Duties
Applies project management principles and detailed knowledge about Information Technology to create and maintain security documents such as Business Impact Assessments (IA), System Security Plans (SSP), Information System Contingency Plans (ISCP), System Characterization Document (SCD), Configurations Management Plans (CMP), Privacy Impact Analysis (PIA) and other security documents.
Provides intermediate level advice and assistance in the areas of security architecture, systems auditing, security tools, and all areas related to Information Security. Duties also include acquiring/maintaining systems authorization, providing audit support, and initiating protective or corrective actions if security risks are identified. Plans, coordinates, and evaluates vulnerability system scanning, ISCP exercises, and other Information Security related activities.
Work is reviewed periodically by team lead during assigned tasks and at completion to ensure timeliness and quality. Work activities typically support the work of other employees and contribute to activities of the organization.
Applies detailed technical knowledge to evaluate security controls on a variety of information system platforms (Windows, Linux/Unix, etc.), databases (Oracle, MS-SQL, MySQL), and networking technology. Researches, verifies, complies, and summarizes systems support data and information, using Microsoft Office, Project, and Visio.
This is a highly visible position that supports multiple Federal agencies throughout the United States. Periodically develops reports and provides system status briefings to management at all levels throughout the Federal Government as required. Advises manager, team leads, and peers of known and projected program deviations related to security issues pertaining to facilities, communications, personnel, hardware, and software in accordance with federal guidelines and policies. Contacts are internal and external to the organizational unit, to include interactions with mid-level management personnel.
Conducts risk and vulnerability assessments of planned and installed information systems to identify vulnerabilities, risks, and protection needs. Develops system security contingency plans and disaster recovery procedures.
Established policies/procedures provide guidance for most assignments, but allow some discretion to select the most appropriate approach. Typically receives guidance on selecting approach from a manager, project/program manager, team leader, or more experienced technical specialist.
Implements, maintains, and conducts on-site and remote analyses of information system standard security products and associated systems in order to determine overall technical features and standard security protection required for IS and networks at all levels of information security.
Provides technical assistance and security guidance in the areas of information systems and telecommunications to information systems owners, technicians, and general users.
Characteristic information technology assignments in the Security specialization at this pay band include:
- Implements and disseminates standard IT security tools, procedures, and practices to protect information assets.
- Plans and coordinates the delivery of an IT security awareness training program for end users at all levels in the organization.
- Evaluates established security authentication technologies such as public key infrastructure certificates, secure cards, and biometrics for adoption in various FAA environments.
- Administers and monitors implementation of authentication software.
- Identifies and specifies standard information systems security requirements associated with migrations to new IT environments/applications and provides guidance in planning and implementing migration activities.
- Reviews specifications for procurement of new but established software to ensure compliance with security requirements at the systems or LAN level.
Requirements
Conditions of employment
- US Citizenship is required.
- Selective Service Registration is required for males born after 12/31/1959.
- Must submit an SF50 (See Required Documents).
- A one-year probationary period may be required.
- Successful completion of a security investigation may be required.
- Please review Required Documents & Additional Information.
Qualifications
BASIC REQUIREMENTS:
To qualify for this position at the FV-H (FG/GS 10-12) level, you must demonstrate in your application that you possess at least one year of specialized experience equivalent to FV-G (FG/GS 5-9) level. Specialized experience is experience that has equipped you with the particular knowledge, skills, and abilities to perform successfully the duties of the position.
Specialized Experience includes: management of ISS projects that require extensive knowledge of IT hardware/software technology; experience preparing ISS systems documentation for certification/accreditation in accordance with FISMA, FedRAMP, and/or other federal IS guidelines or regulations; experience monitoring and evaluating systems¿ compliance with IT security requirements
Applicants should include examples of Specialized Experience in their work history
AND
IT-related experience demonstrating each of the four competencies listed below. The experience may be demonstrated by paid or unpaid experience and/or completion of specific, intensive training (for example, IT certification), as appropriate.
1. Attention to Detail - Is thorough when performing work and conscientious about attending to detail.
2. Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services.
3. Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately.
4. Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations.
OR
Education substitution:
Successful completion of a Ph.D. or equivalent doctoral degree or 3 full years of progressively higher level graduate education leading to a Ph.D. or equivalent doctoral degree. Degree in computer science, engineering, information science, information systems management, mathematics, operations research, statistics, or technology management or degree that provided a minimum of 24 semester hours in one or more of the fields identified above and required the development or adaptation of applications, systems or networks.
