United States Courts

Supervisory Information Technology Specialist (Security)

United States Courts$108K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in cybersecurity leadership roles
  • Proven expertise in cyber threat intelligence and detection engineering
  • Strong background in threat hunting and incident response
  • Experience managing security operations in a 24/7 environment
  • Ability to develop and validate detection methodologies

Responsibilities

  • Lead and manage the Security Operations Support Branch
  • Oversee detection logic development for identifying malicious activities
  • Direct proactive threat hunting for emerging adversary behaviors
  • Establish detection engineering standards and quality assurance
  • Coordinate with the Security Operations Center for improving investigative outcomes

Benefits

  • Access to a comprehensive federal benefits package
  • Eligibility for retirement plans and health insurance
  • Opportunities for professional development and training
  • Paid time off and holidays
  • Access to employee assistance programs
Full Job Description
Summary

This position is in the Department of the Chief Information Officer, Information Technology Security Office, Security Operations Division, Security Operations Support Branch. The Security Operations Division protects the judiciary from cyber threats, strengthens the judiciary's security posture and threat awareness, eliminates threats before they can harm operations, and provides evaluation services to strengthen systems and programs.

Duties

Help

The Supervisory Information Technology Specialist (Security) is in the Information Technology Security Office's Security Operations Division and serves as the Security Operations Support Branch Chief. The Security Operations Branch delivers enterprise detection engineering, threat hunting, threat intelligence, and insider threat capabilities in support of continuous cybersecurity operations. This position reports to the Security Operations Division Chief.

The incumbent is a recognized cyber-security subject matter expert with a strong defensive cybersecurity background and is responsible for leading detection engineering, threat hunting, threat intelligence and insider threat teams to identify cybersecurity threats impacting the confidentiality, integrity, or availability of judicial data.

the Supervisory Information Technology Specialist (Security) leads hypothesis-based threat hunting to identify, investigate, and mitigate advanced persistent threats, zero-day vulnerability abuse, and other malicious activity to bypass traditional security controls. The incumbent lead detection engineering to categorize known attack vectors through the security information and event management. The incumbent is responsible for the threat intelligence program, reporting on malicious threat actors, and identifying insider threats to judiciary data and systems.

  1. Leading, directing, and overseeing the Security Operations Support Branch.
  2. Overseeing the development, testing, deployment, and lifecycle management of detection logic used to identify malicious activity.
  3. Leading the production and operational integration of threat intelligence to inform detection engineering priorities, hunting hypotheses, and risk-based decision making.
  4. Directing proactive threat hunting activities to identify emerging, novel, or evasive adversary behavior not covered by existing detection mechanisms.
  5. Establishing and maintaining detection engineering standards, methodologies, and quality assurance processes to support accuracy, consistency, and operational effectiveness.
  6. Overseeing the validation, tuning, and refinement of detections based on operational feedback, adversary emulation results, and observed threat activity.
  7. Ensuring development of metrics and reporting to measure detection coverage, effectiveness and operational maturity.
  8. Leading the development and maintenance of a common operational picture that identifies baseline behavior and meaningful deviations to support shared situational awareness, prioritization and leadership decision making.
  9. Providing regular executive summaries to senior leadership and judiciary cybersecurity stakeholders for informed enterprise risk understanding prioritization, and resource allocation decisions.
  10. Coordinating closely with Security Operations Center to support alert fidelity, investigative workflows, and continuous improvement of analytic outcomes.
  11. Managing branch personnel, contractor support, and resource planning to sustain required capabilities.


Requirements

Help

Conditions of employment

CONDITIONS OF EMPLOYMENT

  1. All information is subject to verification. Applicants are advised that false answers or omissions of information on application materials or inability to meet the following conditions may be grounds for non-selection, withdrawal of an offer of employment, or dismissal after being employed.
  2. Selection for this position is contingent upon completion of OF-306, Declaration of Federal Employment during the pre-employment process and proof of U.S. citizenship for competitive status positions or conversion to a competitive status position with the AO. If non-citizens are considered for hire into a temporary or any other position with non-competitive status or when it is confirmed by the AO Human Resources Office there are no qualified U.S. citizens for a competitive status position (unless prohibited by a law or statue), non-citizens must provide proof of authorization to work in the U.S. and proof of entitlement to receive compensation. Additional information on the employment of non-citizens can be found at USAJOBS Help Center | Employment of non-citizens/. For a list of documents that may be used to provide proof of citizenship or authorization to work in the United States, please refer to Form I-9, Employment Eligibility Verification.
  3. All new AO employees will be required to complete an FBI fingerprint-based national criminal database and records check and pass a public trust suitability check.
  4. New employees to the AO will be required to successfully pass the E-Verify employment verification check. To learn more about E-Verify, including your rights/responsibilities, visit https://www.e-verify.gov/.
  5. All new AO employees are required to identify a financial institution for direct deposit of pay before appointment.
  6. You will be required to serve a trial period if selected for a first-time appointment to the Federal government, transferring from another Federal agency, or serving as a first-time supervisor. Failure to successfully complete the trial period may result in termination of employment.
  7. If appointed to a temporary position, management may have the discretion of converting the position to permanent depending upon funding and staffing allocation.


Qualifications

Applicants must have demonstrated experience as listed below. This requirement is according to the AO Classification, Compensation, and Recruitment Systems which include interpretive guidance and reference to the OPM Operating Manual for Qualification Standards for General Schedule Positions.

Specialized Experience: Applicants must have at least one full year (52 weeks) of specialized experience which is in or directly related to the line of work of this position. Specialized experience is demonstrated experience in ALL of the following:

  1. Leading cyber threat intelligence, threat hunting, and detection engineering in support of 24/7 security operation center.
  2. Analyzing and integrating threat intelligence from open-source and classified sources.
  3. Developing detection methodologies.
  4. Conducting proactive threat hunting to identify and mitigate cyber threats.


Desired Education:

Bachelor's degree in computer science, cybersecurity, or equivalent technical field is highly desired.

Desired (but not required certification):

  • Offensive Security Professional (OSCP)
  • GIAC Reverse Engineering Malware (GREM)
  • GIAC Exploit Researcher
  • Advanced Penetration Tester (GXPN)


Education

This position does not require education to qualify.

Additional information

Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution.

Benefits

Help

A career with the U.S. government provides employees with a comprehensive benefits package. As a federal employee, you and your family will have access to a range of benefits that are designed to make your federal career very rewarding. Opens in a new windowLearn more about federal benefits.

Review our benefits

Eligibility for benefits depends on the type of position you hold and whether your position is full-time, part-time or intermittent. Contact the hiring agency for more information on the specific benefits offered.

Similar Jobs

More Jobs at United States Courts

More Information Technology Jobs

Find similar Supervisory Information Technology Specialist (Security) jobs: