Skip to main content
U.S. flag
 

Senior Cloud Security Engineer (Information Security)

General Services Administration
Technology Transformation Service

Summary

As a Senior Cloud Security Engineer, you will be the subject matter expert contributing to FedRAMP efforts to ensure commercial cloud services and information systems are meeting FedRAMP requirements. 

Location of position: This position is located in 1800 F Street NW, Washington DC with the Federal Risk and Authorization Management Program (FedRAMP) Division’s Security Branch. 

We are currently filling 3 vacancies, but additional vacancies may be filled as needed.

Overview

Help
Posted today · Apply by 06/09/26
Due by 11:59 p.m. ET on June 9, 2026
This job will close when we have received 400 applications which may be sooner than the closing date. Learn more
Location
3 vacancies in the following location:
Work site options
Telework eligible
Yes—This position is full-time in the office. In rare instances, situational telework may be approved on a case-by-case basis.
Remote job
No
Relocation expenses reimbursed
No
Salary
$143,913 - $187,093 per year

If you are a new federal employee, your starting salary will likely be set at the Step 1 of the grade for which you are selected.

Pay scale & grade
GS 14
Promotion potential
14
Pay scale and grade determines the salary of the job.
Work schedule
Full-time
Travel Required
Occasional travel - Occasion travel may be required to attend classes or conferences.
Appointment type
Term - Term Appointment NTE 2 Years
Occupations and job series
Supervisory status
No
Federal service type
This job is in the Competitive Service
Represented by a union
No
Drug test
No
Security clearance
Not Required
Position sensitivity and risk
High Risk (HR)
Jobs require a background check and some require a security clearance. The type depends on the job.
Background check type
Financial disclosure required
Yes - You will be required to complete a financial disclosure report to verify that no conflict, or an appearance of conflict, exists between your financial interests and this position.
Some jobs require financial disclosure to identify conflicts of interests.
Announcement number
Q2-2026-0005
Control number
871244100

Duties

Help

  • Conducts risk and vulnerability assessments of governmentwide planned and installed information systems within the scope of Federal Risk and Authorization Management Program (FedRAMP) to identify vulnerabilities, risks, and protection needs. Manages systems security evaluations, audits, and reviews as performed by FedRAMP.
  • Provides continuous monitoring support for commercial cloud service information systems, emerging IT, and IT security initiatives, including but not limited to: cloud computing, bring-your-own-device (BYOD), container security, subnetting best practices, Plan of Action & Milestones (POA&M) management, penetration testing, vulnerability scanning, remote access systems, mobile computing platforms, system virtualization, and identity and access management solutions.
  • Provides recommendations and opinions on the security implementations of cloud services as part of the assessment process. Coordinates with contractors and other staff to gather experiences, opinions, and other analyses; combines collected information; and creates summaries of security decisions and recommendations for management and staff review for governmentwide adoption.
  • Ensures new technologies are implemented following IT security engineering standards, integrated with agency strategic IT and IT security architecture, and free of gaps in security.
  • Stays abreast of threats, vulnerabilities, and developments within the realm of information security, especially emerging issues with the potential to impact federal agency or broader government information systems and networks as well as commercial cloud services.

Requirements

Help

Conditions of employment

  • US Citizens and National (Residents of American Samoa and Swains Island)
  • Meet all eligibility criteria within 30 days of the closing date
  • Register with Selective Service if you are a male born after 12/31/1959

If selected, you must meet the following conditions:

  • Current or Former Political Appointees: The Office of Personnel Management (OPM) must authorize employment offers made to current or former political appointees. If you are currently, or have been within the last 5 years, a political Schedule A, Schedule C or Non­Career SES employee in the Executive Branch, you must disclose this information to the HR Office. Failure to disclose this information could result in disciplinary action including removal from Federal Service.
  • Serve a one year probationary period, if required.
  • Undergo and pass a background investigation (Tier 4 investigation level).
  • Have your identity and work status eligibility verified if you are not a GSA employee.  We will use the Department of Homeland Security’s e-Verify system for this. Any discrepancies must be resolved as a condition of continued employment.
  • Complete a financial disclosure report to verify that no conflict, or an appearance of conflict, exists between your financial interest and this position.

Qualifications

For each job on your resume, provide:

  • the exact dates you held  each job (from month/year to month/year)
  • number of hours per week you worked (if part time).    

If you have volunteered your service through a National Service program (e.g., Peace Corps, Americorps), we encourage you to apply and include this experience on your resume.

The GS-14 salary range starts at $143,913.00 per year.   

If you are a new federal employee, your starting salary will likely be set at the Step 1 of the grade for which you are selected.  

Applicants applying for the GS-14 grade level must meet the following requirements: Have IT-related experience demonstrating EACH of the four competencies AND one year of specialized experience equivalent to the GS-13 level in the Federal service as described below:

IT SPECIALIST COMPETENCY REQUIREMENTS:

Attention to Detail - This skill is generally demonstrated by assignments where the applicant investigates and evaluates “state of the art” technology of the industry.

