Telework eligibleFederal

Security Operations and Incident Response Lead

Office of the Chief Information Officer · General Services Administration

Information Technology Management

Salary
$127,829–$187,093/year
Grade
14
Work location
Telework eligible · Lakewood, Colorado; Washington, District of Columbia; Kansas City, Missouri +3 more
Schedule
Full-time
Posted
Sep 30, 2026
Apply by
Oct 6, 2026
Category
Information Technology Management

Apply on USAJOBS →

Source: USAJOBS. Applications happen on the original posting, not on this site.

Summary

As a Security Operations and Incident Response Lead, you will act as the Cyber Incident Commander for any serious IT security incidents. Location of position: The Office of the Chief Information Security Officer is responsible for delivering secure and exceptional technology solutions and experiences to GSA. Position can be filled in any of the following locations: Kansas City, MO; Fort Worth, TX; Washington, DC; Tacoma, WA; Lakewood, CO or Raleigh, NC.

Duties

We are currently filling two vacancies, but additional vacancies may be filled as needed. As a Security Operations and Incident Response Lead you will perform the following duties: Leads GSA's combined Incident Response/Security Operations Center (SOC) program, provides incident handling and digital forensics services (including forensics in virtualized environments), which includes documenting, tracking, and reporting all security incidents in accordance with GSA policy and Cybersecurity and Infrastructure Security Agency (CISA). Leads the GSA SOC and GSA Threat Hunting team to direct and analyze internal threat hunts and ensure ongoing monitoring for security alerting across the GSA Enterprise; works to generate alerting and hunting processes to the benefit of the GSA Enterprise; automates repetitive processes as necessary; monitors and ensures alerting from GSA Data Loss Prevention tools (Zscaler, Cloudlock etc.). Provides security consulting and threat hunt support for GSAIT information systems and emerging IT and IT Security initiatives, including but not limited to: Cloud computing, bring-your-own-device (BYOD), Virtual Desktop Infrastructure, mobile devices, Remote Access Systems, Mobile Computing Platforms, Active Directory, System Virtualization, physical access control systems (building security), Zero Trust and identity and access management solutions; ensuring new technologies are implemented in support of GSA risk management strategy and shaping ongoing incident response and recovery policies. Provides technical expertise and advice on the restructuring and/or re-architecting of GSA networks to ensure the remediation of identified security risks to provide the maximum protection of various types of sensitive Government data. Supports automation and integrations as well as deploys and pilots new Security toolsets in support of GSA Enterprise security operations.

Requirements

If selected, you must meet the following conditions: Current or Former Political Appointees: The Office of Personnel Management (OPM) must authorize employment offers made to current or former political appointees. If you are currently, or have been within the last 5 years, a political Schedule A, Schedule C or Non­Career SES employee in the Executive Branch, you must disclose this information to the HR Office. Failure to disclose this information could result in disciplinary action including removal from Federal Service. Serve a one year probationary period, if required. Undergo and pass a background investigation (Tier 5 investigation level). You must be granted this clearance before you can start the job. Have your identity and work status eligibility verified if you are not a GSA employee. We will use the Department of Homeland Security's e-Verify system for this. Any discrepancies must be resolved as a condition of continued employment. Complete a financial disclosure report to verify that no conflict, or an appearance of conflict, exists between your financial interest and this position. Any applicant tentatively selected for this position will be required to submit to urinalysis to screen for illegal drug use prior to appointment. Appointment to the position will be contingent upon a negative drug test result.

Education

There is no substitution of education for experience at the GS-14 level.

How you will be evaluated

Your application will be evaluated against the basic qualifications which includes any specialized experience and/or education requirements (if applicable). Qualified candidates will be considered in accordance with the Office of Personnel Management Direct Hire Guidelines. Applications will not be rated or ranked. Veterans' Preference is not applicable to the direct hire recruitment procedures. Failure to submit a complete application or missing required supporting documentation may result in you not being considered for the position. Falsification of your background, education, and/or experience is grounds for non-selection or dismissal if hired. SME Resume Review: Subject Matter Experts (SMEs) will evaluate your resume to determine your qualifications for this position using a pass/fail process. ICTAP/CTAP Candidates: The Interagency Career Transition Assistance Plan (ICTAP) and Career Transition Assistance Plan (CTAP) provide eligible displaced Federal competitive service employees with selection priority over other candidates for competitive service vacancies. To be qualified you must submit appropriate documentation (a copy of the agency notice, your most recent performance rating, and your most recent SF-50 noting current position, grade level, and duty location) and be found “well-qualified" for this vacancy. In addition to meeting the basic qualifications stated in the qualification section of this announcement, well qualified is defined as: experience that exceeds the minimum qualifications of the position, demonstrated by meeting at least 3 out of 5 KSA's listed below: Skill in advising clients on complex mission requirements by applying advanced IT security frameworks to deliver efficient, secure solutions and guide high-level policy initiatives. Skill in applying qualitative and/or quantitative methods for the assessment and improvement of an IT Security program effectiveness. Knowledge of IT Security, its governing laws, regulations, methodologies and/or policies to provide sound and authoritative technical guidance on all issues related to an assigned program. Skill in analyzing and integrating complex research, technical, and policy information needed to address high priority, sensitive, and visible issues and derive solutions impacting security and resiliency of information and communications technology. Knowledge of Information Technology Security and software programming techniques to support automation integration and application of experimental theories and new developments to problems not susceptible to treatment by accepted methods. Demonstration of these KSA's must be supported by your resume. You may preview questions for this vacancy.

About this listing

Office of the Chief Information Officer has 1 open listing on the site. This one is telework eligible, based in Lakewood, Colorado and 5 other locations. See all Office of the Chief Information Officer listings, or read what fully remote and telework eligible mean.

Advertised pay is $127,829 to $187,093 a year. That covers GS-14 on the General Schedule, where pay also depends on step and locality; how GS pay works.

This announcement is open for 6 days, from Sep 30, 2026 to Oct 6, 2026. Among currently open Information Technology Management postings, the typical advertised window is about 13 days. As of Oct 6, 2026, it closes today.

Who can apply: the public (U.S. citizens). The announcement's "This job is open to" section has the exact eligibility rules.

Similar open roles

Context computed from the GovRemoteJobs inventory as of Oct 6, 2026, refreshed daily.

Check your resume against this job

Rule-based, on-device analysis — your resume text is never sent to our servers or stored anywhere. Not a substitute for professional resume review.