Skip to main content
U.S. flag
Back to results
 

Lead Cloud Security Engineer (Information Security)

General Services Administration
Technology Transformation Service

Summary

As a Lead Cloud Security Engineer, you will serve as a definitive subject matter expert contributing to FedRAMP efforts to ensure commercial cloud services and information systems are meeting FedRAMP requirements.

Location of position: This position is located in 1800 F Street NW, Washington DC with the Federal Risk and Authorization Management Program (FedRAMP) Division’s Security Branch.

We are currently filling four vacancies, but additional vacancies may be filled as needed.

Overview

Help
Accepting applications
Open & closing dates
05/04/2026 to 05/11/2026
This job will close when we have received 400 applications which may be sooner than the closing date. Learn more
Salary
$169,279 - $197,200 per year

If you are a new federal employee, your starting salary will likely be set at the Step 1 of the grade for which you are selected.

Pay scale & grade
GS 15
Location
4 vacancies in the following location:
Washington, DC
Remote job
No
Telework eligible
Yes—This position is full-time in the office. In rare instances, situational telework may be approved on a case-by-case basis.
Travel Required
Occasional travel - Occasion travel may be required to attend training or conferences.
Relocation expenses reimbursed
No
Appointment type
Permanent
Work schedule
Full-time
Service
Competitive
Promotion potential
15
Supervisory status
No
Security clearance
Not Required
Drug test
No
Position sensitivity and risk
High Risk (HR)
Trust determination process
Financial disclosure
Yes - You will be required to complete a financial disclosure report to verify that no conflict, or an appearance of conflict, exists between your financial interests and this position.
Bargaining unit status
No
Announcement number
Q2-2026-0006
Control number
867607100

Duties

Help

  • Leads risk and vulnerability assessments of governmentwide planned and installed information systems within the scope of Federal Risk and Authorization Management Program (FedRAMP) to identify vulnerabilities, risks, and protection needs.
  • Provides continuous monitoring support for commercial cloud service information systems, emerging IT, and IT security initiatives, including but not limited to: cloud computing, bring-your-own-device, container security, subnetting best practices, Plan of Action & Milestones (POA&M) management, penetration testing, vulnerability scanning, remote access systems, mobile computing platforms, system virtualization, and identity and access management solutions.
  • Acts as a senior subject matter expert for specific cloud services and provides expert advice to governmentwide stakeholders on the security posture of the service, secure use of the service, and recommendations for deployment.
  • Ensures new technologies are implemented following IT security engineering standards, integrated with agency strategic IT and IT security architecture, and free of gaps in security.
  • Supports security measures and goals set by the FedRAMP board and FedRAMP Program Management Office, promoting IT security awareness by receiving information system security alerts, advisories, and directives from various sources; generating internal security alerts, advisories, and directives as deemed necessary; and disseminating security alerts, advisories, and directives to internal and external enterprise entities with IT system security responsibility.

Requirements

Help

Conditions of employment

  • US Citizens and National (Residents of American Samoa and Swains Island)
  • Meet all eligibility criteria within 30 days of the closing date
  • Register with Selective Service if you are a male born after 12/31/1959

If selected, you must meet the following conditions:

  • Current or Former Political Appointees: The Office of Personnel Management (OPM) must authorize employment offers made to current or former political appointees. If you are currently, or have been within the last 5 years, a political Schedule A, Schedule C or Non­Career SES employee in the Executive Branch, you must disclose this information to the HR Office. Failure to disclose this information could result in disciplinary action including removal from Federal Service.
  • Serve a one year probationary period, if required.
  • Undergo and pass a background investigation (Tier 4 investigation level).
  • Have your identity and work status eligibility verified if you are not a GSA employee.  We will use the Department of Homeland Security’s e-Verify system for this. Any discrepancies must be resolved as a condition of continued employment.
  • Complete a financial disclosure report to verify that no conflict, or an appearance of conflict, exists between your financial interest and this position.

Qualifications

For each job on your resume, provide:

  • the exact dates you held  each job (from month/year to month/year)
  • number of hours per week you worked (if part time).    

If you have volunteered your service through a National Service program (e.g., Peace Corps, Americorps), we encourage you to apply and include this experience on your resume.

The GS-15 salary range starts at $169,279.00 per year.   

If you are a new federal employee, your starting salary will likely be set at the Step 1 of the grade for which you are selected.  

Applicants applying for the GS-15 grade level must meet the following requirements: Have IT-related experience demonstrating EACH of the four competencies AND one year of specialized experience equivalent to the GS-14 level in the Federal service as described below:

IT SPECIALIST COMPETENCY REQUIREMENTS:

Attention to Detail - This skill is generally demonstrated by assignments where the applicant investigates and evaluates “state of the art” technology of the industry.

