Information Technology Specialist (Security)

Washington, D.C
May 23, 2019
May 29, 2019
IT, Security Engineer
Full Time


The position will be responsible for providing Advanced Threat Hunting expertise to the 24x7x365 operations of the Security Operations Center (SOC). This position is critically important in meeting AO goals of protecting the security of Judiciary assets - including people, systems, facilities, and information through the active pursuit of potential Advanced Persistent Threats (APT) within the Judiciary environment.
Learn more about this agency


This position is located within the IT Security Office (ITSO) of the Department of Technology Services (DTS). The incumbent is a recognized IT security expert within the Judiciary with a strong background in cyber security, hunt operational mission planning, program management, data analytics, behavioral modeling, penetration testing and a proven record of successfully leading advanced threat hunting and threat evaluation activities. The incumbent will provide direct support in ensuring the confidentiality, integrity, and availability of systems, networks, data, and users throughout the Judiciary. The duties of this position will include but not be limited to:
  • Develop and refine threat hunting mission plans to systematically assess the entirety of the Judiciary for possible Advanced Persistent Threat (APT) intrusions.
  • Lead Ad Hoc hunt missions and provide subject matter expertise in support of day to day SOC intrusion detection and incident response activities to ascertain extent of compromise and residual threat.
  • Hunt for and identify threat actor groups and their techniques, tools and processes.
  • Continuously improve processes for use across multiple detection sets and develop automated as well as machine assisted capabilities to enhance detection of anomalous behavior.
  • Document best practices using available collaboration tools and workspaces. Develop and maintain SOPs and operation guides for mission functions, tools and infrastructure.
  • Develop dashboards and reports to identify threats, suspicious/anomalous activities, malware, user activity, etc.
  • Support forensic analysis and malware reverse engineering efforts to provide more effective indicators of compromise (IOC) in support of intrusion detection efforts.
  • Research and incorporate emerging threat tactics, techniques and procedures to detect new threats and threat actors.

  • Travel Required

    Occasional travel - You may be expected to travel for this position.

    Supervisory status

    Promotion Potential


    Conditions of Employment

  • All information is subject to verification. Applicants are advised that false answers or omissions of information on application materials or inability to meet the following conditions may be grounds for non-selection, withdrawal of an offer of employment, or dismissal after being employed.
  • Selection for this position is contingent upon completion of OF-306, Declaration of Federal Employment during the pre-employment process and proof of U.S. citizenship for competitive status positions or conversion to a competitive status position with the Administrative Office of the US Courts. In instances where non-citizens are considered for hire into temporary or any other position with non competitive status or when it is confirmed by the AO's Human Resources Office that there are no qualified U.S. citizens for a competitive status position (unless prohibited by a law or statue), non-citizens must provide proof of authorization to work in the United States and proof of entitlement to receive compensation. Additional information on the employment of non-citizens can be found at For a list of documents that may be used to provide proof of citizenship or authorization to work in the United States, please refer to Form I-9, Employment Eligibility Verification.
  • All new AO employees will be required to complete a FBI fingerprint-based national criminal database and records check and pass a public trust suitability check.
  • You will be required to serve a trial period if selected for a first-time appointment to the Federal government, transferring from another Federal agency, or serving as a first-time supervisor. Failure to successfully complete the trial period may result in termination of employment. This does not apply to current federal Judiciary employees.
  • Relocation expenses may be provided, but only if authorized by the Director of the AO.
  • More than one selection may be made from this announcement.
  • All requirements must be met by the closing date of this announcement.

  • Qualifications

    Applicants must have demonstrated experience as listed below. This requirement is according to the AO Classification, Compensation, and Recruitment Systems which include interpretive guidance and reference to the OPM Operating Manual for Qualification Standards for General Schedule Positions.

    Basic Requirements: You must have Information Technology (IT) related experience which demonstrates proficiency in each of the following competencies:

    1. Attention to Detail - Is thorough when performing work and conscientious about attending to detail.
    2. Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services.
    3. Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately.
    4. Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations.


    Specialized Experience : Applicants must have at least one full year (52 weeks) of specialized experience which is in or directly related to the line of work of this position. Specialized experience is demonstrated experience in ALL of the areas defined below:
  • Working in a cybersecurity operations environment leading advanced threat hunting and threat evaluation activities.
  • Experience with penetration testing and vulnerability evaluations to align hunting efforts with established threat actor methodologies.
  • Experience leading teams of analysts in conducting active threat hunting operations
  • Familiar or certified with Splunk, Incident Management, Cyber Threat Intelligence, Software vulnerabilities & exploitation, data analysis, malware analysis, APT/criminal infrastructure analysis, exploit kits and penetration testing. (Your resume must show clear and convincing evidence of all areas of specialized experience.)
  • The following is desired but not required:
  • CompTIA Security+, Certified Ethical Hacker, OSCP, CISM, CISSP or equivalent certifications.
  • Degree in Information Security, Cyber Security or Information Technology.
  • Demonstrated knowledge of Linux/Unix, Windows and MacOS operating systems.
  • Experience with Snort, Bro and other network IDS tools
  • (Resume must show clear and convincing evidence of all areas of specialized experience. We will not make assumptions.)


    This position does not require education to qualify.

    Additional information

    The AO is an Equal Opportunity Employer.

    How You Will Be Evaluated

    You will be evaluated for this job based on how well you meet the qualifications above.

    We will review your resume and supporting documentation and compare this information to your responses on the occupational questionnaire to determine if you meet the minimum qualifications for this job. If you meet the minimum qualifications for this job, we will evaluate your application package, to assess the quality, depth, and complexity of your accomplishments, experience, and education as they relate to the requirements listed in this vacancy announcement.

    You should be aware that your ratings are subject to evaluation and verification. If a determination is made that you have rated yourself higher than is supported by your resume and/or narrative responses, you will be assigned a rating commensurate to your described experience. Failure to submit the mandatory narrative responses will result in not receiving full consideration and/or rating credit. Deliberate attempts to falsify information may be grounds for not selecting you, withdrawing an offer of employment, or dismissal after being employed.

    Background checks and security clearance

    Security clearance
    Not Required

    Drug test required

    Required Documents

    For this job announcement the following documents and/or information are required:
    • Resume - Any written format you choose to describe your job-related qualifications.
    • Citizenship - Include country of citizenship on resume.
    • Notification of Personnel Action (SF-50) - All applicants outside of the AO must submit a copy of your latest SF-50 to verify current or former Federal employment status.
    • Veterans Preference documentation - Certificate of Release or Discharge from Active Duty (DD Form 214), if applicable Application for 10-Point Veteran Preference (SF-15) and an official statement, dated 1991 or later, from the Department of Veterans Affairs or from a branch of the Armed Forces, certifying to the veteran's present receipt of compensation.

    If you are relying on your education to meet qualification requirements:

    Education must be accredited by an accrediting institution recognized by the U.S. Department of Education in order for it to be credited towards qualifications. Therefore, provide only the attendance and/or degrees from schools accredited by accrediting institutions recognized by the U.S. Department of Education .

    Failure to provide all of the required information as stated in this vacancy announcement may result in an ineligible rating or may affect the overall rating.

    Similar jobs