[İş Radarı](https://jobradar.live/) / [Jobs](https://jobradar.live/ilanlar) / Senior IT Specialist

Active
Hybrid
District of Columbia, District of Columbia
Posted · 22.09.2026
USAJOBS

# Senior IT Specialist

Office of Inspector General

The Office of Inspector General (OIG), works within the U. S. Department of Transportation (DOT) to prevent or stop waste, fraud and abuse in departmental programs. The OIG also consults with the Congress about programs in progress and proposed new laws and regulations. The OIG carries out its mission by issuing audit reports, evaluations, and management advisories with findings and recommendations to improve program delivery and performance.
This position is located in the Office of Inspector General, Principal Assistant Inspector General for Auditing and Evaluation, Assistant Inspector General for Financial, Information Technology and Procurement Audits. The incumbent is responsible for the planning, leading, supervision of highly complex analyses, assessments, audits and evaluations of sensitive information systems, information technology methods, controls and strategies, policies and procedures, and management practices. This includes providing independent assessments to determine the adequacy of the Department of Transportation's cybersecurity posture for its systems, networks, telecommunications infrastructures, operational practices, utilization of information technology system resources, cyber-security operations to determine its efficiency and compliance with laws, regulations, policies, and/or contract; by conducting activities related to the detection and prevention of fraud, waste, and abuse. As an Senior IT Specialist you will: Provide technical skills, advice, guidance, and recommendations to management and other JA staff on critical IT security issues and makes decisions or recommendations that significantly influence important IT security policies and programs within DOT. The incumbent also provides strategic budget planning and Contracting Officer's Representative (COR) duties including contract administration, conducts risk assessments and penetration testing, prioritizes assets, allocates IT resources, and implements security measures in support of the JA-20 Lab. Be responsible for conducting the performance of audits and serving as the senior IT specialist on an OIG Red Team by leading red team operations/penetration tests, social engineering campaigns and physical penetration of DOT modes to determine the effectiveness of organizations, IT programs and activities, and examining whether an entity is complying with all applicable laws and regulations. Be responsible for performing and supporting team members that perform all phases of audit work in which red team engagements are performed including planning the audit and defining engagement scopes, managing testing timelines, overseeing junior testers and preparing the audit report. The incumbent must ensure that all phases of the audit are done in accordance with generally accepted Government auditing standards. Lead in developing annual and long-range IT audit plans, provides technical advice, hands-on practical training and guidance to subordinate staff for red team/penetration test activities, audit activities and coordination functions, and maintains close liaisons with Department program and management officials in the areas of assigned responsibility. Be responsible for creating, monitoring, renewing, and getting approval of the budget plan to ensure efficient allocation of resources for hardware, cybersecurity software, training, and contracts. Plan and design the architecture of the lab and other services to support secure and scalable operations to include hardware, software, networking (such as routing and switches), security, and virtual machines. Support report preparation and ensures effectiveness of presentation, adequacy of supporting data, and conformance with policies and standards. Conducts site visits to make sure that audits are being performed and supervised in an effective and timely manner. Develop quality technical vulnerability assessments and penetration testing reports to create executive-level summaries for non-technical agency stakeholders. Provide technical supports and serves as an Information System Security Officer (ISSO) for the JA-20 Lab while achieving and maintaining an Authority to Operate (ATO) for the OIG Lab General Support System (GSS) infrastructure. Be required to lead the preparation of Congressional testimony. This includes leading (1) the preparation of the written and oral statements, (2) the research and assembly of supporting documentation, and (3) quality of the product all within established timeframes.
All documents must be received, and eligibility requirements must be met by the closing date of the announcement. Your resume must be well documented with the specialized experience, otherwise you may be deemed ineligible. To meet the minimum qualifications for this position, you must meet the Basic Education Requirements & Specialized Experience qualifications for the grade(s) at which you are requesting consideration. Applicants must meet qualifications and time-in-grade requirements by the closing date of this vacancy announcement. To be eligible, applicants must meet the basic education and/or experience requirements below. Specialized Experience GS-14: To qualify, you must have at least one year of specialized experience equivalent to the GS-13 grade level in the federal service including: expert knowledge of wide range of IT concepts, theory, computer methods and procedures; expert knowledge applying cyber- security and information security principles and concepts sufficient to plan, coordinate, and assess IT security operations and the security of