IT Specialist (Security)

Commander, Navy Installations Command

• $92K — $110K *
Hines, IL 60141In-Person
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of IT security experience with a focus on network security and cyber defense principles.
  • Proven ability to analyze network traffic and identify anomalous activities.
  • Experience using intrusion detection and prevention systems (IDS/IPS) for threat identification.
  • Strong understanding of federal cybersecurity regulations and risk mitigation strategies.
  • Hands-on experience with SIEM and EDR platforms, particularly in threat detection and response.

Responsibilities

  • Apply IT security principles to safeguard sensitive information within the VA.
  • Conduct in-depth analysis of network traffic to detect potential security threats.
  • Collaborate with cyber defense team to validate network alerts and incidents.
  • Perform event correlation from various data sources to assess attack effectiveness.
  • Identify security gaps and provide recommendations for improving security architecture.

Benefits

  • Access to a comprehensive benefits package as a federal employee.
  • Eligibility for annual leave based on federal service.
  • Opportunity for flexible and telework arrangements.
Full Job Description
Summary

This IT Specialist (Security) position is located in the Office and Information and Technology (OI&T), Office of Information Security (OIS), Information Security Office (ISO), Cyber Security Operations Center (CSOC). The Office of Information and Technology (OI&T) provides adaptable, secure, and cost- effective technology services across the Department of Veterans Affairs (VA).

Duties

Help

Major Duties:

  • Knowledge of information technology (IT) security principles and methods (e.g., firewalls, demilitarized zones, encryption).
  • Knowledge of defense-in-depth principles and network security architecture.
  • Knowledge of cyber defense and information security policies, procedures, and regulations.
  • Skill to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
  • Ability to interpret the information collected by network tools (e.g. Ns lookup, Ping, and Traceroute).
  • Determine tactics, techniques, and procedures (TTPs) for intrusion sets.
  • Conduct research, analysis, and correlation across a wide variety of all source data sets (indications and warnings).
  • Knowledge of adversarial tactics, techniques, and procedures.
  • Skill in collecting data from a variety of cyber defense resources.
  • Skill in performing packet-level analysis.
  • Characterize and analyze network traffic to identify anomalous activity and potential threats to network resources.
  • Coordinate with enterprise-wide cyber defense staff to validate network alerts.
  • Ensure that cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.
  • Knowledge of the common attack vectors on the network layer.
  • Ability to apply techniques for detecting host and network-based intrusions using intrusion detection technologies.
  • Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack.
  • Analyze identified malicious activity to determine weaknesses exploited, exploitation methods, effects on system and information.
  • Reconstruct a malicious attack or activity based off network traffic.
  • Knowledge of incident response and handling methodologies.
  • Skill in using incident handling methodologies.
  • Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy.
  • Knowledge of cyber defense and vulnerability assessment tools and their capabilities.
  • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code).
  • Skill in assessing security controls based on cybersecurity principles and tenets. (e.g., CIS CSC, NIST SP 800-53, Cybersecurity Framework, etc.).
  • Knowledge of Intrusion Detection System (IDS)/Intrusion Prevention System (IPS) tools and applications.


Work Schedule: Monday - Friday, 8:00am to 4:30pm

Compressed/Flexible: Compressed/flexible schedule available at the manager's discretion

Telework: This position may be authorized for telework.

Virtual: This is not a virtual position.

Position Description/PD#: IT Specialist (Security)/PD17400A

Relocation/Recruitment Incentives: Not Authorized

Permanent Change of Station (PCS): Not Authorized

PCS Appraised Value Offer (AVO): Not Authorized

Requirements

Help

Conditions of employment

  • You must be a U.S. Citizen to apply for this job
  • To be considered for this position, you must complete all required steps in the process. In addition to the application and questionnaire, this position requires an online assessment. The online assessment measures critical general competencies required to perform the job.
  • Physical Requirements: The work required does not inherently include any physical requirements essential for successful job performance that could not otherwise be performed with accommodation or workplace adjustment. A pre-placement physical examination is not required.
  • You may be required to serve a probationary period
  • Subject to background/security investigation
  • Selected applicants will be required to complete an online onboarding process. Acceptable form(s) of identification will be required to complete pre-employment requirements (https://www.uscis.gov/i-9-central/form-i-9-acceptable-documents). Effective May 7, 2025, driver's licenses or state-issued dentification cards that are not REAL ID compliant cannot be utilized as an acceptable form of identification for employment.
  • As a condition of employment for accepting this position, you will be required to serve a 1-year probationary period during which we will evaluate your fitness and whether your continued employment advances the public interest. In determining if your employment advances the public interest, we may consider:
  • your performance and conduct;
  • the needs and interests of the agency;
  • whether your continued employment would advance organizational goals of the agency or the Government; and
  • whether your continued employment would advance the efficiency of the Federal service.


