Skip to main content
U.S. flag
Back to results

IT Specialist (Vulnerability Management) (Infosec)

Federal Communications Commission
This job announcement has closed

Summary

This position is located in the Cybersecurity Group, Office of Chief Information Officer (OCIO), Office of Managing Director (OMD), Federal Communications Commission (FCC), located in Washington, DC.

RELOCATION EXPENSES WILL NOT BE PAID.  

THIS VACANCY ANNOUNCEMENT MAY BE USED TO FILL ADDITIONAL POSITIONS WITHIN 90 DAYS.

Overview

Help
Hiring complete
Open & closing dates
09/27/2024 to 10/14/2024
Salary
$117,962 to - $153,354 per year
Pay scale & grade
GS 13
Location
1 vacancy in the following location:
District of Columbia, DC
Remote job
No
Telework eligible
Yes—as determined by the agency policy.
Travel Required
Occasional travel - Occasional travel may be required
Relocation expenses reimbursed
No
Appointment type
Permanent
Work schedule
Full-time - This is a full-time position. Work schedules, including telework, are at the discretion of the supervisor, consistent with agency policy.
Service
Competitive
Promotion potential
13 - This position is at the full performance level
Supervisory status
No
Security clearance
Sensitive Compartmented Information
Drug test
Yes
Position sensitivity and risk
Special-Sensitive (SS)/High Risk
Trust determination process
Financial disclosure
No
Bargaining unit status
No
Announcement number
DHA-OMD-2024-007
Control number
811857800

This job is open to

Help

Clarification from the agency

OPEN TO THE PUBLIC - Open to all U.S. Citizens. Individuals who typically apply for positions under other authorities may also apply competitively to this position. (e.g. VRA, Schedule A, Peace Corps, Students, Recent Graduates, Military Spouses, National Guard, Indian Preference, Land Management, Family of Overseas Employees, Federal Employees, Agency Employees, ICTAP) Non-citizens may be eligible for this excepted service position under certain circumstances.

Duties

Help

This position is responsible for: reviewing vulnerability scanned reports (continuous scanning of the systems, identifying what’s needed to resolve the vulnerabilities, etc.); immediately responding to data calls put out by Cybersecurity and Infrastructure Agency (CISA); and managing the plan of action and milestones (POAM) for all information systems which are needed to allow FCC employees to complete their work.

Performs assessments of systems, service and networks within the FCC enterprise and identifies where those systems/networks/services deviate from acceptable baseline configurations, security/privacy policy, or federal mandates/directives. Measures effectiveness of defense-in-depth architecture against known vulnerabilities.

Reviews technical tests, network scans, vulnerability scans, and/or penetration testing results to evaluate the effectiveness of systems, devices, procedures, and methods used to safeguard FCC assets.

Reviews and analyzes vulnerability scan reports and results from security control assessments and works with appropriate teams within IT to remediate confirmed vulnerabilities in accordance with FCC and other federal policies, mandates, standards, and frameworks. Reviews threat and vulnerability assessment findings to quantify and prioritize the remediation of vulnerabilities in a system or service.

Determines deviations from acceptable configurations or enterprise or local policy, assesses the level of risk, and develops and/or recommends appropriate mitigation countermeasures in operational and non-operational situations.

Oversees, evaluates, and supports the documentation, validation, and accreditation processes necessary to assure that new IT systems/services meet applicable cybersecurity requirements at the organizational and federal level.

Performs technical (evaluation of technology) and nontechnical (evaluation of people and operations) risk and vulnerability assessments of relevant technology focus areas (e.g., local computing environment, network and infrastructure, enclave boundary, supporting infrastructure, and applications).

Identifies patterns of non-compliance to determine their impact on the enterprise's levels of risk and/or the cybersecurity program's overall effectiveness.

Monitors information security data sources to maintain organizational situational awareness.

Tracks and analyzes audit findings and may provide recommendations to ensure appropriate mitigation actions are taken.

