
IT Specialist (2210) federal resume example: GS-12 INFOSEC
A complete two-page resume for a GS-2210-12 IT Specialist (INFOSEC) job, written to OPM’s rules. Below it: what changed in the 2210 qualification standard in April 2026, the competencies you need at each grade, and how announcements word specialized experience.
Updated October 2026. Sources are listed at the end.
- Two pages, US Letter
- Series, grade and hours on every job
- No sign-up
What makes it work
- Every job shows title, employer, month/year dates and hours per week, with series and grade on the federal job. The part-time job says 20 hours, so it’s credited correctly.
- The main job uses the words GS-12 announcements use: Risk Management Framework, authorization packages, POA&Ms, scan and log analysis, advising system owners.
- It shows the level, not just the duty: “lead”, “manage” and results across 14 systems and 2,300 assets point to work done with little guidance, which is what level 4 proficiency means.
- The competencies appear as actions: briefing CIO staff (Oral Communication), deadlines agreed with 6 teams (Teamwork), POA&M tracking for FISMA reports (Information Management).
About IT Specialist (2210) resumes
What the 2210 series covers
The Information Technology Management series, 2210, covers administrative IT jobs that manage, develop, deliver and support IT systems and services, where knowledge of IT principles, concepts and methods is the main requirement. The usual title is IT Specialist; OPM also authorizes IT Cybersecurity Specialist for 2210 jobs that include cybersecurity work.
OPM’s April 2026 classification standard groups the work into three clusters: IT Operations and Security (system administration, networks, customer support, information security), IT Development and Analysis (software, systems analysis, data management) and IT Strategy and Planning (policy, enterprise architecture, IT investment). Jobs built on theoretical computer science or engineering belong in professional series such as Computer Science (1550) instead.
Parenthetical titles: INFOSEC, SYSADMIN and the rest
From 2001, OPM’s job family standard for the IT group set eleven specialty titles for 2210, shown in parentheses after the basic title: Policy and Planning, Enterprise Architecture, Security, Systems Analysis, Applications Software, Operating Systems, Network Services, Data Management, Internet, Systems Administration and Customer Support. Agencies could combine two when both were significant, and use short abbreviations in automated systems. That’s where INFOSEC and SYSADMIN in job titles come from.
The April 2026 standard replaced the job family standard and no longer prescribes parenthetical titles. Agencies may set their own, as long as the position description reflects that work, and many still post titles such as IT Specialist (INFOSEC) or IT Specialist (SYSADMIN/INFOSEC). The parenthetical tells you which work your resume has to prove: for an INFOSEC job, most of your main job’s lines should be about security.
The 2210 qualification standard changed in April 2026
On April 13, 2026, OPM issued a competency-based qualification standard for 2210 that consolidates and replaces the old Alternative A and Alternative B standards. Applicants must meet a minimum proficiency level, on a scale from 1 (Awareness) to 5 (Expert), for each required competency at the grade, as shown through the agency’s assessments. At GS-12 the levels are:
- Attention to Detail, Customer Service, Interpersonal Skills and Teamwork: level 4 (Advanced)
- Information Management: level 4
- Decision Making, Oral Communication, Problem Solving and Technical Competence: level 3 (Intermediate); Problem Solving and Technical Competence rise to 4 at GS-13 and above
- At GS-11: Attention to Detail, Customer Service, Interpersonal Skills, Problem Solving, Teamwork and Technical Competence, all at level 3
Specialized experience, education and certifications
Agencies add technical competencies from their own job analysis, such as Risk Management or Security Incident Management for a security job, and define the specialized experience. OPM says these skills are normally gained through the equivalent of one year of specialized experience at the next lower grade, but may now be gained in other ways. For GS-12, that usually means a year at the GS-11 level.
Some 2026 announcements still list the four competencies from the old Alternative A standard (Attention to Detail, Customer Service, Oral Communication and Problem Solving), so follow the announcement. Education is no longer a minimum qualification, and it didn’t replace experience at GS-12 under the old standard either. Certification, licensure or special training can count as an alternative to experience. Current GS employees should check the announcement for any time-in-grade rule; OPM has proposed eliminating it.
