Job opening: Information Technology Specialist (Security)
Salary: $94 199 - 176 555 per year
Published at: Sep 14 2023
Employment Type: Full-time
The Information Technology Specialist (Security) position is located in the Department of Administrative Services (DAS), Administrative Systems Office (ASO), Security and Data Integration Staff (SDIS). The SDIS is responsible for administering and overseeing the system security requirements for various Human Resources, Financial, Facilities and AO Support applications and information systems.
Duties
This position will be report to the Deputy Chief of the Security and Data Integration Staff (SDIS) in the Administrative Systems Office (ASO). The ASO is seeking a self-motived professional Information Technology Specialist (Security) to serve as an Information Systems Security Officer administering and overseeing the system security program for the various applications and information systems within the Human Resources, Financial, Facilities, and AO Support portfolios. The incumbent will be the primary advisor to the Chief and Deputy Chief of the SDIS and various Portfolio Managers on information security matters pertaining to assigned applications and systems.
The incumbent will be providing recommendations concerning safeguarding of information systems and conducting comprehensive assessments of the management, operational, and technical security controls employed within or inherited by an information system to determine the overall effectiveness of the controls. Also, the incumbent will be reviewing information systems to identify potential security weaknesses, recommends improvements to address vulnerabilities, implements changes and documents upgrades. The ideal candidate must have excellent communication skills with all levels, from end users to executives.
The duties of the position include, but are not limited to:
Communicating Judiciary security policies, procedures, and safeguards for all applications and information systems assigned; and coordinating the tracking of remediation actions to mitigate risks in accordance with established policies and procedures.
Developing and maintaining security documentation, including system security plans, incident response plans, contingency plans, and all applicable security documentation.
Analyzing and advising on the risk and remediation of security issues based on reports from vulnerability assessment scanners, patch management tools, and emerging threat information.
Ensuring risk assessments are conducted periodically to re-evaluate the security and risk posture of the system and mitigation strategies, as well as to assess the impact of new requirements.
Developing remediation plans, along with stakeholders, for discovered vulnerabilities and documenting them in Plan of Actions and Milestones (POA&M).
Assisting with investigations into security violations related to applications and information systems assigned; and ensuring corrective actions are implemented and information security incidents are handled in accordance with Judiciary policies and procedures.
Participating in associated security and change control boards for assigned applications and information systems and evaluating the risk impact of proposed changes to the Judiciary.
Conducting meetings and briefings with Project Managers, Portfolio Managers, Business Owners, and System Owners on the state of security for the systems under their purview.
Ensuring information security is addressed in the development and acquisition process of all applications and information systems assigned consistent with the Judiciary's System Development Life cycle (SDLC); and reviewing new and existing information security technologies to support secure engineering across SDLC phases.
Ensuring security assessments and continuous monitoring activities are conducted for all applications and information systems assigned to ensure effective implementation and compliance with established policies and procedures.
Creating, maintaining, and updating security related documentation for all applications and information systems assigned to include, risk assessments, system security plans, security manuals, contingency plans, and incident response plans.
Working with system and business stakeholders to determine the information type and system impact levels and determine the control baseline for protection of those systems and data.
Ensuring Judiciary policies, procedures, and practices are followed related to the applications and information systems assigned; and validating engineered information security and application security controls meet the specified requirements.
Qualifications
Applicants must have demonstrated experience as listed below. This requirement is according to the AO Classification, Compensation, and Recruitment Systems which include interpretive guidance and reference to the OPM Operating Manual for Qualification Standards for General Schedule Positions.
Specialized Experience: Applicants must have at least one full year (52 weeks) of specialized experience which is in or directly related to the line of work of this position. Specialized experience must demonstrate experience in ALL areas defined below:
Managing an information security program for IT applications and infrastructure;
Developing system security plans and supporting documentation in remediating security weaknesses; and
Experience documenting security controls, processes, and improvements.
Highly Desired:
Knowledge of NIST SP 800-53 or other Federal guidance.
Knowledge of current security tools and hardware/software security implementation.
Knowledge of communication protocols and encryption techniques/tools.
Applicant with the following certification is highly desirable:
Certified Information Systems Security Professional (CISSP) Certification
Education
This position does not require education to qualify.
Contacts
- Address Department of Administrative Services
One Columbus Circle, NE
Washington, DC 20544
US
- Name: Ahniya Roberts
- Phone: 202-502-3800
- Email: [email protected]
Map