Beth Cobert, acting director of the Office of Personnel Management, seemed a bit out of place on the agenda for the 2016 DoD Intelligence Information Systems (DoDIIS) conference, a gathering of mostly Department of Defense and intelligence community officials. However, since the massive breach of OPM networks was announced in 2015, the human resources agency has been working closely with the DoD and IC to improve its cybersecurity posture.
OPM and Cobert have learned a lot through this collaboration, the latter said during an Aug. 2 keynote at DoDIIS, particularly when it comes to the cyber workforce.
“The importance of this collaboration — reaching across these boundaries — is one of the most important lessons I’ve learned,” she said. “We in the civilian side of the world need to leverage your valued expertise to help us protect that information. Just as OPM has partnered with you [DoD and IC] in our effort to secure our systems, we need to find ways to learn from you and to take a whole-of-government approach.”
As the government’s HR department, OPM is at the fore of trying to fix the glaring skill shortage when it comes to cybersecurity and plans to take some queues from the defense and intelligence communities.
For instance, Cobert pointed to the IC’s use of alternative hiring authorities to onboard top cyber talent more quickly and at higher pay scales.
“There are many flexibilities that agencies aren’t taking full advantage of,” she said. “The intelligence community is one of the leaders and models of how to leverage these flexibilities.”
Further, Cobert suggested the civilian government should establish titles and accreditation systems that mirror the military.
“As all of you know, when someone says they’re a Navy Seal or an Army Ranger, you know exactly what that means — we know they have the needed skills, we know they’re at the top of their game,” she said. “We want to build something akin to that model that includes badges and a rigorous qualification program that we can provide to our cyber professionals across government. So when someone says they’re a ‘cyber defender’ or ‘cyber warrior’ or ‘cyber investigator,’ their level of expertise will be immediately understood and recognizable.”
In some ways, civilian agencies are already adopting military mentalities when it comes to cyber and IT positions, most notably with rotational assignments.
Military personnel are used to shifting job titles and locales but for civilian employees this can be a new experience. However, Cobert cited the Millennial mentality that seems to prefer having multiple experiences over the life of a career, rather than spending 50 years at the same job.
“We’re also focused on rotational assignments — something that is embedded in the DNA of the IC and DoD but something that, frankly, is not seen in other parts of the civilian government,” she said. “But we know that that’s a great example for us to both find talent when we need it and to help people learn new skills.”
Some of that is being done now on the civilian side but it’s still new.
The U.S. Digital Services, for example, was built on this idea, asking tech experts from the private sector to join the government for short “tours of duty,” usually of no more than two years. Using the military as a framework, Cobert said she would like to expand that to intra-governmental tours, enabling feds to move around within the public sector.




