Supervisory Information Technology Specialist/ Pen Tester

Location
District of Columbia, DC; 1 vacancy , United States
Posted
May 19, 2023
Closes
Jun 18, 2023
Ref
726704700
Function
Other
Hours
Full Time
Summary

The Office of Inspector General (OIG), works within the U. S. Department of Transportation (DOT) to promote efficiency and effectiveness, and prevent or stop waste, fraud and abuse in departmental programs. We do this through audits and investigations. OIG also consults with the Congress about programs in progress and proposed new laws and regulations. The Inspector General Act of 1978 gives the Office of Inspector General autonomy to do its work without interference.

Duties

As a Supervisory Information Technology Specialist (INFOSEC)/Senior Red Team Operator you will:

The incumbent of this position works as an information technology specialist and member of a red team responsible for performing penetration tests on networks, Web applications, wireless networks, cloud infrastructure, external network testing, and databases. The incumbent will also perform social engineering and physical breaching. In addition, the incumbent is responsible for performing an objective and systematic examination of records, management reports, management controls, policies and practices affecting or reflecting the operating results of financial and information technology programs. The incumbent works with senior level red teamers/auditors/analysts in providing an independent assessment of the performance of assigned IT programs and conducting activities related to the detection and prevention of fraud, waste, and abuse.

The incumbents major duties and responsibilities will include but not be limited to:
  • Experience identifying and exploiting common web-application vulnerabilities, such as: SQL Injection, DOM Manipulation, Authorization System Bypass, Design Logic issues, bounds checking, role & access validation, and filter evasion.
  • Perform web application testing, mobile application testing, network penetration testing, and source code reviews
  • Utilize attacker tools, tactics, and procedures to perform analysis and identify vulnerabilities,
  • Perform red team operations - exploitation, persistence, and evasion
  • Identify network and system vulnerabilities and misconfigurations likely to be executed by advanced adversaries through the use of threat intelligence and expert employment of emulated adversary tools.
  • Conduct full exploitation operations in Windows and *nix environments
  • Perform innovative research and promote an environment of innovation and knowledge sharing
  • Perform vulnerability assessments and penetration test of DOT IT infrastructure, and provide oversight and governance of organization Red Team Lab to ensure compliance with the Federal Information Security Modernization Act of 2014.
  • Preparing a comprehensive work plan, including the methodology for examining and testing IT programs and systems.
  • Researching pertinent laws, legislative history, regulations, contracts, and internal controls to ascertain the purpose, scope, and objectives of the assigned IT program or system;
  • Reviewing operating systems and/or network configurations;
  • Evaluating software applications and/or systems components, such as web applications and database systems;
  • Performing vulnerability assessments and penetration testing on computer and/or network systems;
  • Analyzing potential vulnerabilities to identify security weaknesses for remediation;
  • Conducting site visits at field locations to gather evidence, based on the approved work plan;
  • Conducting interviews with program officials at Headquarters and/or in the field;
  • Preparing work papers that provide support for key findings and potential recommendations, based on technical evaluation;
  • Conducting entrance and exit conferences with the audited agency and conducting follow-up inquiries to evaluate the adequacy of corrective actions taken on prior audit findings, and;
  • Supporting the team in issuing final written products that adhere to high quality standards and reflect internal OIG management review and comments received from the audited operating administration.


Requirements

Conditions of Employment

  • Must be a U.S. Citizen.
  • Submit application and resume online by 11:59 P.M. EST on the closing date.
  • This position is subject to a background investigation.
  • This position requires a secret clearance.


Qualifications

To be eligible, applicants must meet the basic education and/or experience requirements below.

Specialized Experience

GS-14: To qualify, you must have at least one year of specialized experience equivalent to the GS-13 grade level in the federal service including: expert knowledge of wide range of IT concepts, theory, computer methods and procedures; expert knowledge applying cyber- security and information security principles and concepts sufficient to plan, coordinate, and assess IT security operations and the security of data, networks, systems and applications; providing technical advice and guidance regarding IT security issues; conducting penetration testing, red teaming, audits and/or assessments of IT programs; conducting interviews with officials; conducting comprehensive analysis and studies requiring the application of complex analytical and statistical methods and techniques; and preparing audit assessment reports.