Specialized experience, and the lines that prove it
How announcements for this series commonly describe it, in our words. Always use the wording in the announcement you’re applying to.
Experience applying IT security methods with some guidance: running vulnerability scans and following up on fixes, checking system documentation against NIST security controls, and helping users and system owners resolve security problems.
- Ran monthly Nessus scans of 600 workstations and tracked critical findings with system owners until closed.
- Reviewed 9 system security plans against NIST SP 800-53 controls and drafted corrections for the ISSO.
- Resolved account lockout, encryption and access tickets for 1,200 users.
Experience carrying out the security authorization process for systems with little guidance: assessing controls, preparing authorization packages and POA&Ms, analyzing scan and log data to find and fix weaknesses, and advising system owners on how to meet security requirements.
- Led the Risk Management Framework process for 14 systems; all received a 3-year authorization to operate.
- Cut the average age of critical vulnerabilities from 41 to 12 days across 2,300 assets by setting remediation deadlines with 6 teams.
- Advise project teams at the weekly change board on encryption, logging and access requirements.
Experience acting as a technical authority for a security program: setting policy or architecture across many systems, leading continuous monitoring or incident response, and advising senior managers on risk.
- Wrote the regional continuous monitoring strategy adopted for 40 systems and briefed it to the CIO.
- Led incident response for 3 major incidents, coordinating 5 teams and reporting to the agency SOC.
- Recommended risk acceptance or remediation for 25 high findings in decision memos to the authorizing official.
The example resume, as text
The same content as the PDF, for reading or copying. Replace everything with your own experience.
Avery Castillo, IT Specialist (INFOSEC)
Kansas City, MO · avery.castillo@example.com · (555) 555-0117 · U.S. citizen
Information security specialist with more than eight years in IT, including four years at GS-11 running security authorization, vulnerability management and incident response for federal systems. CISSP certified, with a record of explaining risk in plain terms to system owners and managers. Seeking a GS-2210-12 IT Specialist (INFOSEC) position.
Work experience
IT Specialist (INFOSEC), U.S. Department of Veterans Affairs, Office of Information and Technology, Kansas City, MO
- Lead the Risk Management Framework process for 14 systems: categorize each system, tailor NIST SP 800-53 controls, assess them and assemble the authorization package; all 14 received a 3-year authorization to operate.
- Run weekly authenticated Tenable.sc scans of 2,300 servers and workstations; cut the average age of critical vulnerabilities from 41 to 12 days by agreeing remediation deadlines with 6 system owner teams.
- Built Splunk correlation searches and dashboards for privileged account activity; detected and contained 2 credential misuse incidents in FY2025, both reported within the 1-hour requirement.
- Serve as incident handler for the regional response team: triage alerts, preserve evidence, write incident reports and brief the ISSO and CIO staff on root cause and corrective actions.
- Manage 96 plan of action and milestones (POA&M) items across 14 systems; closed 71 in 18 months and keep the rest current in the agency GRC tool for quarterly FISMA reporting.
- Wrote the office’s Windows Server 2022 security baseline from CIS Benchmarks; compliance rose from 68% to 94% across 410 servers in 9 months.
- Review proposed changes for security impact at the weekly change advisory board and advise project teams on encryption, logging and access control requirements.
Systems Administrator, Northgate Health Systems, Overland Park, KS
- Administered 180 Windows and Linux servers and Active Directory for 2,400 users at 5 hospitals; clinical systems stayed at 99.95% availability for 3 years.
- Automated patching with WSUS and PowerShell, cutting the monthly patch cycle from 10 days to 3.
- Rolled out multifactor authentication for remote access to all 2,400 users and supplied evidence for the annual HIPAA security risk assessment.
- Sent logs from 180 servers to the hospital SIEM and wrote the alert runbook used by the 4-person operations team.
- Restored the patient scheduling system within its 4-hour recovery objective after a 2021 storage failure, using recovery steps I had documented.
IT Support Technician (part-time), Brightwater Community Bank, Lee’s Summit, MO
- Resolved about 40 help desk tickets a week for 3 branches and imaged and deployed 120 workstations.
- Set up accounts, permissions and laptop encryption for new staff under the bank’s access control policy.
