving original findings. Revise and maintain security and privacy plans to reflect the current state of implemented controls, including updates resulting from corrective actions taken by system owners or common control providers. Verify that system security and privacy documentation accurately describes all implemented controls, including compensating controls applied to meet security requirements. Develop comprehensive Plans of Action and Milestones (POA&Ms) that include timelines, deadlines, methods, Measures of Effectiveness, and Measures of Success to track remediation progress. Administer the Agency Computer Security Awareness Training Program, ensuring mandatory compliance and delivering specialized cybersecurity training tailored to workforce needs. Design, maintain, and implement the Department's IT Security Training and Awareness Program in collaboration with departmental IT leaders and security professionals. Enhance secure system operations by proactively addressing security issues identified through continuous monitoring, control assessments, and incident response activities. Major duties for this position at the GS-14 level are similar to the GS-13, however, they are performed under less supervision. Requirements Conditions of Employment Qualifications You must meet the Basic Requirements and the Specialized Experience to qualify for the IT Specialist (AI), as described below. Basic Qualifications: Applicants must have IT-related experience demonstrating each of the following competencies listed below: Attention to Detail - Is thorough when performing work and conscientious about attending to detail. Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. Decision Making - Makes sound, well-informed, and objective decisions; perceives the impact and implications of decisions; commits to action, even in uncertain situations, to accomplish organizational goals; causes change. Information Management - Identifies a need for and knows where or how to gather information; organizes and maintains information or information management systems. Interpersonal Skills - Shows understanding, friendliness, courtesy, tact, empathy, concern, and politeness to others; develops and maintains effective relationships with others; may include effectively dealing with individuals who are difficult, hostile, or distressed; relates well to people from varied backgrounds and different situations Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. Teamwork - Encourages and facilitates cooperation, pride, trust, and group identity; fosters commitment and team spirit; works with others to achieve goals. Technical Competence - Uses knowledge that is acquired through formal training or on-the-job experience to perform one's job; works with, understands, and evaluates technical information related to the job; advises others on technical issues. AND Applicants must have 52 weeks of specialized experience equivalent to at least the next lower grade level, in the Federal Service. For GS-13 : Applicants must have 52 weeks of specialized experience equivalent to at least the next lower grade level GS-12 in the Federal Service. For GS-14 : Applicants must have 52 weeks of specialized experience equivalent to at least the next lower grade level, GS-13 in the Federal Service. Specialized Experience is the experience that equipped the applicant with the particular knowledge, skills, and abilities (KSA's) to perform the duties of the position successfully, and that is typically in or related to the position to be filled. To be creditable, specialized experience must have been equivalent to at least the next lower grade level. Applicants must meet 3 of the 4 statements below to be found qualified. Qualifying specialized experience for GS-13 includes: Experience independently managing, implementing, and maintaining enterprise cloud services and cloud applications within a defined program area, ensuring reliability, availability, and compliance with organizational standards. Experience applying expert-level knowledge of the Federal Information Security Modernization Act (FISMA), National Institute of Standards and Technology (NIST) Risk Management Framework (RMF), and related Cybersecurity policies to assigned systems. Experience conducting detailed analysis of vulnerability scan results, collaborating with system owners and technical teams to coordinate remediation, and verifying the secure deployment of IT applications and systems. Experience supporting the development, review, and implementation of agency security policies, procedures, and standards, and ensuring program-level compliance with governance and regulatory mandates. Qualifying specialized experience for GS-14 includes: Experience with leading the management, implementation, and optimization of enterprise cloud services and cloud applications across multiple programs. Experience with serving as a technical authority on FISMA, NIST RMF, and federal cybersecurity policies; interpreting requirements for senior leadership, shaping organizational risk decisions, and developing enterprise-level compliance strategies. Experience with coordinating remediation efforts across cross-functional teams and ensuring secure deployment practices are integrated into enterprise processes. Experience with developing, implementing, and evaluating agency-wide security governance frameworks, and advising executives on security posture, compliance risks, and mitigation strategies. Education Education may not be substituted for experience at this level. Additional Information This position is being filled through the Direct Hire Authority. Traditional rating and ranking of applications does NOT apply. Veterans' preference does not apply. The mission of the Department of Labor (DOL) is to protect the welfare of workers and job seekers, improve working conditions, expand high-quality employment opportunities, and assure work-related benefits and rights for all workers. Refer to these links for more information: GENERAL INFORMATION, REASONABLE ACCOMMODATION, ADDITIONAL DOCUMENTATION, FORMER FEDERAL EMPLOYEES As a condition of employment, all personnel must undergo a background investigation for access to DOL facilities, systems, information and/or classified materials before they can enter on duty: BACKGROUND INVESTIGATION Click here for Career Ladder Promotion Information Click here for Telework Position Information. This is not a remote work position. The selectee will report to an assigned DOL office location on a regular basis and is eligible for participation in telework as determined by management in accordance with DOL policy. Based on agency needs, additional positions may be filled using this vacancy. The Department of Labor may use certain incentives and hiring flexibilities, currently offered by the Federal government to attract highly qualified candidates. Click here for Additional Information. The Fair Chance Act (FCA) prohibits Federal agencies from requesting an applicant's criminal history information before the agency makes a conditional offer of employment. If you believe a DOL employee has violated your rights under the FCA, you may file a complaint of the alleged violation following our agency's complaint process Guidelines for Reporting Violations of the Fair Chance Act. Note: The FCA does not apply to some positions specified under the Act, such as law enforcement or national security positions. All applicants tentatively selected for this position will be required to submit to screening for illegal drug use prior to the appointment. All Department of Labor employees are subject to the provisions of the Drug-Free Workplace Program under Executive Order 12564 and Public Law 100-71. Reasonable Accommodation (RA) Requests: If you believe you have a disability (i.e., physical or mental), covered by the Rehabilitation Act of 1973 as amended that would interfere with completing the USA Hire Competency Based Assessments, you will be granted the opportunity to request a RA in your online application. Requests for RA for the USA Hire Competency Based Assessments and appropriate supporting documentation for RA must be received prior to starting the USA Hire Competency Based Assessments. Decisions on requests for RA are made on a case-by-case basis. If you meet the minimum qualifications of the position, after notification of the adjudication of your request, you will receive an email invitation to complete the USA Hire Competency Based Assessments, based on your adjudication decision. You must complete all assessments within 48 hours of receiving the URL to access the USA Hire Competency Based Assessments if you received the link after the close of the announcement. To determine if you need a RA, please review the Procedures for Requesting a Reasonable Accommodation for Online Assessments.