Administrative Office of the U.S. Courts logo

Information Technology Specialist (Security)

Administrative Office of the U.S. Courts

Washington, DCFull-time$102–192K/yrPosted today

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$102–192K/yr
Location
Washington, DC
Schedule
Full-time
Work Authorization
US work authorization required

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

The Information Technology Specialist (Security) serves as a cyber threat intelligence analyst and technical cybersecurity subject matter expert within the Chief Information Officer’s Security Operations Division, providing threat intelligence support, managing the intelligence production cycle, and delivering actionable reports to senior judiciary stakeholders.

Skills & qualifications

RequiredNice to have

Skills

Cyber Threat Intelligence AnalysisThreat Actor AttributionInsider Threat DetectionOperational Telemetry IntegrationSecurity Tooling ManagementIncident Response SupportMetrics DevelopmentExecutive Reporting

Qualifications

One Year Specialized ExperienceBachelor's Degree in Computer Science or Cybersecurity or Equivalent Technical FieldCertified Information Systems Security Professional (CISSP)GIAC Cyber Threat Intelligence (GCTI)GIAC Reverse Engineering Malware (GREM)

Full job description

Summary

The position is in the Department of the Chief Information Officer, Information Technology Security Office, Security Operations Division, Security Operations Branch. The Security Operation Division protects the judiciary from cyberthreats, strengthens the judiciary's security posture and threat awareness, eliminates threats before they can harm operations, and provides evaluation services to strengthen systems and programs.

Duties

The Information Technology Specialist (Security) serves as a Cyber Threat Intelligence Analyst, a technical cybersecurity subject matter expert and performs multiple and varying assignments under the direction of the Chief, Security Operations Divisions. The incumbent will be responsible for providing threat intelligence support to security operations. Duties Include: Conducting independent technical research and analysis to identify emerging and novel threat vectors, synthesizing intelligence from adversary tradecraft, vulnerability disclosures and operational telemetry to inform proactive threat identification. Managing all phases of the intelligence production cycle, ensuring timely and actionable reports for stakeholders across the judiciary. Maintaining and improving a common operational picture of the judiciary's threat environment, integrating internal telemetry, open-source intelligence, and cybersecurity threat feeds to provide leadership with a continuous, accurate understanding of the current threat landscape. Managing the indicators of compromise lifecycle, including ingestion, validation, enrichment, prioritization, and operationalization across security tooling and detection platforms. Responding to intelligence support requests from the Security Operations Center, providing timely, technically accurate assessments that enable effective triage, investigation, and incident response. Conducting threat actor attribution analysis and develops comprehensive threat actor profiles, documents adversary tactics, techniques, and procedures to support cyber threat hunting and detection engineering. Identifying insider threats to judiciary data and systems, applying behavioral analytics and intelligence tradecraft to detect, assess, and report on indicators of malicious or negligent insider activity. Maintaining intelligence analysis standards, methodologies, and quality assurance processes to support accuracy, consistency, and operational effectiveness. Developing metrics and reporting to measure effectiveness and operational maturity of the cyber threat intelligence program. Providing regular executive summaries to senior leadership and judiciary cybersecurity stakeholders for informed enterprise risk understanding, prioritization, and resource allocation decisions. Performing the tasks and meeting the skills, knowledge, and abilities as described in NIST Special Publication 800-181 National Initiative for Cybersecurity Education Cybersecurity Workforce for the role of Threat Analysis (PD-WRL-006). Requirements

CONDITIONS OF EMPLOYMENT All information is subject to verification. Applicants are advised that false answers or omissions of information on application materials or inability to meet the following conditions may be grounds for non-selection, withdrawal of an offer of employment, or dismissal after being employed. Selection for this position is contingent upon completion of OF-306, Declaration of Federal Employment during the pre-employment process and proof of U.S. citizenship for competitive status positions or conversion to a competitive status position with the AO. If non-citizens are considered for hire into a temporary or any other position with non-competitive status or when it is confirmed by the AO Human Resources Office there are no qualified U.S. citizens for a competitive status position (unless prohibited by a law or statue), non-citizens must provide proof of authorization to work in the U.S. and proof of entitlement to receive compensation. Additional information on the employment of non-citizens can be found at USAJOBS Help Center | Employment of non-citizens/. For a list of documents that may be used to provide proof of citizenship or authorization to work in the United States, please refer to Form I-9, Employment Eligibility Verification. All new AO employees will be required to complete an FBI fingerprint-based national criminal database and records check and pass a public trust suitability check. New employees to the AO will be required to successfully pass the E-Verify employment verification check. To learn more about E-Verify, including your rights/responsibilities, visit https://www.e-verify.gov/. All new AO employees are required to identify a financial institution for direct deposit of pay before appointment. You will be required to serve a trial period if selected for a first-time appointment to the Federal government, transferring from another Federal agency, or serving as a first-time supervisor. Failure to successfully complete the trial period may result in termination of employment. If appointed to a temporary position, management may have the discretion of converting the position to permanent depending upon funding and staffing allocation. Qualifications

Applicants must have demonstrated experience as listed below. This requirement is according to the AO Classification, Compensation, and Recruitment Systems which include interpretive guidance and reference to the OPM Operating Manual for Qualification Standards for General Schedule Positions. Specialized Experience: Applicants must have at least one full year (52 weeks) of specialized experience which is in or directly related to the line of work of this position. Specialized experience is demonstrated experience in ALL of the following: Developing, testing, and maintaining detection logic to identify malicious activity across enterprise systems. Developing metrics, reporting, and lessons learned to communicate risks, gaps, and readiness outcomes to senior leadership. Integrating and managing threat intelligence platforms. Desired Education: Bachelor's degree in computer science, cybersecurity, or equivalent technical field is highly desired. Desired Certifications: Certified Information System Security Professional (CISSP) GIAC Cyber Threat Intelligence (GCTI) GIAC Reverse Engineering Malware (GREM)

Education

This position does not require education to qualify. How You Will Be Evaluated

We will review your resume and supporting documentation and compare this information to your responses on the occupational questionnaire to determine if you meet the minimum qualifications for this job. If you meet the minimum qualifications for this job, we will evaluate your application package, to assess the quality, depth, and complexity of your accomplishments, experience, and education as they relate to the requirements listed in this vacancy announcement. You should be aware that your ratings are subject to evaluation and verification. If a determination is made that you have rated yourself higher than is supported by your resume and/or narrative responses, you will be assigned a rating commensurate to your described experience. Failure to submit the mandatory narrative responses will result in not receiving full consideration and/or rating credit. Deliberate attempts to falsify information may be grounds for not selecting you, withdrawing an offer of employment, or dismissal after being employed. Other Information

The AO is an Equal Opportunity Employer.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.