
Information Technology Specialist (Security)
Administrative Office of the U.S. Courts
Most applications go out cold — see where you stand first. No sign-up to start.
Don't just apply. Show up ready.
Olive works from this exact posting — no sign-up to start.
At a glance
Job overview
The Information Technology Specialist (Security) leads detection engineering efforts to identify and categorize cybersecurity threats impacting judicial data, ensuring detections are appropriate, validated, and aligned with threat intelligence while providing metrics, reporting, and coordination with the Security Operations Center.
Skills & qualifications
Skills
Qualifications
Full job description
Summary This position is in the Department of the Chief Information Officer, Information Technology Security Office, Security Operations Division. The Security Operation Division protects the judiciary from cyber threats, strengthens the judiciary's security posture and threat awareness, eliminates threats before they can harm operations, and provides evaluation services to strengthen systems and programs. Responsibilities The Information Technology Specialist (Security) leads detection engineering efforts to identify and categorize cybersecurity threats impacting the confidentiality, integrity, or availability of judicial data. The incumbent ensures detections are appropriate for the threat environment and are consistently validated. The incumbent perform multiple and varying assignments under the direction of the Chief, Security Operations Support Branch. Duties Include: Providing technical leadership, direction, and federal oversight for the detection engineering team in support of continuous cybersecurity operations. Conducting development, testing, deployment, and lifecycle management of detection logic used to identify malicious activity across the judiciary's information technology fabric. Integrating threat intelligence reporting and indicators of compromise to inform detection logic and identify malicious activity. Continually validating threat detections to ensure they appropriately identify malicious activity Conducting threat research to identify novel or emergent techniques that are not yet integrated into the detection engineering program. Enforcing detection engineering standards, methodologies, and quality assurance processes to support accuracy, consistency, and operational effectiveness. Performing validation, tuning, and refinement of detection based on operational feedback, adversary emulation results, and observed threat activity. Ensuring the development of metrics and reporting to measure detection coverage, effectiveness, and operational maturity. Providing quarterly report summaries to senior leadership and judiciary cybersecurity stakeholders on the detection engineering effectiveness and program risk. Closely coordinating with the Security Operations Center to improve alerts, fidelity, investigative workflows, and the continuous improvement of analytic outcomes. Requirements Conditions of Employment CONDITIONS OF EMPLOYMENT All information is subject to verification. Applicants are advised that false answers or omissions of information on application materials or inability to meet the following conditions may be grounds for non-selection, withdrawal of an offer of employment, or dismissal after being employed. Selection for this position is contingent upon completion of OF-306, Declaration of Federal Employment during the pre-employment process and proof of U.S. citizenship for competitive status positions or conversion to a competitive status position with the AO. If non-citizens are considered for hire into a temporary or any other position with non-competitive status or when it is confirmed by the AO Human Resources Office there are no qualified U.S. citizens for a competitive status position (unless prohibited by a law or statue), non-citizens must provide proof of authorization to work in the U.S. and proof of entitlement to receive compensation. Additional information on the employment of non-citizens can be found at USAJOBS Help Center | Employment of non-citizens/. For a list of documents that may be used to provide proof of citizenship or authorization to work in the United States, please refer to Form I-9, Employment Eligibility Verification. All new AO employees will be required to complete an FBI fingerprint-based national criminal database and records check and pass a public trust suitability check. New employees to the AO will be required to successfully pass the E-Verify employment verification check. To learn more about E-Verify, including your rights/responsibilities, visit https://www.e-verify.gov/. All new AO employees are required to identify a financial institution for direct deposit of pay before appointment. You will be required to serve a trial period if selected for a first-time appointment to the Federal government, transferring from another Federal agency, or serving as a first-time supervisor. Failure to successfully complete the trial period may result in termination of employment. If appointed to a temporary position, management may have the discretion of converting the position to permanent depending upon funding and staffing allocation. Qualifications Applicants must have demonstrated experience as listed below. This requirement is according to the AO Classification, Compensation, and Recruitment Systems which include interpretive guidance and reference to the OPM Operating Manual for Qualification Standards for General Schedule Positions. Specialized Experience: Applicants must have at least one full year (52 weeks) of specialized experience which is in or directly related to the line of work of this position. Specialized experience is demonstrated experience in ALL of the following: Developing scalable or automated data pipelines. Leading or overseeing detection engineering, threat hunting, or intelligence functions within an enterprise cybersecurity environment. Developing and maintaining a common operational picture to provide context of an organization's risk posture. Desired Education: Bachelors' degree in computer science, cybersecurity, or equivalent technical field is highly desired. Desired Certifications: Offensive Security Professional (OSCP) GIAC Reverse Engineering Malware (GREM) GIACE Exploit Researcher Advanced Penetration Tester (GXPN) Education This position does not require education to qualify. Additional Information The AO is an Equal Opportunity Employer.
You've read the whole posting — now see how you match it.