Education
- Bachelor of Science, Cybersecurity, University of Central Missouri, 05/2018, GPA 3.5/4.0
Certifications and training
- Certified Information Systems Security Professional (CISSP), ISC2, 06/2023
- CompTIA Security+, CompTIA, 08/2018
- Splunk Core Certified Power User, Splunk, 02/2024
- Hacker Tools, Techniques, and Incident Handling (SEC504), SANS Institute, 10/2023
Skills
- Security frameworks: NIST Risk Management Framework, NIST SP 800-53 Rev. 5, FISMA reporting, CIS Benchmarks
- Tools: Tenable.sc and Nessus, Splunk, Microsoft Defender for Endpoint, PowerShell, Python
- Systems: Windows Server, Red Hat Enterprise Linux, Active Directory, VMware vSphere
Additional information
- Background investigation: Tier 4 public trust, favorably adjudicated 2022
- Awards: Special Contribution Award, 2024, for the Windows Server security baseline
- Languages: Spanish (professional working proficiency)
- Professional organizations: ISC2 member
Mistakes to avoid
- A tool list with no results. “Splunk, Nessus, RMF” proves nothing; what you found, fixed or authorized with them does.
- Duties without the level. For GS-12, show you run the work, not that you “assisted” with it.
- Missing series, grade or hours, so a reviewer can’t credit a federal job as a year at GS-11.
- A parenthetical the resume doesn’t back up, such as applying for INFOSEC with a main job that’s mostly help desk work.
- Questionnaire answers the resume can’t support. If you rate yourself expert in incident response, a resume line has to show it.
- Going over two pages with long skills lists. A resume over the limit isn’t considered.
Check yours before you apply
Upload your resume to count the pages and check every job for month/year dates, hours per week, series and grade. Paste the announcement too, to see which qualifications your resume proves. Free, no account. Starting from scratch? Use the two-page federal resume template.
Questions
What does INFOSEC mean in a GS-2210 job title?
It marks information security work, carried over from the Security specialty in OPM’s old IT job family standard. Since April 2026 OPM no longer prescribes parentheticals for 2210, but agencies can still set them, and INFOSEC remains common in announcements.
What competencies does OPM require for the 2210 series?
At GS-12, the April 2026 standard requires Attention to Detail, Customer Service, Decision Making, Information Management, Interpersonal Skills, Oral Communication, Problem Solving, Teamwork and Technical Competence, each at a set level. Agencies can add technical competencies. Some announcements still use the older four from Alternative A.
Do I need a degree for a 2210 IT Specialist job?
Not as a minimum qualification under OPM’s new 2210 standard. You qualify through the required competencies and specialized experience, or through certification, licensure or special training. Agencies can require a specific credential when their job analysis supports it.
Does private-sector or contractor IT experience count?
Yes. OPM says these skills are typically gained in the IT field or in work where IT is the primary concern, and agencies must give full credit to acceptable experience and training. List it with dates and hours like any other job.
How long can a 2210 federal resume be?
Two pages, the limit for Title 5 jobs on USAJOBS since September 27, 2025. OPM suggests a sans-serif font such as Lato, 0.5-inch margins and 10-point text. Upload a PDF and check the page count.
Sources
- OPM: Competency-Based Qualification Standard for the Information Technology Management Series, 2210
- OPM memo: Competency-Based Qualification Standards for the IT Management Series, 2210 (April 13, 2026)
- OPM: Competency-Based Qualification Standard for 2210, frequently asked questions
- OPM: Competency-Based Classification Standard for the IT Management Series, 2210
- OPM memo: Issuance of the Competency Based Position Classification Standard for 2210 (April 13, 2026)
- OPM: Information Technology (IT) Management Series 2210 (Alternative A), the earlier standard
- OPM: Job Family Standard for Administrative Work in the IT Group, 2200 (titling section)
- OPM: Interpretive Guidance for Cybersecurity Positions
- OPM: OPM Proposes Eliminating Outdated Time-in-Grade Rule
- OPM: Applicant guidance on the two-page resume limit
- OPM: Agency guidance on the two-page limit on resume length
General guidance. The job announcement is the final word on what to submit.