And

Experience

Experience must be IT related; the experience may be demonstrated by paid or unpaid experience and/or completion of specific, intensive training (for example, IT certification), as appropriate

GS-5 through GS-15 (or equivalent): For all positions individuals must have IT-related experience demonstrating each of the four competencies listed below. The employing agency is responsible for identifying the specific level of proficiency required for each competency at each grade level based on the requirements of the position being filled.
  1. Attention to Detail - Is thorough when performing work and conscientious about attending to detail.
  2. Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services.
  3. Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately.
  4. Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations.

Preferred Qualifications:
  • 5+ years of security testing experience (red teaming, cloud security, application security, or network security)
  • One or more of the following industry certifications: OSCP, OSWA, OSWP, OSWE, OSEP, OSED, GPEN, GCPN, GWAPT, GMOB, GAWN, GXPN, eWPT, eCPPT, eMAPT, PNPT
  • Contributions to the security community such as research, public CVEs, bug-bounty recognitions, open-source projects, blogs, publications, etc
  • Experience with server administration, TCP/IP networking, vulnerability identification and exploitation, vulnerability exploit code development, offensive security operation coordination and communication, vulnerability tracking and remediation, mobile testing
  • Familiarity with various programming languages such as Python, C, Ruby, ASM are a plus
  • Experience with cloud-based environments (GCP, Azure, AWS, etc.)
  • Experience with common testing frameworks, such as the MITRE ATT&CK framework
  • Experience with NIST 800-53 rev 5, NIST 800-115

Qualifications must be met by the closing date of the announcements.

Additional information

OIG carries out its mission by issuing audit reports, evaluations, management advisories, and other products with findings and recommendations to improve program delivery and performance.

This vacancy will be filled through OPM's Direct Hire Authority. Veterans' preference and traditional rating and ranking of applicants does not apply to positions filled under this authority.

PLEASE NOTE THIS VACANCY IS LIMITED TO THE FIRST 75 APPLICATIONS RECEIVED AND WILL CLOSE AT MIDNIGHT ON THE CLOSING DATE OR AT MIDNIGHT ON THE DAY WE RECEIVE THE 75TH APPLICATION, WHICHEVER COMES FIRST.

THIS ANNOUNCEMENT MAY BE USED TO FILL ADDITIONAL LIKE VACANCIES IN THE ANNOUNCED DUTY LOCATION.

This position has been identified as a telework-eligible position.

Candidates will be asked to fill out a Declaration for Federal Employment (Optional Form 306). Individuals selected for positions will be required to certify that their application materials are accurate when they enter on duty.

Except for disabled individuals, non-status candidates must be in the area of consideration. Competitive status is not required if applicant is a disabled individual who may be eligible for appointment under a special Schedule A appointing authority in the excepted service. Applicants who meet this provision may apply even if they are outside the area of consideration.

Any male applicant who was born after December 31, 1959, and who is subsequently selected for this position must certify that he is registered for the military selective service by the date he is to enter on duty. False certification may result in termination after appointment.

THIS AGENCY PROVIDES REASONABLE ACCOMMODATIONS TO APPLICANTS WITH DISABILITIES. IF YOU NEED A REASONABLE ACCOMMODATION FOR ANY PART OF THE APPLICATION AND HIRING PROCESS, PLEASE NOTIFY THE AGENCY. THE DECISION ON GRANTING REASONABLE ACCOMMODATIONS WILL BE ON A CASE-BY-CASE BASIS.

