Skip to main content
U.S. flag
Back to results

IT SPECIALIST (INFOSEC)

Securities and Exchange Commission
Office of Information Technology, Cybersecurity Analysis Branch
This job announcement has closed

Summary

This position is location in the Office of Information Technology in Washington DC.

Overview

Help
Hiring complete
Open & closing dates
05/16/2023 to 05/30/2023
This job will close when we have received 150 applications which may be sooner than the closing date. Learn more
Salary
$140,830 to - $238,592 per year

Starting salary is based on experience. The range is listed for informational purposes. Initial pay will be set below the maximum. See more below.

Pay scale & grade
SK 14
Location
1 vacancy in the following location:
Washington
Remote job
No
Telework eligible
Yes—as determined by the agency policy.
Travel Required
Not required
Relocation expenses reimbursed
No
Appointment type
Permanent
Work schedule
Full-time
Service
Competitive
Promotion potential
14
Supervisory status
No
Security clearance
Top Secret
Drug test
Yes
Position sensitivity and risk
Critical-Sensitive (CS)/High Risk
Trust determination process
Announcement number
23-DH-11958384-SH
Control number
726125400

Videos

Duties

Help

At the Securities and Exchange Commission (SEC), we are committed to diversity, equity, inclusion and accessibility (DEIA) and value a workforce that reflects the diverse experiences and perspectives of the communities we serve. As such, we welcome applications from qualified individuals of all backgrounds who share our commitment to public service.

Typical duties:

  • Creating new intrusion detection mechanisms that identify cybersecurity incidents, and automating common incident response activities using Splunk Search Processing Language (SPL) with a high degree of proficiency.
  • Leveraging data extraction and analysis tools, with a high degree of proficiency, to include but not limited to: Perl Compatible Regular Expressions (PCRE), GNU Coreutils, CyberChef, Python modules, Microsoft Excel/Splunk Pivot Tables, SPL, etc.
  • Proficiency with Python 3.x and/or PowerShell for automating multi-platform enterprise infrastructure tasks associated with cybersecurity analysis and incident response.
  • Forming sound analytical assessments by systematically applying the Lockheed Martin Cyber Kill Chain®, the "The Diamond Model of Intrusion Analysis", and MITRE ATT&CK framework against all available data during the course of analysis.
  • Conducting static and dynamic malware analysis, evaluating network packet captures (PCAP), and analyzing log of multi- platform/multi-cloud enterprise environments.
  • Evaluating, generating, and applying detections associated with cyber threat intelligence with a high degree of proficiency.
  • Coordinating a team of analysts during complex incident response activities.
  • Communicating effectively with colleagues and senior leadership from technical and non-technical backgrounds on the status of ongoing incident response efforts.

Requirements

Help

Conditions of employment

  • You must be a US Citizen.
  • Application procedures are specific to this vacancy announcement. Please read all the instructions carefully. Failure to follow the instructions may result in you not being considered for this position.
  • Supplementary vacancies may be filled in addition to the number stated in this announcement.
  • This position has promotion potential to the SK-14.
  • PROBATIONARY PERIOD: This appointment may require completion of a one-year probationary period.
  • SECURITY CLEARANCE: Entrance on duty is contingent upon completion of a pre-employment security investigation. Favorable results on a Background Investigation may be a condition of employment or selection to another position.
  • PERMANENT CHANGE OF STATION (PCS): Moving/Relocation expenses are not authorized.
  • DIRECT DEPOSIT: All Federal employees are required to have Federal salary payments made by direct deposit to a financial institution of their choosing.
  • This position is in the collective bargaining unit.
  • This position is eligible to request telework in accordance with the SEC 's telework policy.
  • This announcement will close when we have received 150 applications which may be sooner than the closing date.
  • DRUG TESTING: This position is subjected to drug testing requirements.

Qualifications

All qualification requirements must be met by the closing date of this announcement.

Qualifying experience may be obtained in the private or public sector. Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic; religious; spiritual; community, student, social). Volunteer work helps build critical competencies, knowledge, and skills and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.