OR
Combination Education and Experience: May be qualifying for this position. Refer to OPM's Operating Manual Qualification Standards at, https://www.opm.gov/policy-data-oversight/classification-qualifications/general-schedule-qualification-standards/#url=GS-ADMIN for more information.
AND
In addition to the minimum qualifications, the following has been determined to be a selective factor for this position. This means possession of this criterion is part of the minimum qualifications and is essential to perform the duties and responsibilities of this position. Applicants who do not possess this criterion are ineligible for further consideration.
Selective Placement Factor (SPF): Applicant must possess one or more current intermediate level Information Security certifications from one of the following governing bodies:
- Comp TIA
- ISACA
- EC-Council
- Global Information Assurance Certification (GIAC)
- International Information System Security Certification Consortium (ISC2)
- International Association of Privacy Professionals (IAPP)
Applicants must submit proof documentation of the certification(s) they hold.
ALSO
Quality Ranking Factor (QRF): Well-qualified candidates will have demonstrated experience and possession of the following areas: Addressing information Systems Security concerns of an organization by applying the Risk Management Framework (RMF) Security Life Cycle as an information security professional with experience creating and/or managing (in accordance with NIST or other Federal Departmental/Agency guidelines and regulations) the following: BIA, SSP, ISCP, SCD, CMP, PIA, and other security documents. Installing, maintaining, managing, and/or securing IT network devices or physical/virtual servers running on a variety of platforms (e.g. Linux/UNIX, Windows, Solaris, Oracle, SQL, MySQL, Cisco, etc.).
Qualifications must be met by the closing date of this vacancy announcement
Education
Refer to Qualifications.
Information Regarding KSA's:
As a part of the Federal-Wide Hiring Reform Initiative (streamlining the hiring process), the FAA is committed to eliminating the use of the Knowledge, Skills and Ability (KSA) narratives from the initial application in the hiring process for all announcements. Therefore, as an applicant for this announcement, you are NOT required to provide a narrative response in the text box listed below each KSA.
In lieu of providing a KSA narrative response in the text box listed below each KSA, in your work history, please include information that provides specific examples of how you meet the response level or answer you chose for each KSA. Your work history examples should be specific and clearly reflect the highest level of ability. Your KSA answers will be evaluated further to validate whether the level that you selected is appropriate based on the work history and experience you provided. Your answers may be adjusted by a Human Resource Specialist as appropriate.
Eligible applicants meeting the minimum qualification requirements and selective factor(s), if applicable, may be further evaluated on the Knowledge, Skills and Abilities (KSA) and Other Factors listed in the announcement. Based on this evaluation, applicants will be placed in one of the following categories: score order, category grouping, or alphabetical and referred to the selecting official for consideration.
Make sure your resume includes detailed information to support your qualifications and answers to the job questionnaire.
Additional information
We may use this vacancy to fill other similar vacant positions.
Position may be subject to a background investigation.
A one-year probationary period may be required.
The person selected for this position may be required to file a financial disclosure statement within 30 days of entry on duty. FAA policy limits certain outside employment and financial investments in aviation-related companies. www.faa.gov/jobs/workinghere/financial-disclosure-requirements
NOTES:
1) Applicants must apply online to receive consideration for this vacancy announcement. Faxed, mailed, or emailed applications cannot be accepted.
2) Please ensure you answer all questions and follow all instructions carefully. Errors or omissions may impact your rating or may result in you not being considered for the job.
3) Some, all or none of the applicants may be interviewed.
4) This position is covered by the FAA Core Compensation plan. Additional information about core compensation is available on the following website: http://jobs.faa.gov/FAACORECompensation.htm
5) Position(s) may be realigned based on approved reorganization.
6) Additional information regarding living in Oklahoma can be found at www.abetterlifeokc.com
7) To confirm receipt of documents, please contact Caleb Weston at Caleb.A.Weston@faa.gov.
Links to Important Information: Locality Pay, COLA
Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution.
A career with the U.S. government provides employees with a comprehensive benefits package. As a federal employee, you and your family will have access to a range of benefits that are designed to make your federal career very rewarding. Opens in a new windowLearn more about federal benefits.
Review our benefits
Eligibility for benefits depends on the type of position you hold and whether your position is full-time, part-time or intermittent. Contact the hiring agency for more information on the specific benefits offered.