ALL APPLICANTS WILL RECEIVE CONSIDERATION REGARDLESS OF RACE, COLOR, RELIGION, GENDER, SEXUAL ORIENTATION, NATIONAL ORIGIN, AGE, POLITICAL AFFILIATION, UNION AFFILIATION OR NON-AFFILIATION, MARITAL STATUS, NON-DISQUALIFYING PHYSICAL HANDICAP, OR ANY OTHER NON-MERIT REASON. THE OFFICE OF INSPECTOR GENERAL (OIG), U. S. DEPARTMENT OF TRANSPORTATION (DOT) IS AN EQUAL OPPORTUNITY EMPLOYER.

Relocation expenses will not be paid.

Benefits

A career with the U.S. government provides employees with a comprehensive benefits package. As a federal employee, you and your family will have access to a range of benefits that are designed to make your federal career very rewarding. Opens in a new windowLearn more about federal benefits.

The Office of Inspector General (OIG), U.S. Department of Transportation (DOT) offers all standard federal benefits that includes, in part, paid vacation; sick leave; holidays; health benefits; and participation in the Federal Employees Retirement System. This link provides an overview of the benefits currently offered to Federal employees https://help.usajobs.gov/index.php/Pay_and_Benefits.

The Department of Transportation recognizes the importance and encourages the use of telework. Telework supports departmental mission and performance goals and improves the Department's capability to support homeland and national security requirements. Telework improves individual and organizational productivity; helps reduce highway congestion and mobile source emissions; serves as a recruitment and retention tool; helps maintain operations during emergency situations; and improves work life quality.

This position has been identified as a telework-eligible position.

Eligibility for benefits depends on the type of position you hold and whether your position is full-time, part-time or intermittent. Contact the hiring agency for more information on the specific benefits offered.

How You Will Be Evaluated

You will be evaluated for this job based on how well you meet the qualifications above.

All applicants who meet the basic qualification requirements will be forwarded to the Selecting Official for consideration. This vacancy will be filled through OPM's Direct Hire Authority. Veterans' preference and traditional rating and ranking of applicants does not apply to positions filled under this authority.

Your application will be evaluated for basic eligibility and to determine if your experience and/or education meet the minimum qualification requirements described in this announcement. All applicants who meet the minimum qualifications and other basic requirements will be referred and are eligible for selection.

You may preview questions for this vacancy.

Benefits

A career with the U.S. government provides employees with a comprehensive benefits package. As a federal employee, you and your family will have access to a range of benefits that are designed to make your federal career very rewarding. Opens in a new windowLearn more about federal benefits.

The Office of Inspector General (OIG), U.S. Department of Transportation (DOT) offers all standard federal benefits that includes, in part, paid vacation; sick leave; holidays; health benefits; and participation in the Federal Employees Retirement System. This link provides an overview of the benefits currently offered to Federal employees https://help.usajobs.gov/index.php/Pay_and_Benefits.

The Department of Transportation recognizes the importance and encourages the use of telework. Telework supports departmental mission and performance goals and improves the Department's capability to support homeland and national security requirements. Telework improves individual and organizational productivity; helps reduce highway congestion and mobile source emissions; serves as a recruitment and retention tool; helps maintain operations during emergency situations; and improves work life quality.

This position has been identified as a telework-eligible position.

Eligibility for benefits depends on the type of position you hold and whether your position is full-time, part-time or intermittent. Contact the hiring agency for more information on the specific benefits offered.

Required Documents

As a new or existing federal employee, you and your family may have access to a range of benefits. Your benefits depend on the type of position you have - whether you're a permanent, part-time, temporary or an intermittent employee. You may be eligible for the following benefits, however, check with your agency to make sure you're eligible under their policies.

Resume: PLEASE MAKE SURE YOUR EXPERIENCE IS CLEARLY DOCUMENTED IN YOUR RESUME OTHERWISE YOU MAY BE DEEMED INELIGIBLE.
  • Your resume must support the specialized experience described in this announcement.
  • If your resume includes a photograph or other inappropriate material or content, it will not be used to make eligibility and qualification determinations and you may not be considered for this vacancy.
  • For qualifications determinations your resume must contain hours worked per week and the dates of employment (i.e., HRS per week and month/year to month/year or month/year to present). If your resume does not contain this information, your application may be marked as incomplete and you may not receive consideration for this position.
  • For additional information see:
    • What to include in your resume
    • Resume Writing

DD-214/VA LETTER/ and SF-15- To receive consideration including veteran's preference points, all veterans must submit a copy of their DD-214 (copy Member #4). If you are claiming 10-point preference, you must submit your SF-15 (revised 12/04). The form is available at http://www.opm.gov/forms/html/sf.asp. If you are a current service member, in lieu of a DD-214, you may submit a statement from your military personnel center certifying the nature and dates of your service and expected date of separation.

