Jobs and Careers
FE

Cyber Threat/Incident Analyst (Associate/Sr./Engineer/Sr. Engineer)

Federal Reserve System
United Statesfull_timeVerifiedPosted 19 Sept 2024

About the role

Company

Federal Reserve Bank of Atlanta

As an employee of the Atlanta Fed, you will help support our mission of promoting the stability and efficiency of the U.S. economy and financial system. Your work will affect the economy of the Southeast, the United States, and the world. The work we do here is important, and how we do it is just as important as what we do. We live our values of integrity, excellence, and respect every day. We do the right thing, we do things right, and we treat people right. A career at the Federal Reserve Bank of Atlanta gives you the chance to do work that touches lives and helps communities prosper.

We are a dynamic hybrid workplace environment that requires at least 2 days a week in the office.

Position Summary:

The Threat and Vulnerability Management team provides vulnerability management and incident response services for the 6th Federal Reserve District. Under direct supervision from management and other team members, the TVM Analyst uses existing processes and procedures to solve routine or standard problems required to protect the organization’s information assets. Participates in one functional area defined below as primary responsibility and assists in other areas as requested. Works with critical and sensitive information daily and is relied upon to maintain intended security safeguards.

Key Responsibilities:

Participates in one functional area defined below as primary responsibility and assists in other areas as requested.

  • Foundational Skills:
    • Limited prior knowledge and experience with:
      • The MITRE ATT&CK framework.
      • Digital Forensics and Incident Response (DFIR).
      • Common cyber-attacks, malware, and the risk they pose.
      • Security Information Event Manager (SIEM) technology: searches, log analysis, and creation of alerts/alarms.
      • Typical enterprise networking architecture, protocols, and packet analysis.
      • Current trends in malware, cyber-attacks, and OS/application vulnerabilities.
      • Web application vulnerabilities, such as injection, configuration, information leakage, and typical threats, attacks, and countermeasures.
      • Dynamic web application vulnerability assessment scanners: configuration, scanning, and interpreting/triaging test results.
      • Enterprise network vulnerability scanning applications, including use and administration.
      • Communicating with stakeholders regarding cyber topics, can drive results to reduce risk in the environment.
      • Threat hunting methodologies and frameworks.
      • Cloud service provider technologies and security.
  • Function Areas:
    • Flaw Remediation
      • Applies patches, configurations, group policy objects, or other remediation activities to workstations and other endpoints using a variety of toolsets.
      • Reviews reports and conducts additional research on how to remediate vulnerabilities.
      • Coordinates remediation activities.
    • Host Vulnerability Assessment
      • Manages and maintains network scanning configuration (but not infrastructure).
      • Measures, reports, analyzes, and communicates vulnerabilities in terms of both risk and compliance.
      • Notifies stakeholders of vulnerabilities, collaborates on remediation recommendations, tracks and escalates remediation performance.
    • Incident Response
      • Manages all aspects of information security incidents. Prepares through exercises and continuous learning, performs evidence collections and analysis, contains and eradicates threats, documents activities, manages stakeholder communication and involvement, and conducts Lessons Learned reviews.
      • Communicates threats, impacts, and trend information to leadership and stakeholders.
      • Lead remediation projects where security gaps have been identified.
    • Incident Detection
      • Augments national SOC detection capabilities by implementing local detection interests. Collaborates with stakeholders on detection capabilities and use case design.
      • Monitors and analyzes logs and data, produces reports and real-time alerts.
      • Leverages industry frameworks to understand attacker tactics, techniques, and procedures to prioritize detection use cases.
      • Hunts for threats based on attack methods discovered from incidents, industry reports and intel.
    • Web Application Vulnerability Assessment
      • Identifies, validates, reports, and escalates vulnerabilities in web applications using dynamic and integrated application security testing (DAST & IAST).
      • Collaborates with stakeholders to understand vulnerability risks and remediation techniques.
      • Configures and maintains dynamic and/or integrated scanning applications.
    • Other Position Priorities:
      • Participates on workgr

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Federal Reserve System

View company profile →