Summary
This position is assigned to the Non-appropriated Fund Chief Information Officer, NAF Systems Division; Commander, Navy Installation Command, Millington, TN. The incumbent is responsible for leading the evaluation, analysis, configuration, and delivery of computer and/or system security for enterprise devices across CNIC NAF operations. The position ensures computer system operational readiness, and user support in accordance with Navy policy for the benefit of CNIC NAF employees and customers.
Duties
Help
In order to qualify for this position, resumes must provide sufficient experience and/or education, knowledge, skills, and ability to perform the duties of the position. Applicant resumes are the key means for evaluating skills, knowledge, and abilities as they relate to this position therefore, applicants are encouraged to be clear and specific when describing experience.
Duties include but are not limited to:
Endpoint Security and Vulnerability Management:
- Manages the end-to-end vulnerability lifecycle for all endpoint devices (Windows, macOS, iOS, Android, Digital Signage, Time Clock) using enterprise tools such as Microsoft Intune, Defender for Endpoints (MDE), proprietary firmware.
- Plans, deploys, and verifies security patches, firmware updates, and configuration changes to ensure compliance with DoD/DoN mandates (e.g., STIGs, IAVMs, Zero Trust).
- Conducts regular vulnerability assessments, analyzes security alerts (e.g., CVEs), and collaborates with cybersecurity teams to respond to incidents and maintain system Authority to Operate (ATO). Monitors endpoints for threats, intrusions, and anomalous activity, taking corrective action to mitigate risks.
- Develops and maintains automation scripts (e.g., PowerShell) to enforce security configurations and streamline reporting for audits.
Device and Systems Administration:
- Develops, maintains, and deploys secure baseline images for Windows and macOS operating systems.
- Develops, maintains, and deploys iOS and Android operating systems and profiles.
- Provisions, configures, and manages the lifecycle of physical and virtual devices within the NAF enterprise, including desktops, laptops, tablets, and POS systems.
- Administers cloud-based identity and access management through Azure/Entra ID and enforces endpoint policies via Intune and Group Policy Objects (GPOs).
- Installs, configures, and maintains operating systems and software supporting NAF business operations in retail, hospitality, and MWR.
- Perform assessment, analysis for solution, implementation of corrective action to resolve device cyber security compliance discrepancies.
Technical Support and Consultation:
- Provides Tier II/III technical support for complex hardware, software, and security-related issues.
- Acts as a subject matter expert, consulting with program managers and users to analyze requirements and recommend secure technology solutions.
- Develops and maintains technical documentation, solution guides, and knowledgebase articles to support staff and standardize processes.
- Presents informal training to users on cybersecurity best practices.
- Serves as Contracting Officer Representative (COR) or Assistant Contracting Officer Representative (ACOR) or Technical Advisor (TA) as required.
Requirements
Help
Conditions of employment
- Must pass all applicable records and background check.
- Must successfully pass the E-Verify employment verification check. Any discrepancies must be resolved as a condition of employment.
- Must have or be able to obtain and maintain clearance for a Tier 3 (T3 (64)) Investigation Non-Critical Sensitive National Security Sensitivity designation and Moderate Risk designation.
- Must earn and maintain appropriate foundational and residential qualifications from the DoD Cyber Workforce Qualification Matrix (as described in DODM 8140) within nine (9) months.
Qualifications
Resumes must include information which demonstrates experience and knowledge, skills, and ability (KSAs) as they relate to this position. Applicants are encouraged to be clear and specific when describing their experience level and KSAs.
A qualified candidate possesses the following:
- Comprehensive, practical knowledge of IT endpoint security principles and practices, including vulnerability management, patch deployment, threat response, and compliance within a DoD/DoN environment (STIG, RMF).
- Advanced skill in administering enterprise management tools, specifically Microsoft Intune, Entra ID, and Defender for Endpoints (MDE).
- Proficient skill in administering and securing diverse operating systems, including Windows, macOS, iOS, and Android.
- Strong ability to develop and maintain secure system images and automate administrative tasks using scripting languages such as PowerShell.
- Knowledge of IT infrastructure supporting business operations (e.g., Point-of-Sale, financial systems) and data security standards such as PCI-DSS and PII.
- Knowledge of LAN/WAN and wireless networking principles.
- Excellent communication skills to effectively train users, collaborate with technical/nontechnical teams, and provide clear documentation.
- Proficient in computer systems management principles, models, methods (e.g., end-to-end systems performance monitoring), tools, and service management concepts for hardware and related standards (e.g., Azure, Entra ID, Intune, MDE, ITIL).
- Skill in configuring and optimizing software, including utilizing software-based computer protection tools (e.g., local policies, group policies, antivirus software, anti-spyware).
- Proficient in using cloud storage (e.g., Azure Storage, Azure Blob, etc.).
- Skill in the use of Microsoft 365 programs (e.g., Teams, Planner, Word, Excel, PowerPoint, Outlook).
- Skill in querying databases and other data sources, cleansing and normalizing data, preparing analysis and presenting data in an effective format using available technology tools.
- Skill in the effective and efficient use of planning and project/task assignment and tracking software.
Education
There is no positive educational requirement for this position.
Additional information
Salary is dependent on experience and/or education.
Some positions have special requirements. Selectee may be required to complete a one (1) year probationary period. Participation in Direct Deposit/Electronic Fund Transfer within the first 30 days of employment is required. We utilize E-Verify to confirm selectee's eligibility to work in the United States. Salary is dependent on experience and/or education.
This announcement may be used to fill additional vacancies within 60 days of issuance of selection certificate. For positions requiring travel more than twice per year, selectee may be required to obtain and maintain in good standing a government-issued Travel Card for official government travel purposes.
Executive Order 12564 requires a federal workplace free of illegal drugs. According to the Executive Order, all Federal employees are required to remain drug free throughout their employment. Commander, Navy Installations Command is a Drug-Free Federal Workplace. The use of illegal drugs will not be tolerated, and use of or intoxication by illegal drugs will result in penalties up to and including removal from Federal Service.
Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution.
Help
Review our benefits