PERFORMANCE APPRAISAL - All applicants MUST submit a copy of your most recent official annual performance appraisal, whether or not you are a Federal employee. If it is not provided, please provide an explanation as to why it is not provided.

SCHEDULE A - To receive consideration for Schedule A appointment, you must submit your certification from a State Vocational Rehabilitation Office or the Department of Veterans Affairs that you are likely to succeed in the performance of the position. The letter must be printed on "medical professional's" letterhead and must include a signature or it is invalid.

CTAP/ICTAP - If you are eligible under the Career Transition Assistance Program (CTAP) or the Interagency Career Transition Assistance Program (ICTAP), a copy of your certificate of surplus status, certificate of expected separation, or a specific Reduction-in-Force notice establishing your eligibility under CTAP/ICTAP. CTAP/ICTAP candidates must meet all qualification requirements for the vacant position to include any selective factors; meet the definition of best qualified (GOLD Category); and be able to satisfactorily perform the duties of the position upon entry.

Supporting documents may either be uploaded or faxed to 571-258-4052. The requested information MUST be received by fax within 48 hours prior to the closing date of the vacancy announcement (not including Saturdays, Sundays or government holidays).

If you are relying on your education to meet qualification requirements:

Education must be accredited by an accrediting institution recognized by the U.S. Department of Education in order for it to be credited towards qualifications. Therefore, provide only the attendance and/or degrees from schools accredited by accrediting institutions recognized by the U.S. Department of Education.

Failure to provide all of the required information as stated in this vacancy announcement may result in an ineligible rating or may affect the overall rating.

How to Apply

Applications submitted via WWW.USAJOBS.GOV must be received before midnight eastern time on the closing date of the announcement. No extensions will be granted. If you fail to submit a COMPLETE on-line resume, you WILL NOT be considered for this position. Please make sure that the responses provided in the questionnaire are fully supported by your resume, that your resume is detailed and you have highlighted your most relevant experience for this position (to include starting and ending dates of employment for each position held), and education (if applicable) as it relates to this job opportunity. If you fail to provide this information, it may result in you being rated "ineligible" or "not qualified" for this position.

If you exaggerate or falsify your experience, education and/or your responses to questions, your ratings are subject to change or you may be removed from employment consideration. Applicants who do not respond to the application questions will be rated ineligible.

If applying on-line poses a hardship to any applicant, the Servicing Personnel Office listed on the announcement will provide assistance to ensure that applications are submitted on-line by the closing date. Applicants must contact the Servicing Human Resources Office PRIOR TO THE CLOSING DATE to speak to someone who can provide assistance for on-line submission. Requests for extensions will not be granted.

Agency contact information

Davitta Kauffman

Phone

202-366-1490

TDD

202-366-2136

Fax

571-258-4052

Email

davitta.kauffman@oig.dot.gov

Address

DOT, OFFICE OF THE INSPECTOR GENERAL
1200 New Jersey Ave SE
West Building, Room W71-123
Washington, District of Columbia 20590
United States

Next steps

Once your complete application is received, we will conduct an evaluation of your qualifications. All applicants who meet the minimum qualifications and other basic requirements will be referred to the hiring manager for further consideration and possible interview. You will be notified of your application status by the servicing human resources specialist via e-mail. It is essential that you have a current e-mail address on file and remove any restrictions from your e-mail account that may prohibit our contacting you via e-mail.

You may also check the status of your application at WWW.USAJOBS.OPM.GOV.

Similar jobs