Information Security Analyst, Sr
Federal Reserve SystemAbout the role
Company
Federal Reserve Bank of MinneapolisThe Federal Reserve Bank of Minneapolis invites applications for an experienced Information Security Analyst / Information System Security Officer (ISSO) to support the Bank in its role as a Fiscal Agent for the Department of Treasury and the Bureau of the Fiscal Service.In this role an ISSO, you will help to ensure that all relevant IT security requirements prescribed by the Federal Reserve or Fiscal Service are implemented and maintained throughout the lifecycle of the information system. You will work across multiple divisions within the Federal Reserve Bank of Minneapolis.
Best qualified candidates will have previous or current experience with NIST based information security control and risk management frameworks as well as a commitment to delivering high-quality, prompt, and efficient services to stakeholders. Strong candidates will bring the technical experience and ability to adapt and adjust to situations. In addition, they should have excellent critical thinking, risk management, collaboration and communication skills.
This is not a remote position. An essential function of this position is working onsite, this position qualifies for a hybrid working arrangement that will be determined by the department.
Responsibilities:
Ensure that applicable IT security policies are implemented for assigned information systems.
Ensure that the operational security posture of the information systems is maintained and kept consistent with current security policies and that all assessments of security controls are conducted, documented and reported.
Ensure that applicable requirements for Information Security Continuous Monitoring are followed including:
Completing annual Security Assessments and Authorizations as well as assessments whenever there are significant changes to the information system, the facilities where the system resides, or other conditions that may impact the security or ongoing authorization status of the system.
Ensuring sure that an Operational Continuous Monitoring Plan is maintained and executed as part of the System Security Plan (SSP).
Ensuring the accomplishment of risk assessments prior to the implementation of system changes to determine impacts to the security controls established for the system.
Ensuring that all Exceptions and Plan of Action and Milestones (POA&Ms) are created, reviewed, and reported to the System Owner, Program/Project Manager and Authorizing Official (AO).
Serve as the principal advisor to the Authorizing Official, System Owner, and Chief Information Security Officer on all matters (technical and otherwise) involving security of information system.
Coordinate with the information System Owner to update the SSP, manage and control changes to the system, and ensure that security impacts of proposed changes are evaluated by or reported to officials responsible for change control.
Ensure that IT Security management, operational and technical controls are incorporated throughout the system life cycle.
Ensure that all IT security documentation (e.g. System Security Plan, Information System Contingency Plan, and Configuration Management Plan) is properly maintained, approved, updated and compliant with security program requirements.
Report existing or potential security issues and incidents to the System Owner and escalate as needed to Chief Information Security Officer (CISO), or AO.
Evaluate known threats and vulnerabilities to ascertain if additional safeguards are needed and brief the AO accordingly.
Ensure documentation of mitigating actions or risk acceptances/exceptions in an Issue Resolution with signed approval of AO and ensure esta
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s