Fresh Listing

Posted: March 6, 2026 (0 days ago)

This job was posted recently. Fresh listings typically have less competition.

Information Security Specialist

Centers for Medicare & Medicaid Services

Department of Health and Human Services

Fresh

Location

Salary

$143,913 - $187,093

per year

Closes

March 13, 2026More HHS jobs →

Job Description

Summary

This job involves protecting the government's health IT systems by managing risks in the supply chain for technology purchases, ensuring contracts are secure and threats are minimized.

You'll develop processes to assess vulnerabilities in software and services, coordinate with other agencies, and recommend improvements to safeguard national security.

It's a great fit for experienced cybersecurity professionals with a background in federal contracting and risk analysis who enjoy strategic planning and policy work.

Key Requirements

  • At least one year of specialized experience equivalent to GS-13 level in federal or private sector
  • Developing and implementing Supply Chain Risk Management (SCRM) and ICT Cyber-SCRM (CSCRM) programs
  • Reviewing ICT Cyber-Supply Chain Risk Management (C-SCRM) contracts to ensure compliance with requirements
  • Implementing security measures for Information and Communications Technology (ICT) supply chains, focusing on connected software applications
  • Coordinating enterprise-wide and inter-agency processes for analyzing ICT and CSCRM transactions and contracts
  • Conducting C-SCRM risk assessments, identifying vulnerabilities, threats, and national security impacts
  • Monitoring, prioritizing, and mitigating ICT supply chain risks across the organization

Full Job Description

This position is located in the Department of Health & Human Services (HHS), Centers for Medicare & Medicaid Services (CMS), Office of Information Technology (OIT), Information Security and Privacy Group (ISPG), Div of Strategic Information.

As a Information Security Specialist, GS-0080-14, you will you will be responsible for developing, coordinating, and planning a wide range of work methods or improvement of complex processes such as integration of the ICTC-SCRM Acquisition Security program.

ALL QUALIFICATION REQUIREMENTS MUST BE MET BY THE CLOSING DATE OF THIS ANNOUNCEMENT.

Your resume (limited to no more than 2 pages) must include detailed information as it relates to the responsibilities and specialized experience for this position.

Evidence of copying and pasting directly from the vacancy announcement without clearly documenting supplemental information to describe your experience will result in an ineligible rating.

This will prevent you from being considered further.

In order to qualify for the GS-14, you must meet the following: You must demonstrate in your resume at least one year (52 weeks) of qualifying specialized experience equivalent to the GS-13 grade level in the Federal government, obtained in either the private or public sector, to include: 1) Developing and implementing a Supply Chain Risk Management (SCRM) and Information Communications Technology (ICT) Cyber-SCRM (CSCRM) program; 2) Reviewing Information Communications Technology (ICT) Cyber-Supply Chain Risk Management (C-SCRM) contracts to ensure that requirements are met; AND 3) Implementing requirements for securing the Information and Communications Technology and Services Supply Chain with specific emphasis on connected software applications.

Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional, philanthropic, religious, spiritual, community, student, social).

Volunteer work helps build critical competencies, knowledge, and skills, and can provide valuable training and experience that translates directly to paid employment.

You will receive credit for all qualifying experience, including volunteer experience.

Click the following link to view the occupational questionnaire: https://apply.usastaffing.gov/ViewQuestionnaire/12904500 Major Duties:

  • Coordination and policy development of an enterprise wide and inter-agency process for the analysis of transactions of all work and contract actions related to ICT and CSCRM functions.
  • Develop the methods and processes to conduct C-SCRM risk assessments and impacts to national security risks and foreign influence for all CMS ICT contract actions.
  • Develop criteria for evaluating the effectiveness of the systems and makes recommendations which improve/update existing operations.
  • Establish a process to assess and manage ICT supply chain risks, identify vulnerabilities and threats throughout the ICT supply chain lifecycle, and analyzes the impact of those vulnerabilities and threats.
  • Monitor ICT supply chain risks, and prioritizes and mitigates identified risks based on criticality across the organization.

Check your resume before applying to catch common mistakes

Browse Similar Jobs

Posted on USAJOBS: 3/6/2026 | Added to FreshGovJobs: 3/7/2026

Source: USAJOBS | ID: CMS-OIT-26-12904500-DE