Get more replies from employers
Send a job-specific resume in minutes.
The Department of the Air Force Headquarters seeks an Information Technology Security Specialist to plan, coordinate, and supervise security across JWICS network and server systems, from installation through maintenance and upgrades.
The role requires strong RMF expertise, deep knowledge of system security concepts, and the ability to manage A&A artifacts like SSPs and POA&Ms to achieve system authorization.
The primary purpose of this position is: To serve as an Information Technology Security Specialist with responsibility for security planning, coordinating, and supervising the security during installation, testing, modifying, upgrading, operation, troubleshooting, and maintenance of network and server hardware and softwaresystems on the installation's Joint Worldwide Intelligence Communications Systems (JWICS)network.
This is a GG-12 position in the Defense Civilian Intelligence Personnel System (DCIPS). The GG-12 duties for the "Professional" work category are at the "Full Performance" work level and are equivalent to those at the GG-12 level. The selectee's salary will be set within the grade equivalent to a GS/GG grade based on the selectee's qualifications in relation to the job. In order to qualify, you must meet the specialized experience requirements described in the Office of Personnel Management (OPM) Qualification Standards for General Schedule Positions for the GG-2210, Information Technology (IT) Management Series (Alternative A). BASIC REQUIREMENT OR INDIVIDUAL OCCUPATIONAL REQUIREMENT: Experience must be IT related; the experience may be demonstrated by paid or unpaid experience and/or completion of specific, intensive training (for example, IT certification), as appropriate. For all positions individuals must have IT-related experience demonstrating each of the four competencies listed below. The employing agency is responsible for identifying the specific level of proficiency required for each competency at each grade level based on the requirements of the position being filled.
In addition to meeting the basic requirement above, to qualify for this position you must also meet the qualification requirements listed below. EXPERIENCE REQUIRED: Your resume must reflect the quality level of experience which demonstrates the possession of the knowledge, skills, abilities, and competencies necessary for successful job performance required for this position. Examples of creditable experience include: knowledge of, and skill in applying, IT cybersecurity principles, concepts, and practices to perform a wide range of duties in support of the Information System Security Manager (ISSM). The role requires detailed practical knowledge of the Risk Management Framework (RMF) and its procedural application, including the ability to independently prepare, manage, and maintain all required Assessment &Authorization (A&A) documentation. This includes creating and updating System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), and other artifacts necessary to achieve system authorization. A comprehensive knowledge of system security concepts is required, including network security, access control, and vulnerability management. The position must apply this knowledge to implement security controls, analyze vulnerability scan results, review system audit logs, and direct system administrators in applying required patches and configurations. Note: Creditable experience may include previous military experience, experience gained in the private sector, or experience gained in another government agency.
KNOWLEDGE, SKILLS AND ABILITIES (KSAs): Your qualifications will be evaluated on the basis of your level of knowledge, skills, abilities and/or competencies in the following areas: Knowledge of computer network security concepts, including network architecture, access control, and defense in-depth principles, sufficient to direct system administrators in applying secure configurations and to advise configuration control boards. Knowledge of the system development lifecycle and the ability to ensure cybersecurity principles and requirements are integrated and addressed in all phases of system change and modernization. Working knowledge of system vulnerability management, including the ability to manag