Apply with hirly
IT Specialist (Security)
Deputy Assistant Secretary for Information and Technology · Hines, Illinois, United States · Martinsburg, West Virginia, United States
Upload your resume to see how well you match this job — free, in seconds, no account needed.
Your resume is used only to score it against this job. If you don't create an account, it is deleted within 24 hours.
Summary This IT Specialist (Security) position is located in the Office and Information and Technology (OI&T), Office of Information Security (OIS), Information Security Office (ISO), Cyber Security Operations Center (CSOC). The Office of Information and Technology (OI&T) provides adaptable, secure, and cost- effective technology services across the Department of Veterans Affairs (VA). Duties Major Duties: Knowledge of information technology (IT) security principles and methods (e.g., firewalls, demilitarized zones, encryption). Knowledge of defense-in-depth principles and network security architecture. Knowledge of cyber defense and information security policies, procedures, and regulations. Skill to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation). Ability to interpret the information collected by network tools (e.g. Ns lookup, Ping, and Traceroute). Determine tactics, techniques, and procedures (TTPs) for intrusion sets. Conduct research, analysis, and correlation across a wide variety of all source data sets (indications and warnings). Knowledge of adversarial tactics, techniques, and procedures. Skill in collecting data from a variety of cyber defense resources. Skill in performing packet-level analysis. Characterize and analyze network traffic to identify anomalous activity and potential threats to network resources. Coordinate with enterprise-wide cyber defense staff to validate network alerts. Ensure that cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level. Knowledge of the common attack vectors on the network layer. Ability to apply techniques for detecting host and network-based intrusions using intrusion detection technologies. Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack. Analyze identified malicious activity to determine weaknesses exploited, exploitation methods, effects on system and information. Reconstruct a malicious attack or activity based off network traffic. Knowledge of incident response and handling methodologies. Skill in using incident handling methodologies. Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy. Knowledge of cyber defense and vulnerability assessment tools and their capabilities. Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code). Skill in assessing security controls based on cybersecurity principles and tenets. (e.g., CIS CSC,
Nist Sp
800-53, Cybersecurity Framework, etc.). Knowledge of Intrusion Detection System (IDS)/Intrusion Prevention System (IPS) tools and applications. Work Schedule: Monday
- Friday, 8:00am to 4:30pm Compressed/Flexible: Compressed/flexible schedule available at the manager's discretion Telework: This position may be authorized for telework. Virtual: This is not a virtual position. Position Description/PD#: IT Specialist (Security)/PD17400A Relocation/Recruitment Incentives: Not Authorized Permanent Change of Station (PCS): Not Authorized PCS Appraised Value Offer (AVO): Not Authorized Qualifications To qualify for this position, applicants must meet all requirements by the closing date of this announcement, 10/07/2026. Applicants must have IT-related experience demonstrating each of the four competencies listed below at a proficiency level equivalent to the next lower grade level in federal service You must meet both the Basic Requirement and the Specialized Experience and the Selective Placement Factor to qualify for this series as described below Attention to Detail
- Is thorough when performing work and conscientious about attending to detail. Customer Service
- Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. Oral Communication
- Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. Problem Solving
- Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. AND Specialized Experience: You must have one year of specialized experience equivalent to at least the next lower grade GS-13 in the normal line of progression for the occupation in the organization. Experience characterizing and analyzing network traffic to identify anomalous activity and potential threats to network resources; performing event correlation using information gathered from a variety of enterprise sources to determine the effectiveness of an observed attack; analyzing malicious activity to determine weaknesses exploited, exploitation methods, and effects on systems and information; and providing risk mitigation recommendations based on Federal laws, regulations, and organizational policies. AND- Selective Placement Factor: Developing, tuning, and validating detection analytics and correlation rules within Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) platforms to support proactive threat hunting and cybersecurity incident response operations, to include applying a structured adversary behavior framework (e.g., MITRE ATT&CK) to identify tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) not detected through automated alerting; and experience providing technical direction and quality review of work performed by contract staff supporting these functions, in a non-supervisory capacity. Physical Demands: The work is primarily sedentary during the planning/preparation phase. The work may require walking and standing for prolong periods in conjunction with travel and at the onsite assessment location. The incumbent may carry light items such as papers, books or computers, or drive a motor vehicle. The work does not require any special physical effort. Work Environment: The work area is adequately lighted, heated, and ventilated. The work environment involves everyday risks or discomforts that require normal safety precautions. The responsibilities of the position require frequent travel and may subject the incumbent to various resultant environmental changes; incumbent must be amenable to such period of travel and to working in unfamiliar surroundings. This position requires occasional travel using both air and ground transportation. For more information on these qualification standards, please visit the United States Office of Personnel Management's website at Education There is no educational substitution at this grade level.