United States Courts

Information Technology Specialist (Security)

United States Courts$95K — $115K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Minimum of one year of specialized experience in detection engineering or threat hunting.
  • Experience in developing scalable or automated data pipelines.
  • Ability to manage and oversee intelligence functions in cybersecurity environments.
  • Proven experience maintaining an organization's risk posture.
  • Bachelor's degree in computer science or cybersecurity preferred.
  • Certifications such as OSCP, GREM, or GXPN are desired.

Responsibilities

  • Lead detection engineering efforts to identify and categorize cybersecurity threats.
  • Provide technical direction and oversight for the detection engineering team.
  • Develop, test, and manage detection logic for malicious activity identification.
  • Integrate threat intelligence into detection logic for improved threat identification.
  • Validate threat detections for their effectiveness against malicious activity.
  • Conduct research on new and emerging threat techniques.
  • Ensure adherence to detection engineering standards and quality assurance processes.
  • Develop metrics and reports to measure detection effectiveness and program risk.

Benefits

  • Comprehensive benefits package for federal employees and their families.
  • Access to a range of rewarding federal career benefits.
Full Job Description
Summary

This position is in the Department of the Chief Information Officer, Information Technology Security Office, Security Operations Division. The Security Operation Division protects the judiciary from cyber threats, strengthens the judiciary's security posture and threat awareness, eliminates threats before they can harm operations, and provides evaluation services to strengthen systems and programs.

Duties

Help

The Information Technology Specialist (Security) leads detection engineering efforts to identify and categorize cybersecurity threats impacting the confidentiality, integrity, or availability of judicial data. The incumbent ensures detections are appropriate for the threat environment and are consistently validated. The incumbent perform multiple and varying assignments under the direction of the Chief, Security Operations Support Branch.

Duties Include:

  1. Providing technical leadership, direction, and federal oversight for the detection engineering team in support of continuous cybersecurity operations.
  2. Conducting development, testing, deployment, and lifecycle management of detection logic used to identify malicious activity across the judiciary's information technology fabric.
  3. Integrating threat intelligence reporting and indicators of compromise to inform detection logic and identify malicious activity.
  4. Continually validating threat detections to ensure they appropriately identify malicious activity
  5. Conducting threat research to identify novel or emergent techniques that are not yet integrated into the detection engineering program.
  6. Enforcing detection engineering standards, methodologies, and quality assurance processes to support accuracy, consistency, and operational effectiveness.
  7. Performing validation, tuning, and refinement of detection based on operational feedback, adversary emulation results, and observed threat activity.
  8. Ensuring the development of metrics and reporting to measure detection coverage, effectiveness, and operational maturity.
  9. Providing quarterly report summaries to senior leadership and judiciary cybersecurity stakeholders on the detection engineering effectiveness and program risk.
  10. Closely coordinating with the Security Operations Center to improve alerts, fidelity, investigative workflows, and the continuous improvement of analytic outcomes.


Qualifications

Applicants must have demonstrated experience as listed below. This requirement is according to the AO Classification, Compensation, and Recruitment Systems which include interpretive guidance and reference to the OPM Operating Manual for Qualification Standards for General Schedule Positions.

Specialized Experience: Applicants must have at least one full year (52 weeks) of specialized experience which is in or directly related to the line of work of this position. Specialized experience is demonstrated experience in ALL of the following:

  1. Developing scalable or automated data pipelines.
  2. Leading or overseeing detection engineering, threat hunting, or intelligence functions within an enterprise cybersecurity environment.
  3. Developing and maintaining a common operational picture to provide context of an organization's risk posture.


Desired Education:

Bachelors' degree in computer science, cybersecurity, or equivalent technical field is highly desired.

Desired Certifications:

  • Offensive Security Professional (OSCP)
  • GIAC Reverse Engineering Malware (GREM)
  • GIACE Exploit Researcher
  • Advanced Penetration Tester (GXPN)


Education

This position does not require education to qualify.

Benefits

Help

A career with the U.S. government provides employees with a comprehensive benefits package. As a federal employee, you and your family will have access to a range of benefits that are designed to make your federal career very rewarding. Opens in a new windowLearn more about federal benefits.

Review our benefits

Eligibility for benefits depends on the type of position you hold and whether your position is full-time, part-time or intermittent. Contact the hiring agency for more information on the specific benefits offered.

Similar Jobs

More Jobs at United States Courts

More Information Technology Jobs

Find similar Information Technology Specialist (Security) jobs: