Summary
As a Security Operations and Incident Response Lead, you will act as the Cyber Incident Commander for any serious IT security incidents. Location of position: The Office of the Chief Information Security Officer is responsible for delivering secure and exceptional technology solutions and experiences to GSA. Position can be filled in any of the following locations: Kansas City, MO; Fort Worth, TX; Washington, DC; Tacoma, WA; Lakewood, CO or Raleigh, NC.
Duties
We are currently filling two vacancies, but additional vacancies may be filled as needed. As a Security Operations and Incident Response Lead you will perform the following duties: Leads GSA's combined Incident Response/Security Operations Center (SOC) program, provides incident handling and digital forensics services (including forensics in virtualized environments), which includes documenting, tracking, and reporting all security incidents in accordance with GSA policy and Cybersecurity and Infrastructure Security Agency (CISA). Leads the GSA SOC and GSA Threat Hunting team to direct and analyze internal threat hunts and ensure ongoing monitoring for security alerting across the GSA Enterprise; works to generate alerting and hunting processes to the benefit of the GSA Enterprise; automates repetitive processes as necessary; monitors and ensures alerting from GSA Data Loss Prevention tools (Zscaler, Cloudlock etc.). Provides security consulting and threat hunt support for GSAIT information systems and emerging IT and IT Security initiatives, including but not limited to: Cloud computing, bring-your-own-device (BYOD), Virtual Desktop Infrastructure, mobile devices, Remote Access Systems, Mobile Computing Platforms, Active Directory, System Virtualization, physical access control systems (building security), Zero Trust and identity and access management solutions; ensuring new technologies are implemented in support of GSA risk management strategy and shaping ongoing incident response and recovery policies. Provides technical expertise and advice on the restructuring and/or re-architecting of GSA networks to ensure the remediation of identified security risks to provide the maximum protection of various types of sensitive Government data. Supports automation and integrations as well as deploys and pilots new Security toolsets in support of GSA Enterprise security operations.
Requirements
If selected, you must meet the following conditions: Current or Former Political Appointees: The Office of Personnel Management (OPM) must authorize employment offers made to current or former political appointees. If you are currently, or have been within the last 5 years, a political Schedule A, Schedule C or NonCareer SES employee in the Executive Branch, you must disclose this information to the HR Office. Failure to disclose this information could result in disciplinary action including removal from Federal Service. Serve a one year probationary period, if required. Undergo and pass a background investigation (Tier 5 investigation level). You must be granted this clearance before you can start the job. Have your identity and work status eligibility verified if you are not a GSA employee. We will use the Department of Homeland Security's e-Verify system for this. Any discrepancies must be resolved as a condition of continued employment. Complete a financial disclosure report to verify that no conflict, or an appearance of conflict, exists between your financial interest and this position. Any applicant tentatively selected for this position will be required to submit to urinalysis to screen for illegal drug use prior to appointment. Appointment to the position will be contingent upon a negative drug test result.
Education
There is no substitution of education for experience at the GS-14 level.
How you will be evaluated
Your application will be evaluated against the basic qualifications which includes any specialized experience and/or education requirements (if applicable). Qualified candidates will be considered in accordance with the Office of Personnel Management Direct Hire Guidelines. Applications will not be rated or ranked. Veterans' Preference is not applicable to the direct hire recruitment procedures. Failure to submit a complete application or missing required supporting documentation may result in you not being considered for the position. Falsification of your background, education, and/or experience is grounds for non-selection or dismissal if hired. SME Resume Review: Subject Matter Experts (SMEs) will evaluate your resume to determine your qualifications for this position using a pass/fail process. ICTAP/CTAP Candidates: The Interagency Career Transition Assistance Plan (ICTAP) and Career Transition Assistance Plan (CTAP) provide eligible displaced Federal competitive service employees with selection priority over other candidates for competitive service vacancies. To be qualified you must submit appropriate documentation (a copy of the agency notice, your most recent performance rating, and your most recent SF-50 noting current position, grade level, and duty location) and be found “well-qualified" for this vacancy. In addition to meeting the basic qualifications stated in the qualification section of this announcement, well qualified is defined as: experience that exceeds the minimum qualifications of the position, demonstrated by meeting at least 3 out of 5 KSA's listed below: Skill in advising clients on complex mission requirements by applying advanced IT security frameworks to deliver efficient, secure solutions and guide high-level policy initiatives. Skill in applying qualitative and/or quantitative methods for the assessment and improvement of an IT Security program effectiveness. Knowledge of IT Security, its governing laws, regulations, methodologies and/or policies to provide sound and authoritative technical guidance on all issues related to an assigned program. Skill in analyzing and integrating complex research, technical, and policy information needed to address high priority, sensitive, and visible issues and derive solutions impacting security and resiliency of information and communications technology. Knowledge of Information Technology Security and software programming techniques to support automation integration and application of experimental theories and new developments to problems not susceptible to treatment by accepted methods. Demonstration of these KSA's must be supported by your resume. You may preview questions for this vacancy.