This position is in the Department of the Chief Information Officer, Information Technology Security Office, Security Operations Division. The Security Operation Division protects the judiciary from cyber threats, strengthens the judiciary's security posture and threat awareness, eliminates threats before they can harm operations, and provides evaluation services to strengthen systems and programs.
The Information Technology Specialist (Security) leads detection engineering efforts to identify and categorize cybersecurity threats impacting the confidentiality, integrity, or availability of judicial data. The incumbent ensures detections are appropriate for the threat environment and are consistently validated. The incumbent perform multiple and varying assignments under the direction of the Chief, Security Operations Support Branch.
Duties Include: Providing technical leadership, direction, and federal oversight for the detection engineering team in support of continuous cybersecurity operations. Conducting development, testing, deployment, and lifecycle management of detection logic used to identify malicious activity across the judiciary's information technology fabric. Integrating threat intelligence reporting and indicators of compromise to inform detection logic and identify malicious activity.
Continually validating threat detections to ensure they appropriately identify malicious activity Conducting threat research to identify novel or emergent techniques that are not yet integrated into the detection engineering program. Enforcing detection engineering standards, methodologies, and quality assurance processes to support accuracy, consistency, and operational effectiveness.
Performing validation, tuning, and refinement of detection based on operational feedback, adversary emulation results, and observed threat activity. Ensuring the development of metrics and reporting to measure detection coverage, effectiveness, and operational maturity. Providing quarterly report summaries to senior leadership and judiciary cybersecurity stakeholders on the detection engineering effectiveness and program risk.
Closely coordinating with the Security Operations Center to improve alerts, fidelity, investigative workflows, and the continuous improvement of analytic outcomes.
This position does not require education to qualify.
Christina_Stokes@ao.uscourts.gov · (202) 502-3800
This position is with Administrative Office of the U.S. Courts, Judicial Branch.
The posted pay range is $111896 – $167773/yr.
Yes, this position is fully remote.
Applications close on 2026-09-10.
This position is open under the 'Fed Competitive' hiring path.
Source: USAJOBS.gov — U.S. Federal Government
Apply on official site →