Requirements

Help

Conditions of employment

  • US Citizenship.
  • Suitable for employment as determined by a background investigation.
  • Serve a probationary period of one year, if applicable.
  • Males born after 12/31/59 must be registered with Selective Service.
  • Financial disclosure statement may be required upon assuming the position.
  • Drug Testing Required.
  • Security Clearance Required

Please note your resume must thoroughly support your responses to the vacancy questions.  Your resume is an integral part of the process for determining if you meet the basic qualifications of the position and determining if you are to be among the best qualified.

Qualifications

Applicants must meet eligibility and qualification requirements by the closing date of this announcement.  Time in grade restrictions do not apply to Direct Hire procedures.

GS-13

In order to be deemed as qualified, candidates must have one year of specialized experience which is equivalent to at least the GS-12 grade level in the Federal service. Specialized experience is defined as follows:

1. Experience responding to data calls put out by Cybersecurity and Infrastructure Agency (CISA).
2. Experience conducting network scans, vulnerability scans, and/or penetration tests to evaluate the effectiveness of systems.
3. Experience reviewing and analyzing vulnerability scan reports to resolve confirmed vulnerabilities.
4. Experience identifying patterns which demonstrate or display technical security risks to an organization.

PART-TIME OR UNPAID EXPERIENCE: Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic; religious; spiritual; community, student, social). Volunteer work helps build critical competencies, knowledge, and skills and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.

Education

Any/all educational requirements (if applicable) are listed and outlined within the "Qualifications" section.

Additional information

EEO Policy Statement

Reasonable Accommodation Policy Statement

Veterans Information

Legal and Regulatory Guidance

Other:
-  Before hiring, an agency will ask you to complete a Declaration for Federal Employment to determine your suitability for Federal employment and to authorize a background investigation.  The agency will also ask you to sign and certify the accuracy of all the information in your application.  If you make a false statement in any part of your application, you may not be hired; you may be fired after you begin work; or you may be fined or jailed. If you are a male over age 18 who was born after December 31, 1959, you must have registered with the Selective Service System (or have an exemption) to be eligible for a Federal job.

-  If applicable, you will be required to serve a trial period of one year.

-  In order for you to be employed at the FCC, there are certain Commission and Federal laws governing the financial interests of you and members of your immediate family. If selected for the position, you must submit a financial disclosure statement upon assuming the position

How you will be evaluated

You will be evaluated for this job based on how well you meet the qualifications above.

All applicants will be rated on the extent and quality of experience and education relevant to the duties of the position.  The FCC determines the BEST QUALIFIED CANDIDATES based upon whether or not all of the qualification requirements have been met (education, basic experience requirements and specialized experience requirements).

As this position is being advertised under Direct Hire procedures, veterans preference does not apply.

A selecting official may make a selection from the list of candidates who are deemed as "Best Qualified".

Applicants under Merit Promotion will be considered in accordance with the agency's merit promotion plan and union agreement.

There are several parts to the application process that affect the overall evaluation of your application including:

1.  Resume-Must address the specialized experience
2.  SF-50-For current federal employees
3.  Supplemental documentation (e.g., DD-214, SF-50, SF-15, cover letter), if applicable; and
4.  Unofficial or official transcripts

Applicants will be rated ineligible if they do not meet all of the qualification requirements (education, basic experience requirements and specialized experience requirements).

You will be evaluated for this position on the following Knowledge, Skills, Abilities and Other characteristics (KSAOs):

  • Knowledge of a range of information systems vulnerabilities and protection concepts, principles and practices to resolve complex security and information systems controls challenges.
  • Knowledge of risk management, network security architecture concepts, including topology, protocols, components, and principles (e.g., application of defense-in-depth).
  • Knowledge and skill in applying IT systems security principles, concepts, and methods; for the infrastructure protection environment sufficient to develop long-range plans for IT security systems that anticipate, identify, evaluate, mitigate, and minimize risks associated with IT system vulnerabilities.
  • Knowledge and skill in applying information systems security laws, Executive directives, Federal mandates, Federal information systems protocols, systems security certification and accreditation requirements for the enterprise.

You may preview questions for this vacancy.

Your session is about to expire!

Your USAJOBS session will expire due to inactivity in 8 minutes. Any unsaved data will be lost if you allow the session to expire. Click the button below to continue your session.