Customer Service - This skill is generally demonstrated by assignments where the applicant confers with users to evaluate the effectiveness of, or identify the need for, computer programs or management systems.

Oral Communication - This skill is generally demonstrated by assignments where the applicant persuades others to take a particular course of action or to accept findings, recommendations, changes, or alternative viewpoints.

Problem Solving - This skill is generally demonstrated by assignments where the applicant identifies and accommodates technology and resource constraints.

SPECIALIZED EXPERIENCE REQUIREMENTS: 

Specialized Experience is defined as: Coordinating and providing technical advice within a security, compliance, infrastructure, or similar engineering function for a cloud service offering that provides on-demand self-service access to technology resources over the internet; OR as an assessor within a Third Party Assessment Organization (3PAO) conducting comprehensive security assessments of cloud service offerings against Federal Risk and Authorization Management Program (FedRAMP) requirements.

Education

This job does not have an education qualification requirement.

Additional information

Candidates will not be hired based on their race, sex, color, religion, or national origin.

Applicants are encouraged to make their resume searchable in their USAJOBS.gov profile. This will allow Federal hiring specialists and hiring managers across agencies to find their resume as part of agency recruitment campaigns or staffing searches.

If you apply to this position and are selected, we will not ask about your criminal history before you receive a conditional job offer. If you believe you were asked about your criminal history improperly, contact the agency or visit GSA's webpage.

Relocation-related expenses are not approved and will be your responsibility.  

On a case-by-case basis, the following incentives may be approved:

·       Credit toward vacation leave if you are new to the federal government

Additional vacancies may be filled through this announcement in this or other GSA organizations within the same commuting area as needed; through other means; or not at all.

For information on temporary and term appointments go to  USAJOBS Help Center - Appointments

Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution.

How you will be evaluated

You will be evaluated for this job based on how well you meet the qualifications above.

A panel of Subject Matter Experts (SMEs) will review the resumes of qualified candidates and assign a score for each of the five required Knowledge, Skills, and Abilities (KSAs) based on the experience documented in the resume and narrative responses:

  1. Applied knowledge of the NIST SP 800-53 security control framework and FedRAMP requirements; sufficient to technically validate security control implementations in cloud-native environments, analyze output from automated scanning and assessment tools, and coordinate directly with cloud provider engineers to resolve technical gaps in their security authorization packages.
  2. Maintains knowledge of and skill in the most current cloud security, virtualization security, Web application security, network architecture, subnetting best practices, container security, POA&M management, incident handling procedures, vulnerability scanning techniques, and penetration testing techniques.
  3. Knowledge of and related skill in written and verbal communication sufficient to interact with federal government and private industry to maintain and enhance technical knowledge and skills to maintain and expand competencies in the information security arena.
  4. Mastery of and related skill in applying advanced IT principles, concepts, methods, standards, and practices sufficient to contribute to development of and interpret policies, procedures, and strategies governing the planning and delivery of FedRAMP services throughout federal agency operations.
  5. Expert knowledge of IT security areas; governing laws, regulations, methodologies, and/or policies and IT security applications within the federal government sufficient to provide sound and authoritative technical guidance on issues related to assigned FedRAMP functions and advise federal agency personnel in the analysis of complex mission requirements and efficiency and effectiveness in applying IT security to meet such requirements.

Demonstration of these KSAs must be supported by your resume. Applicants should also make note of each KSA, as you will be asked to address them later in the application process

Your possession of the KSAs will place you in one of the following categories:.

  • Best Qualified = 4+ out of 5 KSAs  
  • Well Qualified = 3 out of 5 KSAs (Well Qualified for CTAP/ICTAP) 
  • Qualified = 2 or less out of 5 KSAs.

If you are eligible under the Interagency Career Transition Assistance Plan (ICTAP) or GSA’s Career Transition Assistance Plan (CTAP), your resume must clearly demonstrate experience in at least 3 of the 5 required Knowledge, Skills, and Abilities (KSAs) to receive priority consideration.


You may preview questions for this vacancy.

Technology Transformation Service

Agency contact information

Elvis Zdionica
Phone
607-972-4223
Fax
000-000-0000
Email
Elvis.Zdionica@gsa.gov
Address
GSA, Technology Transformation Service
Servicing HR Office: Branch A
GSA, Office of Human Resources Management (OHRM)
1800 F Street, NW
Washington, District of Columbia 20405
United States

Visit our careers page

Learn more about what it's like to work at Technology Transformation Service, what the agency does, and about the types of careers this agency offers.

https://www.gsa.gov/about-us

Your session is about to expire!

Your USAJOBS session will expire due to inactivity in 8 minutes. Any unsaved data will be lost if you allow the session to expire. Click the button below to continue your session.