About this role
Job SummaryAs an IT Cybersecurity Specialist (INFOSEC), you will provide technical expertise and guidance to WAPA functional and project teams regarding cybersecurity technical issues, risk analyses, mitigation plans and continuity of operations planning. **This is NOT A REMOTE POSITION. The selectee will be required to be physically present at one of the duty location(s) identified.**
QualificationsQUALIFICATION REQUIRMENTS: To qualify for this position, you must meet the minimum qualification requirements as well as the specialized experience requirements outlined below: MINIMUM REQUIREMENTS FOR GRADE 12 and Above (GS or Equivalent): The competencies listed in the "How You Will Be Evaluated" section will be used to evaluate whether or not you meet the minimum proficiency level established for the 2210 series SPECIALIZED EXPERIENCE for Cybersecurity Infrastructure and Architecture (IA): A qualified candidate's online application and resume must demonstrate at least one (1) year of specialized experience equivalent in difficulty and responsibility to the next lower grade level GS-12 in the Federal service (obtained in either the public or private sectors). Specialized experience for this position is defined as having at least two (2) of the following: Test, analyze, and/or implement existing and future systems to complement existing cybersecurity architectures; often leading Authority to Operate (ATO) job functions such as control testing and validation, Plan of Actions & Milestones (POAM) tracking or Risk Acceptance (RA). Analyze security events, including threat model development and resulting security risk analysis of systems. Design and develop security architecture to execute a company's cybersecurity program to meet Federal Information Security Modernization Act (FISMA), North American Electric Reliability (NERC), Critical Information Protection (CIP), or NIST 800-53 Controls. Perform vulnerability management to include scans, assessments, and remediation in conjunction with other IT business units to reduce company-wide risk. -OR- SPECIALIZED EXPERIENCE for Cybersecurity Operations (Ops): A qualified candidate's online application and resume must demonstrate at least one (1) year of specialized experience equivalent in difficulty and responsibility to the next lower grade level GS-12 in the Federal service (obtained in either the public or private sectors). Specialized experience for this position is defined as having at least two (2) of the following: Configure and manage and/or manage the lifecycle of at least 1 (one) of the following cybersecurity systems: Axonius, Carbon Black App Control, Carbon Black Endpoint Detection and Response (EDR), Corelight, Forescout, Splunk, and Tenable. Apply the Risk Management Framework (RMF) and assess cybersecurity systems against federal and industry compliance standards, such as NIST SP 800-53, FISMA, or NERC CIP. Conduct incident response activities, vulnerability assessments, and/or digital forensics, including analyzing security events to understand and mitigate active potential cybersecurity threats.
Major DutiesAs a IT Cybersecurity Specialist, you will: Provide technical oversight of IT operating system security ensuring the confidentiality, integrity, and availability of systems, networks and data. Develop, review and evaluate information security policies for WAPA. Employ Defense in Depth principles and technology and other best practices in security engineering designs and implementation. Evaluate the quality of Federal Information Security Management Act (FISMA) and North American Electric Reliability Corporation (NERC) Critical Information Protection (CIP) evidence for the purposes of ensuring WAPA is meeting regulatory requirements and standards common in the industry (e.g. NERC and FERC guidelines). Create and maintain evidence in specific evidence repositories. Serve as one of WAPA's lead technical experts on systems, network, and cloud security to management and other technical specialists on critical IT issues. Analyze Information Assurance (IA) security events, including threat model development and resulting security risk analysis of systems.RequirementsMust be a U.S. Citizen or National. This employer participates in the e-Verify program. Males born after 12/31/1959 must be registered for Selective Service. Suitable for Federal employment, as determined by a background investigation. Appointments made under the DHA are processed as "new" appointments. Status and Non-Status applicants from outside DOE selected under this authority are required to serve a mandatory one (1) year probationary period. A DOE career status employee selected for this position may be required to serve a new one (1) year probationary period, pursuant to 5 CFR 315.802. Employees serving on a probationary period may be terminated at any time during the probationary or trial period for performance, conduct, or business-related reasons in the interest of Federal service. Limit your resume to no more than two (2) pages. If more than two pages are submitted, only the first two pages will be reviewed to determine your eligibility and qualifications. In accordance with Executive Order 14170, applicants are encouraged to respond to the four short, free-response, essay questions in the questionnaire. Answers to these questions are not scored or rated. Your answers will be reviewed by the hiring manager and agency leadership if you are referred for selection consideration. Overtime may be required on short notice to include nights, holidays and weekends in support of related mission requirements. On-call (Rotational) - The duties of this position may require the incumbent to be placed in a 24/7 on-call status on a rotational basis. On-call status on a rotational basis is anticipated to be approximately 15% of the year. While in an on-call duty status, required to carry a cellular phone and remain within one-half hour travel time of their primary place of residence (or approved on-call place of residence) and, will sustain themselves in an able to respond and perform work condition.