BASIC REQUIREMENT: Possess IT related experience demonstrating each of the four competencies: reviewing work to ensure it is in line with established standards or to identify deficiencies (Attention to Detail); collaborating with customers to identify their information technology needs or to resolve their hardware and software problems (Customer Service); explaining technical information orally to non- technical audiences (Oral Communication); and evaluating alternatives to recommend solutions to hardware or software problems (Problem Solving).

MINIMUM QUALIFICATION REQUIREMENT: In addition to meeting the basic requirement, applicants must also meet the minimum qualification requirement.
SK-14: Applicant must have at least one year of specialized experience equivalent to the GS/SK-13 level: 1) Performing historical and near real-time network traffic and log analysis; 2) performing static and dynamic analysis of suspect websites, documents, binaries, or other artifacts; AND 3) automating analytical tasks related to network defense and incident response.

Additional information

SEC COMPENSATION PROGRAM: The overall salary range listed above is provided for informational purposes as it represents the full range that is applicable to current employees in this occupation/grade; however, a selectee's initial pay is always set below the maximum rate of the range. Please click here for additional information.

IMPORTANT INFORMATION FOR SURPLUS OR DISPLACED FEDERAL EMPLOYEES: Career Transition Assistance Plan (CTAP) and Interagency Career Transition Assistance Plan (ICTAP) are available to individuals who have special priority selection rights under this plan. Individuals must be well-qualified for this position to receive consideration for special priority selection. CTAP or ICTAP eligibles will be considered well-qualified when receiving an adjudicated score of 80 or higher.

Reasonable Accommodation: If you are an applicant who needs a reasonable accommodation for disability to participate in the application process at the SEC, submit the form for Reasonable Accommodation for Participation in Job Application Process here. Please be sure to submit your request at least 5 business days in advance of the date you need the requested accommodation.

Equal Employment Opportunity (EEO) Information for SEC Job Applicants: Federal EEO laws protect all applicants from discrimination on the following bases: race, color, sex (not limited to conduct which is sexual in nature, includes pregnancy, gender identity, sexual orientation, transgender status), age (40 and over), religion, national origin, disability, genetic information, retaliation for participating in the EEO process or opposing discrimination. Applicants who believe they have been discriminated against on any EEO basis can seek recourse through the SEC's administrative complaints process. To be timely, an individual must enter the EEO process within 45 days from when they know (or should have known) of the alleged discrimination. Click here for additional information.

TTY/ASCII: Video Relay Service users are welcome to contact the appropriate SEC office or employee via the contact information listed above. If you do not otherwise have access to a Video Phone or Video Relay service, you may send us an email or use the Federal Video Relay Service via the internet. For more information about using the Federal Relay Service and to create a new account, please see: https://www.federalrelay.us/

How you will be evaluated

You will be evaluated for this job based on how well you meet the qualifications above.

This position is being advertised through the Office of Personnel Management's (OPM) Delegated Direct-Hire Authority (5 U.S.C. Section 3304 and 5 CFR Part 337, Subpart B) and is open to All U.S. Citizens. Under this authority, competitive rating, ranking and veterans' preference procedures do not apply.

We will review your resume and supporting documentation to determine if you meet the minimum qualifications for the position. If you meet the minimum qualifications stated in the vacancy announcement, we will compare your resume and supporting documentation to your responses on the occupational questionnaire. Your resume must support your responses to the occupational questionnaire.

Your qualifications will be evaluated on the following competencies (knowledge, skills, abilities and other characteristics):

  • Information Systems/Network Security and Writing
The Occupational Questionnaire will take you approximately 20 minutes to complete. To preview the Occupational Questionnaire, click the following link https://apply.usastaffing.gov/ViewQuestionnaire/11958384.

Your session is about to expire!

Your USAJOBS session will expire due to inactivity in 8 minutes. Any unsaved data will be lost if you allow the session to expire. Click the button below to continue your session.