data, networks, systems and applications; providing technical advice and guidance regarding IT security issues; conducting penetration testing, red teaming, audits and/or assessments of IT programs; conducting interviews with officials; conducting comprehensive analysis and studies requiring the application of complex analytical and statistical methods and techniques; and preparing audit assessment reports. Experience in security penetration testing experience within enterprise or government environments (red teaming, cloud security, application security, mobile security and/or network security) Proven experience utilizing at least 3 of the following cybersecurity tools: Metasploit Pro, Kali Linux, Netsparker, Core Impact, Tenable, Burp Suite, AppDetective Proven Experience utilizing common testing frameworks such as the NIST 800-115, NIST 800-53A, DoD 8140 / 8570, and/or the MITRE ATT&CK frameworks conducting penetration testing Experience with server administration, TCP/IP networking, vulnerability identification and exploitation, vulnerability exploit code development, offensive security operation coordination and communication, vulnerability tracking and remediation, mobile testing And Experience Experience must be IT related; the experience may be demonstrated by paid or unpaid experience and/or completion of specific, intensive training (for example, IT certification), as appropriate GS-12 through GS-15 (or equivalent): For all positions individuals must have IT-related experience demonstrating each of the competencies listed below. The employing agency is responsible for identifying the specific level of proficiency required for each competency at each grade level based on the requirements of the position being filled. Attention to Detail
• Is thorough when performing work and conscientious about attending to detail. Customer Service
• Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. Decision Making
• Makes sound, well-informed, and objective decisions; perceives the impact and implications of decisions; commits to action, even in uncertain situations, to accomplish organizational goals; causes change. Information Management
• Identifies a need for and knows where or how to gather information; organizes and maintains information or information management systems. Interpersonal Skills
• Shows understanding, friendliness, courtesy, tact, empathy, concern, and politeness to others; develops and maintains effective relationships with others; may include effectively dealing with individuals who are difficult, hostile, or distressed; relates well to people from varied backgrounds and different situations Oral Communication
• Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. Problem Solving
• Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. Teamwork
• Encourages and facilitates cooperation, pride, trust, and group identity; fosters commitment and team spirit; works with others to achieve goals. Technical Competence – Uses knowledge that is acquired through formal training or on-the-job experience to perform one's job; works with, understands, and evaluates technical information related to the job; advises others on technical issues. Your resume will be evaluated based on the following competencies: 1. Audit Planning and Execution
• Knowledge of audit planning and execution techniques using the GAGAS standard, the NIST Risk Management Framework (RMF) and other federal cybersecurity laws, publications, methods, principles, and information technology-based guidance to accomplish audit objectives through combined technical and administrative IT, privacy and cybersecurity program oversight. 2. Audit or Topic Specific Knowledge
• Comprehensive knowledge of transportation related topics and the principles and policies of area(s) of responsibility to provide guidance and leadership in carrying out programs and strategies and to ensure policies and plans include a long-term outlook consistent with agency needs. 3. Written Communication
• Relevant audit or professional writing experience, with demonstrated recognition for writing skills and efficiency. 4. Oral Communication
• Relevant oral communication experience, with demonstrated recognition for oral skills and efficiency or extensive experience communicating with high level officials. 5. Critical Thinking and Analytical Skills
• Experience in both critical thinking and analytical skills, including conducting audit analysis. 6. Teamwork/Working Relationships
• Experience in both teamwork and effective working relationships which resulted in successful project completion. Preferred Qualifications: One or more of the following industry certifications or any equivalent: o GPEN (GIAC Penetration Tester) o GXPN (GIAC Exploit Researcher and Advanced Penetration Tester) o OSCP / OSCP+ (OffSec Certified Professional) o CPENT (Certified Penetration Testing Professional) o CEH (Certified Ethical Hacker)
Federal employees must meet Time-In-Grade (TIG) requirements for merit promotion consideration. TIG is the 52-week requirement Federal employees in competitive service, General Schedule (GS) positions at GS-5 and above must serve before they are eligible for promotion to the next grade level. Applicants must meet qualifications and time-in-grade requirements by the closing date of this announcement.

This job was verified from USAJOBS. Applications are completed on the original source.

[Apply on the original listing ↗](https://jobradar.live/ilan/ad9f83de-e5f7-477d-92c9-83022af54278/git)

## Stop searching one by one for roles like this.

Upload your resume or enter your target roles to see your first 3 matches for free.

[Find jobs for me →](https://jobradar.live/uye/kayit)
Your resume is never shared with employers; it is processed only for matching.

Something wrong with this job?