Customer Service - This skill is generally demonstrated by assignments where the applicant confers with users to evaluate the effectiveness of, or identify the need for, computer programs or management systems.

Oral Communication - This skill is generally demonstrated by assignments where the applicant persuades others to take a particular course of action or to accept findings, recommendations, changes, or alternative viewpoints.

Problem Solving - This skill is generally demonstrated by assignments where the applicant identifies and accommodates technology and resource constraints.

SPECIALIZED EXPERIENCE REQUIREMENTS: 

Specialized experience is defined as: Senior-level experience within a security, compliance, infrastructure, or similar engineering function for a cloud service offering that provides on-demand self-service access to technology resources over the internet; OR as a lead assessor within a Third Party Assessment Organization (3PAO) conducting comprehensive security assessments of cloud service offerings against Federal Risk and Authorization Management Program (FedRAMP) requirements.

Must present evidence of experience as follows:

  • Designing, operating, or evaluating complex multi-tenant cloud environments in strict adherence to FedRAMP-specific mandates.
  • Leading risk-based technical decision-making for cloud deployments or assessments
  • Assessing, operating, or implementing Governance, Risk, and Compliance (GRC) engineering principles, such as: Automation of security control validation, Implementation of policy-as-code, Utilization of machine-readable artifacts to streamline the authorization lifecycle and continuous monitoring processes.

Education

This job does not have an education qualification requirement.

Additional information

Candidates will not be hired based on their race, sex, color, religion, or national origin.

Applicants are encouraged to make their resume searchable in their USAJOBS.gov profile. This will allow Federal hiring specialists and hiring managers across agencies to find their resume as part of agency recruitment campaigns or staffing searches.

If you apply to this position and are selected, we will not ask about your criminal history before you receive a conditional job offer. If you believe you were asked about your criminal history improperly, contact the agency or visit GSA's webpage.

Relocation-related expenses are not approved and will be your responsibility.  

On a case-by-case basis, the following incentives may be approved:

·       Recruitment incentive if you are new to the federal government

·       Relocation incentive if you are a current federal employee

·       Credit toward vacation leave if you are new to the federal government

Additional vacancies may be filled through this announcement in this or other GSA organizations within the same commuting area as needed; through other means; or not at all.

Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution.

How you will be evaluated

You will be evaluated for this job based on how well you meet the qualifications above.

A panel of Subject Matter Experts (SMEs) will review the resumes of qualified candidates and assign a score for each of the five required Knowledge, Skills, and Abilities (KSAs) based on the experience documented in the resume and narrative responses:

  1. Expert knowledge of NIST SP 800-53 security controls, FedRAMP authorization frameworks, and Governance, Risk, and Compliance (GRC) engineering principles, including the application of automation for security assessment and continuous monitoring.
  2. Mastery of knowledge of cloud-native infrastructure and site reliability principles, enabling the evaluation of security implementations and automated vulnerability detection in complex, multi-tenant cloud environments.
  3. Mastery of and skill of cloud-native security architectures, immutable infrastructure, and complex shared responsibility models to provide authoritative recommendations to executive-level stakeholders on the secure implementation of cloud services.
  4. Expert knowledge of secure systems engineering principles and GRC engineering workflows to integrate emerging technologies into security architectures.
  5. Knowledge of FedRAMP security measures and goals, emerging cloud vulnerabilities, and related ways to identify risks impacting commercial cloud services.

Demonstration of these KSAs must be supported by your resume. Applicants should also make note of each KSA, as you will be asked to address them later in the application process

Your possession of the KSAs will place you in one of the following categories:.

  • Best Qualified = 4+ out of 5 KSAs  
  • Well Qualified = 3 out of 5 KSAs (Well Qualified for CTAP/ICTAP) 
  • Qualified = 2 or less out of 5 KSAs.

If you are eligible under the Interagency Career Transition Assistance Plan (ICTAP) or GSA’s Career Transition Assistance Plan (CTAP), your resume must clearly demonstrate experience in at least 3 of the 5 required Knowledge, Skills, and Abilities (KSAs) to receive priority consideration.


You may preview questions for this vacancy.

Technology Transformation Service

Agency contact information

Elvis Zdionica
Phone
607-972-4223
Fax
000-000-0000
Email
Elvis.Zdionica@gsa.gov
Address
GSA, Technology Transformation Service
Servicing HR Office: Branch A
GSA, Office of Human Resources Management (OHRM)
1800 F Street, NW
Washington, District of Columbia 20405
United States

Visit our careers page

Learn more about what it's like to work at Technology Transformation Service, what the agency does, and about the types of careers this agency offers.

https://www.gsa.gov/about-us

Your session is about to expire!

Your USAJOBS session will expire due to inactivity in 8 minutes. Any unsaved data will be lost if you allow the session to expire. Click the button below to continue your session.