Skip to main content
IT Specialist (Security)
JOB

IT Specialist (Security)

  • Job
  • Full-time

Incumbent serves as an IT Specialist (Security) within the Cybersecurity Support Services Section, AMK-231.

Responsibilities
  • Applies project management principles and detailed knowledge about Information Technology to create and maintain security documents such as Business Impact Assessments (IA), System Security Plans (SSP), Information System Contingency Plans (ISCP), System Characterization Document (SCD), Configurations Management Plans (CMP), Privacy Impact Analysis (PIA) and other security documents. Provides intermediate level advice and assistance in the areas of security architecture, systems auditing, security tools, and all areas related to Information Security. Duties also include acquiring/maintaining systems authorization, providing audit support, and initiating protective or corrective actions if security risks are identified. Plans, coordinates, and evaluates vulnerability system scanning, ISCP exercises, and other Information Security related activities. Work is reviewed periodically by team lead during assigned tasks and at completion to ensure timeliness and quality. Work activities typically support the work of other employees and contribute to activities of the organization. Applies detailed technical knowledge to evaluate security controls on a variety of information system platforms (Windows, Linux/Unix, etc.), databases (Oracle, MS-SQL, MySQL), and networking technology. Researches, verifies, complies, and summarizes systems support data and information, using Microsoft Office, Project, and Visio. This is a highly visible position that supports multiple Federal agencies throughout the United States. Periodically develops reports and provides system status briefings to management at all levels throughout the Federal Government as required. Advises manager, team leads, and peers of known and projected program deviations related to security issues pertaining to facilities, communications, personnel, hardware, and software in accordance with federal guidelines and policies. Contacts are internal and external to the organizational unit, to include interactions with mid-level management personnel. Conducts risk and vulnerability assessments of planned and installed information systems to identify vulnerabilities, risks, and protection needs. Develops system security contingency plans and disaster recovery procedures. Established policies/procedures provide guidance for most assignments, but allow some discretion to select the most appropriate approach. Typically receives guidance on selecting approach from a manager, project/program manager, team leader, or more experienced technical specialist. Implements, maintains, and conducts on-site and remote analyses of information system standard security products and associated systems in order to determine overall technical features and standard security protection required for IS and networks at all levels of information security. Provides technical assistance and security guidance in the areas of information systems and telecommunications to information systems owners, technicians, and general users. Characteristic information technology assignments in the Security specialization at this pay band include: Implements and disseminates standard IT security tools, procedures, and practices to protect information assets. Plans and coordinates the delivery of an IT security awareness training program for end users at all levels in the organization. Evaluates established security authentication technologies such as public key infrastructure certificates, secure cards, and biometrics for adoption in various FAA environments. Administers and monitors implementation of authentication software. Identifies and specifies standard information systems security requirements associated with migrations to new IT environments/applications and provides guidance in planning and implementing migration activities. Reviews specifications for procurement of new but established software to ensure compliance with security requirements at the systems or LAN level.
Education

Refer to Qualifications. Information Regarding KSA's: As a part of the Federal-Wide Hiring Reform Initiative (streamlining the hiring process), the FAA is committed to eliminating the use of the Knowledge, Skills and Ability (KSA) narratives from the initial application in the hiring process for all announcements. Therefore, as an applicant for this announcement, you are NOT required to provide a narrative response in the text box listed below each KSA. In lieu of providing a KSA narrative response in the text box listed below each KSA, in your work history, please include information that provides specific examples of how you meet the response level or answer you chose for each KSA. Your work history examples should be specific and clearly reflect the highest level of ability.

Your KSA answers will be evaluated further to validate whether the level that you selected is appropriate based on the work history and experience you provided. Your answers may be adjusted by a Human Resource Specialist as appropriate. Eligible applicants meeting the minimum qualification requirements and selective factor(s), if applicable, may be further evaluated on the Knowledge, Skills and Abilities (KSA) and Other Factors listed in the announcement.

Based on this evaluation, applicants will be placed in one of the following categories: score order, category grouping, or alphabetical and referred to the selecting official for consideration.

Requirements

We are not accepting applications from noncitizens.

Required Documents

A Notification of Personnel Action (SF-50) is required to verify area of consideration. Other supplemental documentation will be accepted in combination with your online application. These documents must be included with your application or emailed to [email protected] on or before the closing date of this announcement. All emailed documents should reference the announcement number.

If you are an FAA employee, you MUST provide a copy of your SF-50 (Notification of Personnel Action) containing information in Blocks 15, 17, 18, 19, 22, and 24 so it can be used to verify your position title, series, grade, tenure, and organization of record by the closing date of the announcement. You may fax your SF-50 or upload it into the on-line application. If faxing the SF-50, please ensure you include the vacancy announcement number on the faxed copy.

If you are an FAA employee, you can access and print your SF-50 from the eOPF system https://eopf.opm.gov/dot/.