IT-related experience; experience may be demonstrated by paid or unpaid experience and/or completion of specific, intensive training (for example, IT certification), as appropriate. Experience must have demonstrated each of the four competencies listed below.
- Attention to Detail - Is thorough when performing work and conscientious about attending to detail.
- Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services.
- Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately.
- Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations.
Desirable Qualifications
Certification in one or more of the following: CISSP, CCSP OSCP, GIAC technical practitioner
For the GS-14: You must have one year of specialized experience equivalent to the GS-13 level in federal service.
Specialized experience must include demonstrated experience in leading and coordinating incident response activities to include detection, analysis, containment, eradication, and/or recovery; conducting threat intelligence and analysis techniques to include utilizing threat intelligence to proactively identify and mitigate potential threats; and applying security monitoring and detection methods to include ensuring continuous monitoring of networks, systems, and applications for security anomalies; and performing malware analysis techniques to include conducting static and dynamic malware analysis to understand malware behavior and impact; and serving as a working professional and utilizing technical knowledge and hands-on experience with security tools and processes. This includes administrating incident handling (IH) and response (IR), security incident and event management (SIEM) dashboards, inputs, "playbooks" and metrics to achieve efficiency; demonstrated ability to enhance SIEM, associated SOC/SECOPS toolsets and procedures to sustain posture, achieve cybersecurity maturity as well as sufficient continuous monitoring (CONMON); develop or maintain organizations cybersecurity policy incident and event monitoring (SIEM) triage and response procedures standard in compliance with established laws or regulations; provides guidance to staff on standardized approach for secure cloud offerings in support of secure services. Identify technical threat vectors, advanced persistent threats (APT), attack surface or weaknesses then implements practical technical mitigations and remediation where available.
Applicants must meet all eligibility requirements (e.g., time-in-grade and qualification requirements) within 30 days of the closing date specified in the vacancy announcement.
Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic; religious; spiritual; community, student, social). Volunteer work helps build critical competencies, knowledge, and skills and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.