IT Specialist (Security)
Federal Aviation Administration · Oklahoma City, Oklahoma
Skills in this posting
The posting
Applies project management principles and detailed knowledge about Information Technology to create and maintain security documents such as Business Impact Assessments (IA), System Security Plans (SSP), Information System Contingency Plans (ISCP), System Characterization Document (SCD), Configurations Management Plans (CMP), Privacy Impact Analysis (PIA) and other security documents.
Provides intermediate level advice and assistance in the areas of security architecture, systems auditing, security tools, and all areas related to Information Security. Duties also include acquiring/maintaining systems authorization, providing audit support, and initiating protective or corrective actions if security risks are identified.
Plans, coordinates, and evaluates vulnerability system scanning, ISCP exercises, and other Information Security related activities. Work is reviewed periodically by team lead during assigned tasks and at completion to ensure timeliness and quality.
Work activities typically support the work of other employees and contribute to activities of the organization. Applies detailed technical knowledge to evaluate security controls on a variety of information system platforms (Windows, Linux/Unix, etc.), databases (Oracle, MS-SQL, MySQL), and networking technology.
Researches, verifies, complies, and summarizes systems support data and information, using Microsoft Office, Project, and Visio. This is a highly visible position that supports multiple Federal agencies throughout the United States.
Periodically develops reports and provides system status briefings to management at all levels throughout the Federal Government as required.
Advises manager, team leads, and peers of known and projected program deviations related to security issues pertaining to facilities, communications, personnel, hardware, and software in accordance with federal guidelines and policies.
Contacts are internal and external to the organizational unit, to include interactions with mid-level management personnel. Conducts risk and vulnerability assessments of planned and installed information systems to identify vulnerabilities, risks, and protection needs. Develops system security contingency plans and disaster recovery procedures.
Established policies/procedures provide guidance for most assignments, but allow some discretion to select the most appropriate approach. Typically receives guidance on selecting approach from a manager, project/program manager, team leader, or more experienced technical specialist.
Implements, maintains, and conducts on-site and remote analyses of information system standard security products and associated systems in order to determine overall technical features and standard security protection required for IS and networks at all levels of information security.
Provides technical assistance and security guidance in the areas of information systems and telecommunications to information systems owners, technicians, and general users.
Characteristic information technology assignments in the Security specialization at this pay band include: Implements and disseminates standard IT security tools, procedures, and practices to protect information assets. Plans and coordinates the delivery of an IT security awareness training program for end users at all levels in the organization.
Evaluates established security authentication technologies such as public key infrastructure certificates, secure cards, and biometrics for adoption in various FAA environments. Administers and monitors implementation of authentication software.
Identifies and specifies standard information systems security requirements associated with migrations to new IT environments/applications and provides guidance in planning and implementing migration activities.
Reviews specifications for procurement of new but established software to ensure compliance with security requirements at the systems or LAN level.
BASIC REQUIREMENTS: To qualify for this position at the FV-H (FG/GS 10-12) level, you must demonstrate in your application that you possess at least one year of specialized experience equivalent to FV-G (FG/GS 5-9) level.
Specialized experience is experience that has equipped you with the particular knowledge, skills, and abilities to perform successfully the duties of the position.
Specialized Experience includes: management of ISS projects that require extensive knowledge of IT hardware/software technology; experience preparing ISS systems documentation for certification/accreditation in accordance with FISMA, FedRAMP, and/or other federal IS guidelines or regulations; experience monitoring and evaluating systems¿ compliance with IT security requirements Applicants should include examples of Specialized Experience in their work history AND IT-related experience demonstrating each of the four competencies listed below.
The experience may be demonstrated by paid or unpaid experience and/or completion of specific, intensive training (for example, IT certification), as appropriate. 1. Attention to Detail - Is thorough when performing work and conscientious about attending to detail. 2.
Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. 3.
Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. 4.
Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations.
OR Education substitution: Successful completion of a Ph.D. or equivalent doctoral degree or 3 full years of progressively higher level graduate education leading to a Ph.D. or equivalent doctoral degree.
Degree in computer science, engineering, information science, information systems management, mathematics, operations research, statistics, or technology management or degree that provided a minimum of 24 semester hours in one or more of the fields identified above and required the development or adaptation of applications, systems or networks.
OR Combination Education and Experience: May be qualifying for this position. Refer to OPM's Operating Manual Qualification Standards at, https://www.opm.gov/policy-data-oversight/classification-qualifications/general-schedule-qualification-standards/#url=GS-ADMIN for more information.
AND In addition to the minimum qualifications, the following has been determined to be a selective factor for this position. This means possession of this criterion is part of the minimum qualifications and is essential to perform the duties and responsibilities of this position.
Applicants who do not possess this criterion are ineligible for further consideration.
Selective Placement Factor (SPF): Applicant must possess one or more current intermediate level Information Security certifications from one of the following governing bodies: Comp TIA ISACA EC-Council Global Information Assurance Certification (GIAC) International Information System Security Certification Consortium (ISC2) International Association of Privacy Professionals (IAPP) Applicants must submit proof documentation of the certification(s) they hold.
ALSO Quality Ranking Factor (QRF): Well-qualified candidates will have demonstrated experience and possession of the following areas: Addressing information Systems Security concerns of an organization by applying the Risk Management Framework (RMF) Security Life Cycle as an information security professional with experience creating and/or managing (in accordance with NIST or other Federal Departmental/Agency guidelines and regulations) the following: BIA, SSP, ISCP, SCD, CMP, PIA, and other security documents.
Installing, maintaining, managing, and/or securing IT network devices or physical/virtual servers running on a variety of platforms (e.g. Linux/UNIX, Windows, Solaris, Oracle, SQL, MySQL, Cisco, etc.). Qualifications must be met by the closing date of this vacancy announcement
The PivotHop read
- What an it support specialist actually earnsmedian, seniority, by country
- Careers an it support specialist can move intoevery measured route out
- All open it support specialist rolesthe full board
Where these skills also reach
- 160 open network engineer roles50% readiness from it support specialist
- 600 open systems administrator roles44% readiness from it support specialist
- 600 open customer support specialist roles38% readiness from it support specialist
- 64 open technical writer roles36% readiness from it support specialist
More it support specialist roles
- IT SPECIALIST (NETWORK) at Department of the Air Force HeadquartersLackland AFB, Texas$118k–$153k3d agoApply
IT Support Engineer at CognitionSan Francisco3d agoUnlock- SUPERVISORY IT SPECIALIST (PLCYPLN/ENTARCH) at Department of the Air Force HeadquartersRamstein, Germany$133k–$173k3d agoApply
IN_RBAI_Senior Engineer-Production IT Support at BoschGroupBengaluru, IN3d agoUnlock
FachspezialistIn Technischer Support (100%) at Stiebel Eltron AGBirr, Aargau, Switzerland3d agoApply
Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.