Administrative Office of the U.S. Courts logo

Supervisory Information Technology Specialist (Security)

Administrative Office of the U.S. Courts

Washington, DCFull-time$122–197K/yrPosted 1 day ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
$122–197K/yr
Location
Washington, DC
Schedule
Full-time
Work Authorization
US work authorization required

Job overview

The Supervisory Information Technology Specialist (Security) leads detection engineering, threat hunting, threat intelligence, and insider threat teams within the Security Operations Division to protect judicial data from cyber threats.

Skills & qualifications

RequiredNice to have

Skills

Detection EngineeringThreat HuntingThreat IntelligenceInsider Threat AnalysisSecurity Information and Event ManagementHypothesis‑Based HuntingMetrics DevelopmentExecutive ReportingOperational CoordinationLeadership

Qualifications

One Year Specialized Experience in Cyber Threat Intelligence, Threat Hunting, and Detection EngineeringBachelor's Degree in Computer Science, Cybersecurity, or Equivalent Technical FieldOffensive Security Professional (OSCP) CertificationGIAC Reverse Engineering Malware (GREM) CertificationGIAC Exploit Researcher Advanced Penetration Tester (GXPN) CertificationProof of U.S. Citizenship

Full job description

Summary

This position is in the Department of the Chief Information Officer, Information Technology Security Office, Security Operations Division, Security Operations Support Branch. The Security Operations Division protects the judiciary from cyber threats, strengthens the judiciary's security posture and threat awareness, eliminates threats before they can harm operations, and provides evaluation services to strengthen systems and programs.

Duties

The Supervisory Information Technology Specialist (Security) is in the Information Technology Security Office's Security Operations Division and serves as the Security Operations Support Branch Chief. The Security Operations Branch delivers enterprise detection engineering, threat hunting, threat intelligence, and insider threat capabilities in support of continuous cybersecurity operations. This position reports to the Security Operations Division Chief. The incumbent is a recognized cyber-security subject matter expert with a strong defensive cybersecurity background and is responsible for leading detection engineering, threat hunting, threat intelligence and insider threat teams to identify cybersecurity threats impacting the confidentiality, integrity, or availability of judicial data. the Supervisory Information Technology Specialist (Security) leads hypothesis-based threat hunting to identify, investigate, and mitigate advanced persistent threats, zero-day vulnerability abuse, and other malicious activity to bypass traditional security controls. The incumbent lead detection engineering to categorize known attack vectors through the security information and event management. The incumbent is responsible for the threat intelligence program, reporting on malicious threat actors, and identifying insider threats to judiciary data and systems. Leading, directing, and overseeing the Security Operations Support Branch. Overseeing the development, testing, deployment, and lifecycle management of detection logic used to identify malicious activity. Leading the production and operational integration of threat intelligence to inform detection engineering priorities, hunting hypotheses, and risk-based decision making. Directing proactive threat hunting activities to identify emerging, novel, or evasive adversary behavior not covered by existing detection mechanisms. Establishing and maintaining detection engineering standards, methodologies, and quality assurance processes to support accuracy, consistency, and operational effectiveness. Overseeing the validation, tuning, and refinement of detections based on operational feedback, adversary emulation results, and observed threat activity. Ensuring development of metrics and reporting to measure detection coverage, effectiveness and operational maturity. Leading the development and maintenance of a common operational picture that identifies baseline behavior and meaningful deviations to support shared situational awareness, prioritization and leadership decision making. Providing regular executive summaries to senior leadership and judiciary cybersecurity stakeholders for informed enterprise risk understanding prioritization, and resource allocation decisions. Coordinating closely with Security Operations Center to support alert fidelity, investigative workflows, and continuous improvement of analytic outcomes. Managing branch personnel, contractor support, and resource planning to sustain required capabilities. Requirements

CONDITIONS OF EMPLOYMENT All information is subject to verification. Applicants are advised that false answers or omissions of information on application materials or inability to meet the following conditions may be grounds for non-selection, withdrawal of an offer of employment, or dismissal after being employed. Selection for this position is contingent upon completion of OF-306, Declaration of Federal Employment during the pre-employment process and proof of U.S. citizenship for competitive status positions or conversion to a competitive status position with the AO. If non-citizens are considered for hire into a temporary or any other position with non-competitive status or when it is confirmed by the AO Human Resources Office there are no qualified U.S. citizens for a competitive status position (unless prohibited by a law or statue), non-citizens must provide proof of authorization to work in the U.S. and proof of entitlement to receive compensation. Additional information on the employment of non-citizens can be found at USAJOBS Help Center | Employment of non-citizens/. For a list of documents that may be used to provide proof of citizenship or authorization to work in the United States, please refer to Form I-9, Employment Eligibility Verification. All new AO employees will be required to complete an FBI fingerprint-based national criminal database and records check and pass a public trust suitability check. New employees to the AO will be required to successfully pass the E-Verify employment verification check. To learn more about E-Verify, including your rights/responsibilities, visit https://www.e-verify.gov/. All new AO employees are required to identify a financial institution for direct deposit of pay before appointment. You will be required to serve a trial period if selected for a first-time appointment to the Federal government, transferring from another Federal agency, or serving as a first-time supervisor. Failure to successfully complete the trial period may result in termination of employment. If appointed to a temporary position, management may have the discretion of converting the position to permanent depending upon funding and staffing allocation. Qualifications

Applicants must have demonstrated experience as listed below. This requirement is according to the AO Classification, Compensation, and Recruitment Systems which include interpretive guidance and reference to the OPM Operating Manual for Qualification Standards for General Schedule Positions. Specialized Experience: Applicants must have at least one full year (52 weeks) of specialized experience which is in or directly related to the line of work of this position. Specialized experience is demonstrated experience in ALL of the following: Leading cyber threat intelligence, threat hunting, and detection engineering in support of 24/7 security operation center. Analyzing and integrating threat intelligence from open-source and classified sources. Developing detection methodologies. Conducting proactive threat hunting to identify and mitigate cyber threats. Desired Education: Bachelor's degree in computer science, cybersecurity, or equivalent technical field is highly desired. Desired (but not required certification): Offensive Security Professional (OSCP) GIAC Reverse Engineering Malware (GREM) GIAC Exploit Researcher Advanced Penetration Tester (GXPN)

Education

This position does not require education to qualify. How You Will Be Evaluated

We will review your resume and supporting documentation and compare this information to your responses on the occupational questionnaire to determine if you meet the minimum qualifications for this job. If you meet the minimum qualifications for this job, we will evaluate your application package, to assess the quality, depth, and complexity of your accomplishments, experience, and education as they relate to the requirements listed in this vacancy announcement. You should be aware that your ratings are subject to evaluation and verification. If a determination is made that you have rated yourself higher than is supported by your resume and/or narrative responses, you will be assigned a rating commensurate to your described experience. Failure to submit the mandatory narrative responses will result in not receiving full consideration and/or rating credit. Deliberate attempts to falsify information may be grounds for not selecting you, withdrawing an offer of employment, or dismissal after being employed. Other Information

The AO is an Equal Opportunity Employer.

You've read the whole posting — now see how you match it.