Senior IT Specialist
Apply
Position ID:
JA-20-2026-0003
City:
District of Columbia, District of Columbia
Date Posted:
2026-09-22
Expiration Time:
2026-10-06
Job Type:
This is a full-time position.
Job Category:
Information Technology Management
Salary:
143913 - 187093 PA
Job Summary
The Office of Inspector General (OIG), works within the U. S. Department of Transportation (DOT) to prevent or stop waste, fraud and abuse in departmental programs. The OIG also consults with the Congress about programs in progress and proposed new laws and regulations. The OIG carries out its mission by issuing audit reports, evaluations, and management advisories with findings and recommendations to improve program delivery and performance.
Job Description
All documents must be received, and eligibility requirements must be met by the closing date of the announcement. Your resume must be well documented with the specialized experience, otherwise you may be deemed ineligible. To meet the minimum qualifications for this position, you must meet the Basic Education Requirements & Specialized Experience qualifications for the grade(s) at which you are requesting consideration. Applicants must meet qualifications and time-in-grade requirements by the closing date of this vacancy announcement. To be eligible, applicants must meet the basic education and/or experience requirements below. Specialized Experience GS-14: To qualify, you must have at least one year of specialized experience equivalent to the GS-13 grade level in the federal service including: expert knowledge of wide range of IT concepts, theory, computer methods and procedures; expert knowledge applying cyber- security and information security principles and concepts sufficient to plan, coordinate, and assess IT security operations and the security of data, networks, systems and applications; providing technical advice and guidance regarding IT security issues; conducting penetration testing, red teaming, audits and/or assessments of IT programs; conducting interviews with officials; conducting comprehensive analysis and studies requiring the application of complex analytical and statistical methods and techniques; and preparing audit assessment reports. Experience in security penetration testing experience within enterprise or government environments (red teaming, cloud security, application security, mobile security and/or network security) Proven experience utilizing at least 3 of the following cybersecurity tools: Metasploit Pro, Kali Linux, Netsparker, Core Impact, Tenable, Burp Suite, AppDetective Proven Experience utilizing common testing frameworks such as the NIST 800-115, NIST 800-53A, DoD 8140 / 8570, and/or the MITRE ATT&CK frameworks conducting penetration testing Experience with server administration, TCP/IP networking, vulnerability identification and exploitation, vulnerability exploit code development, offensive security operation coordination and communication, vulnerability tracking and remediation, mobile testing And Experience Experience must be IT related; the experience may be demonstrated by paid or unpaid experience and/or completion of specific, intensive training (for example, IT certification), as appropriate GS-12 through GS-15 (or equivalent): For all positions individuals must have IT-related experience demonstrating each of the competencies listed below. The employing agency is responsible for identifying the specific level of proficiency required for each competency at each grade level based on the requirements of the position being filled. Attention to Detail - Is thorough when performing work and conscientious about attending to detail. Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. Decision Making - Makes sound, well-informed, and objective decisions; perceives the impact and implications of decisions; commits to action, even in uncertain situations, to accomplish organizational goals; causes change. Information Management - Identifies a need for and knows where or how to gather information; organizes and maintains information or information management systems. Interpersonal Skills - Shows understanding, friendliness, courtesy, tact, empathy, concern, and politeness to others; develops and maintains effective relationships with others; may include effectively dealing with individuals who are difficult, hostile, or distressed; relates well to people from varied backgrounds and different situations Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. Teamwork - Encourages and facilitates cooperation, pride, trust, and group identity; fosters commitment and team spirit; works with others to achieve goals. Technical Competence – Uses knowledge that is acquired through formal training or on-the-job experience to perform one's job; works with, understands, and evaluates technical information related to the job; advises others on technical issues. Your resume will be evaluated based on the following competencies: 1. Audit Planning and Execution - Knowledge of audit planning and execution techniques using the GAGAS standard, the NIST Risk Management Framework (RMF) and other federal cybersecurity laws, publications, methods, principles, and information technology-based guidance to accomplish audit objectives through combined technical and administrative IT, privacy and cybersecurity program oversight. 2. Audit or Topic Specific Knowledge - Comprehensive knowledge of transportation related topics and the principles and policies of area(s) of responsibility to provide guidance and leadership in carrying out programs and strategies and to ensure policies and plans include a long-term outlook consistent with agency needs. 3. Written Communication - Relevant audit or professional writing experience, with demonstrated recognition for writing skills and efficiency. 4. Oral Communication - Relevant oral communication experience, with demonstrated recognition for oral skills and efficiency or extensive experience communicating with high level officials. 5. Critical Thinking and Analytical Skills - Experience in both critical thinking and analytical skills, including conducting audit analysis. 6. Teamwork/Working Relationships - Experience in both teamwork and effective working relationships which resulted in successful project completion. Preferred Qualifications: One or more of the following industry certifications or any equivalent: o GPEN (GIAC Penetration Tester) o GXPN (GIAC Exploit Researcher and Advanced Penetration Tester) o OSCP / OSCP+ (OffSec Certified Professional) o CPENT (Certified Penetration Testing Professional) o CEH (Certified Ethical Hacker)