GRC Careers: AI Governance, Risk and Compliance JobsConnecting Talent and Trust. Post a Job Log in

JobsMultiple LocationsIT Cybersecurity Specialist (Security)

IT Cybersecurity Specialist (Security)

Centers for Medicare & Medicaid Services
CybersecurityOn-siteFull-timeMultiple Locations$115711 - $158322 Per Year

Centers for Medicare & Medicaid Services is hiring for the job of IT Cybersecurity Specialist (Security), Multiple Locations (On-site). This is a Cybersecurity job in the governance, risk, and compliance field, with a posted range of $115711 - $158322 Per Year. Review the full details below and apply directly with Centers for Medicare & Medicaid Services.

Organization: Centers for Medicare & Medicaid ServicesLocation: Multiple LocationsWorkplace: On-siteFocus: CybersecuritySalary: $115711 - $158322 Per YearPosted: Sep 10, 2026
Centers for Medicare & Medicaid Services is hiring for this Cybersecurity job in Multiple Locations, one of the metros GRC Careers tracks for governance, risk, and compliance hiring.

This position is located in the Department of Health & Human Services (HHS), Centers for Medicare & Medicaid Services (CMS), Office of Information Technology (OIT), Information Security and Privacy Group (ISPG), Division of Security and Privacy Compliance (DSPC). As a IT Cybersecurity Specialist (Security), GS-2210-13, you will secure Software-as-a-Service (SaaS) platforms and cloud-hosted business applications utilized throughout CMS.

Qualifications: ALL QUALIFICATION REQUIREMENTS MUST BE MET BY THE CLOSING DATE OF THIS ANNOUNCEMENT. Your resume (limited to no more than 2 pages) must include detailed information as it relates to the responsibilities and specialized experience for this position. Evidence of copying and pasting directly from the vacancy announcement without clearly documenting supplemental information to describe your experience will result in an ineligible rating. This will prevent you from being considered further. There is a Basic Requirement and Minimum Qualification Requirement for this position. You must meet both requirements. Basic Requirement: You must have IT related experience, demonstrated by paid or unpaid experience obtained in either the private or public sector, and/or completion of specific, intensive training that demonstrates that I possess each of the following four competencies: (1) Attention to Detail - Is thorough when performing work and conscientious about attending to detail. (2) Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. (3) Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. (4) Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. AND In order to qualify for the GS-13, you must meet the following: You must demonstrate in your resume at least one year (52 weeks) of qualifying specialized experience equivalent to the GS-12 grade level in the Federal government, obtained in either the private or public sector, to include: 1) Securing SaaS platforms and cloud-hosted applications (e.g., Microsoft 365, Salesforce, ServiceNow) using SaaS Security Posture Management (SSPM) or Cloud Access Security Broker (CASB) technologies to identify issues - such as misconfigurations, policy violations, and security risks; AND 2) Applying federal cybersecurity frameworks - such as Federal Information Security Modernization Act (FISMA), Federal Risk and Authorization Management Program (FedRAMP), or National Institute of Standards and Technology Risk Management Framework (NIST RMF) - to assess and monitor the compliance posture of cloud environments; AND 3) Developing and integrating automated workflows, scripts, or security tools to manage security findings across a cloud or SaaS environment. Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional, philanthropic, religious, spiritual, community, student, social). Volunteer work helps build critical competencies, knowledge, and skills, and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.

Location and market context

This job is based in Multiple Locations on-site. Local candidates benefit from being close to Centers for Medicare & Medicaid Services's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.

About cybersecurity governance jobs

Cybersecurity governance connects security control frameworks to business and regulatory risk, covering policy, risk assessment, and control assurance rather than hands-on operations. Jobs like this one are typically evaluated against frameworks such as NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices.

How to position yourself for this cybersecurity governance job

Strong candidates emphasize security control frameworks, risk assessment, policy and standards, and translating technical security posture into governance and board-level reporting. In your resume and outreach, tie your experience to how Centers for Medicare & Medicaid Services would apply NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices, and lead with concrete outcomes rather than duties.

Similar GRC jobs

More jobs at Centers for Medicare & Medicaid Services

More GRC jobs in Multiple Locations

Hiring for Cybersecurity?

Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.

Post a job  Pricing from $99 · About GRC Careers · Hiring toolkit

Want to be next in a job like this?

Jobs like IT Cybersecurity Specialist (Security) in Multiple Locations open regularly. Be first to know, privately. No current employer ever sees you looking.

New Cybersecurity jobs, the moment they post.

One click unsubscribe.
Know your GRC? Take the 2-minute AI Governance Challenge. No signup needed.
Play now →

Employer, or see something wrong with this posting? Report this posting and we will review it promptly.