Supervisory Information Technology Specialist (Security)
Administrative Office of the U.S. Courts — Washington, District of Columbia, United States
Job description
This position is in the Department of the Chief Information Officer, Information Technology Security Office, Security Operations Division, Security Operations Support Branch. The Security Operations Division protects the judiciary from cyber threats, strengthens the judiciary's security posture and threat awareness, eliminates threats before they can harm operations, and provides evaluation services to strengthen systems and programs.
Duties:
The Supervisory Information Technology Specialist (Security) is in the Information Technology Security Office's Security Operations Division and serves as the Security Operations Support Branch Chief. The Security Operations Branch delivers enterprise detection engineering, threat hunting, threat intelligence, and insider threat capabilities in support of continuous cybersecurity operations. This position reports to the Security Operations Division Chief. The incumbent is a recognized cyber-security subject matter expert with a strong defensive cybersecurity background and is responsible for leading detection engineering, threat hunting, threat intelligence and insider threat teams to identify cybersecurity threats impacting the confidentiality, integrity, or availability of judicial data. the Supervisory Information Technology Specialist (Security) leads hypothesis-based threat hunting to identify, investigate, and mitigate advanced persistent threats, zero-day vulnerability abuse, and other malicious activity to bypass traditional security controls. The incumbent lead detection engineering to categorize known attack vectors through the security information and event management. The incumbent is responsible for the threat intelligence program, reporting on malicious threat actors, and identifying insider threats to judiciary data and systems. Leading, directing, and overseeing the Security Operations Support Branch. Overseeing the development, testing, deployment, and lifecycle management of detection logic used to identify malicious activity. Leading the production and operational integration of threat intelligence to inform detection engineering priorities, hunting hypotheses, and risk-based decision making. Directing proactive threat hunting activities to identify emerging, novel, or evasive adversary behavior not covered by existing detection mechanisms. Establishing and maintaining detection engineering standards, methodologies, and quality assurance processes to support accuracy, consistency, and operational effectiveness. Overseeing the validation, tuning, and refinement of detections based on operational feedback, adversary emulation results, and observed threat activity. Ensuring development of metrics and reporting to measure detection coverage, effectiveness and operational maturity. Leading the development and maintenance of a common operational picture that identifies baseline behavior and meaningful deviations to support shared situational awareness, prioritization and leadership decision making. Providing regular executive summaries to senior leadership and judiciary cybersecurity stakeholders for informed enterprise risk understanding prioritization, and resource allocation decisions. Coordinating closely with Security Operations Center to support alert fidelity, investigative workflows, and continuous improvement of analytic outcomes. Managing branch personnel, contractor support, and resource planning to sustain required capabilities.
Location: Washington, District of Columbia
Education:
This position does not require education to qualify.
How you will be evaluated:
We will review your resume and supporting documentation and compare this information to your responses on the occupational questionnaire to determine if you meet the minimum qualifications for this job. If you meet the minimum qualifications for this job, we will evaluate your application package, to assess the quality, depth, and complexity of your accomplishments, experience, and education as they relate to the requirements listed in this vacancy announcement. You should be aware that your ratings are subject to evaluation and verification. If a determination is made that you have rated yourself higher than is supported by your resume and/or narrative responses, you will be assigned a rating commensurate to your described experience. Failure to submit the mandatory narrative responses will result in not receiving full consideration and/or rating credit. Deliberate attempts to falsify information may be grounds for not selecting you, withdrawing an offer of employment, or dismissal after being employed.
Other information:
The AO is an Equal Opportunity Employer.
How to apply:
To apply for this position, you must complete the online application and submit the documentation specified in the Required Documents section below. The complete application package must be submitted by 09/10/2026 to receive consideration. To begin, click Apply Online to access an online application. Follow the prompts to select your USAJOBS resume and/or other supporting documents. You will need to be logged into your USAJOBS account or you may need to create a new account. You will be taken to an online application. Complete the online application, verify the required documentation, and submit the application. You will receive an email notification when your application has been received for the announcement. To verify the status of your application, log into your USAJOBS account, https://my.usajobs.gov/Account/Login, select the Application Status link and then select the More Information link for this position. The Application Status page will display the status of your application, the documentation received and processed, and your responses submitted to the online application. Your uploaded documents may take several hours to clear the virus scan process. Click the following link to view and print the occupational questionnaire https://apply.usastaffing.gov/ViewQuestionnaire/13031720