Upon completion of your probationary period, your employment will be terminated unless you receive certification, in writing, that your continued employment advances the public interest.

Qualifications

To qualify for this position, applicants must meet all requirements by the closing date of this announcement, 10/07/2026.

Applicants must have IT-related experience demonstrating each of the four competencies listed below at a proficiency level equivalent to the next lower grade level in federal service

You must meet both the Basic Requirement and the Specialized Experience and the Selective Placement Factor to qualify for this series as described below

  1. Attention to Detail - Is thorough when performing work and conscientious about attending to detail.
  2. Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services.
  3. Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately.
  4. Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations.


AND

  • Specialized Experience: You must have one year of specialized experience equivalent to at least the next lower grade GS-13 in the normal line of progression for the occupation in the organization. Experience characterizing and analyzing network traffic to identify anomalous activity and potential threats to network resources; performing event correlation using information gathered from a variety of enterprise sources to determine the effectiveness of an observed attack; analyzing malicious activity to determine weaknesses exploited, exploitation methods, and effects on systems and information; and providing risk mitigation recommendations based on Federal laws, regulations, and organizational policies.


AND-

Selective Placement Factor: Developing, tuning, and validating detection analytics and correlation rules within Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) platforms to support proactive threat hunting and cybersecurity incident response operations, to include applying a structured adversary behavior framework (e.g., MITRE ATT&CK) to identify tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) not detected through automated alerting; and experience providing technical direction and quality review of work performed by contract staff supporting these functions, in a non-supervisory capacity.

Physical Demands:

The work is primarily sedentary during the planning/preparation phase. The work may require walking and standing for prolong periods in conjunction with travel and at the onsite assessment location. The incumbent may carry light items such as papers, books or computers, or drive a motor

vehicle. The work does not require any special physical effort.

Work Environment:

The work area is adequately lighted, heated, and ventilated. The work environment involves everyday risks or discomforts that require normal safety precautions. The responsibilities of the position require frequent travel and may subject the incumbent to various resultant environmental changes; incumbent must be amenable to such period of travel and to working in unfamiliar surroundings. This position requires occasional travel using both air and ground transportation.

For more information on these qualification standards, please visit the United States Office of Personnel Management's website at https://www.opm.gov/policy-data-oversight/classification-qualifications/general-schedule-qualification-standards/.

Education

There is no educational substitution at this grade level.

Additional information

Under the Fair Chance to Compete Act, the Department of Veterans Affairs prohibits requesting an applicant's criminal history prior to accepting a tentative job offer. For more information about the Act and the complaint process, visit Human Resources and Administration/Operations, Security, and Preparedness (HRA/OSP) at The Fair Chance Act.

Receiving Service Credit or Earning Annual (Vacation) Leave: Federal Employees earn annual leave at a rate (4, 6 or 8 hours per pay period) which is based on the number of years they have served as a Federal employee. VA may offer newly-appointed Federal employee's credit for their job-related non-federal experience or active duty uniformed military service. This credited service can be used in determining the rate at which they earn annual leave. Such credit must be requested and approved prior to the appointment date and is not guaranteed.

This job opportunity announcement may be used to fill additional vacancies.

If you are unable to apply online or need an alternate method to submit documents, please reach out to the Agency Contact listed in this Job Opportunity Announcement.

The Interagency Career Transition Assistance Plan (ICTAP) and Career Transition Assistance Plan (CTAP) provide eligible displaced VA competitive service employees with selection priority over other candidates for competitive service vacancies. To be qualified you must submit appropriate documentation (a copy of the agency notice, your most recent performance rating, and your most recent SF-50 noting current position, grade level, and duty location) and be found well-qualified for this vacancy. To be well-qualified: applicants must possess experience that exceeds the minimum qualifications of the position including all selective factors, and who are proficient in most of the required competencies of the job. Information about ICTAP and CTAP eligibility is on OPM's Career Transition Resources website at http://www.opm.gov/policy-data-oversight/workforce-restructuring/employee-guide-to-career-transition/.

Expand Hide additional information

Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution.

Benefits

Help

A career with the U.S. government provides employees with a comprehensive benefits package. As a federal employee, you and your family will have access to a range of benefits that are designed to make your federal career very rewarding. Opens in a new windowLearn more about federal benefits.

Review our benefits

Eligibility for benefits depends on the type of position you hold and whether your position is full-time, part-time or intermittent. Contact the hiring agency for more information on the specific benefits offered.

Similar Jobs

More Jobs at Commander, Navy Installations Command

More Information Technology Jobs

Find similar IT Specialist (Security) jobs: