Cyber Threat/Incident Analyst (Associate/Sr./Engineer/Sr. Engineer)
Federal Reserve SystemAbout the role
Company
Federal Reserve Bank of AtlantaAs an employee of the Atlanta Fed, you will help support our mission of promoting the stability and efficiency of the U.S. economy and financial system. Your work will affect the economy of the Southeast, the United States, and the world. The work we do here is important, and how we do it is just as important as what we do. We live our values of integrity, excellence, and respect every day. We do the right thing, we do things right, and we treat people right. A career at the Federal Reserve Bank of Atlanta gives you the chance to do work that touches lives and helps communities prosper.We are a dynamic hybrid workplace environment that requires at least 2 days a week in the office.
Position Summary:
The Threat and Vulnerability Management team provides vulnerability management and incident response services for the 6th Federal Reserve District. Under direct supervision from management and other team members, the TVM Analyst uses existing processes and procedures to solve routine or standard problems required to protect the organization’s information assets. Participates in one functional area defined below as primary responsibility and assists in other areas as requested. Works with critical and sensitive information daily and is relied upon to maintain intended security safeguards.
Key Responsibilities:
Participates in one functional area defined below as primary responsibility and assists in other areas as requested.
- Foundational Skills:
- Limited prior knowledge and experience with:
- The MITRE ATT&CK framework.
- Digital Forensics and Incident Response (DFIR).
- Common cyber-attacks, malware, and the risk they pose.
- Security Information Event Manager (SIEM) technology: searches, log analysis, and creation of alerts/alarms.
- Typical enterprise networking architecture, protocols, and packet analysis.
- Current trends in malware, cyber-attacks, and OS/application vulnerabilities.
- Web application vulnerabilities, such as injection, configuration, information leakage, and typical threats, attacks, and countermeasures.
- Dynamic web application vulnerability assessment scanners: configuration, scanning, and interpreting/triaging test results.
- Enterprise network vulnerability scanning applications, including use and administration.
- Communicating with stakeholders regarding cyber topics, can drive results to reduce risk in the environment.
- Threat hunting methodologies and frameworks.
- Cloud service provider technologies and security.
- Limited prior knowledge and experience with:
- Function Areas:
- Flaw Remediation
- Applies patches, configurations, group policy objects, or other remediation activities to workstations and other endpoints using a variety of toolsets.
- Reviews reports and conducts additional research on how to remediate vulnerabilities.
- Coordinates remediation activities.
- Host Vulnerability Assessment
- Manages and maintains network scanning configuration (but not infrastructure).
- Measures, reports, analyzes, and communicates vulnerabilities in terms of both risk and compliance.
- Notifies stakeholders of vulnerabilities, collaborates on remediation recommendations, tracks and escalates remediation performance.
- Incident Response
- Manages all aspects of information security incidents. Prepares through exercises and continuous learning, performs evidence collections and analysis, contains and eradicates threats, documents activities, manages stakeholder communication and involvement, and conducts Lessons Learned reviews.
- Communicates threats, impacts, and trend information to leadership and stakeholders.
- Lead remediation projects where security gaps have been identified.
- Incident Detection
- Augments national SOC detection capabilities by implementing local detection interests. Collaborates with stakeholders on detection capabilities and use case design.
- Monitors and analyzes logs and data, produces reports and real-time alerts.
- Leverages industry frameworks to understand attacker tactics, techniques, and procedures to prioritize detection use cases.
- Hunts for threats based on attack methods discovered from incidents, industry reports and intel.
- Web Application Vulnerability Assessment
- Identifies, validates, reports, and escalates vulnerabilities in web applications using dynamic and integrated application security testing (DAST & IAST).
- Collaborates with stakeholders to understand vulnerability risks and remediation techniques.
- Configures and maintains dynamic and/or integrated scanning applications.
- Other Position Priorities:
- Participates on workgr
- Flaw Remediation
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s