Information Technology Specialist (Security)
JL04
The position is in the Department of the Chief Information Officer, Information Technology Security Office, Security Operations Division, Security Operations Branch. The Security Operation Division protects the judiciary from cyberthreats, strengthens the judiciary's security posture and threat awareness, eliminates threats before they can harm operations, and provides evaluation services to strengthen systems and programs.
Major duties: The Information Technology Specialist (Security) serves as a Cyber Threat Intelligence Analyst, a technical cybersecurity subject matter expert and performs multiple and varying assignments under the direction of the Chief, Security Operations Divisions. The incumbent will be responsible for providing threat intelligence support to security operations. Duties Include: Conducting independent technical research and analysis to identify emerging and novel threat vectors, synthesizing intelligence from adversary tradecraft, vulnerability disclosures and operational telemetry to inform proactive threat identification.
Managing all phases of the intelligence production cycle, ensuring timely and actionable reports for stakeholders across the judiciary. Maintaining and improving a common operational picture of the judiciary's threat environment, integrating internal telemetry, open-source intelligence, and cybersecurity threat feeds to provide leadership with a continuous, accurate understanding of the current threat landscape.
Managing the indicators of compromise lifecycle, including ingestion, validation, enrichment, prioritization, and operationalization across security tooling and detection platforms. Responding to intelligence support requests from the Security Operations Center, providing timely, technically accurate assessments that enable effective triage, investigation, and incident response. Conducting threat actor attribution analysis and develops comprehensive threat actor profiles, documents adversary tactics, techniques, and procedures to support cyber threat hunting and detection engineering.
Identifying insider threats to judiciary data and systems, applying behavioral analytics and intelligence tradecraft to detect, assess, and report on indicators of malicious or negligent insider activity. Maintaining intelligence analysis standards, methodologies, and quality assurance processes to support accuracy, consistency, and operational effectiveness. Developing metrics and reporting to measure effectiveness and operational maturity of the cyber threat intelligence program.
Providing regular executive summaries to senior leadership and judiciary cybersecurity stakeholders for informed enterprise risk understanding, prioritization, and resource allocation decisions. Performing the tasks and meeting the skills, knowledge, and abilities as described in NIST Special Publication 800-181 National Initiative for Cybersecurity Education Cybersecurity Workforce for the role of Threat Analysis (PD-WRL-006).
Requirements: CONDITIONS OF EMPLOYMENT All information is subject to verification. Applicants are advised that false answers or omissions of information on application materials or inability to meet the following conditions may be grounds for non-selection, withdrawal of an offer of employment, or dismissal after being employed. Selection for this position is contingent upon completion of OF-306, Declaration of Federal Employment during the pre-employment process and proof of U.S.
citizenship for competitive status positions or conversion to a competitive status position with the AO. If non-citizens are considered for hire into a temporary or any other position with non-competitive status or when it is confirmed by the AO Human Resources Office there are no qualified U.S. citizens for a competitive status position (unless prohibited by a law or statue), non-citizens must provide proof of authorization to work in the U.S.
and proof of entitlement to receive compensation. Additional information on