Jobs and Careers
FE

Info Security Analyst, Advanced

Federal Reserve System
Minneapolis, United Statesfull_timeVerifiedPosted 14 Jun 2024
💰 $160,400/yr($106,900/yr$160,400/yr)

About the role

Company

Federal Reserve Bank of Minneapolis

The Federal Reserve Bank of Minneapolis is looking for a dynamic and enthusiastic Information Security Analyst to join our Information Security Governance, Risk & Compliance team.

As an Information Security Analyst, you will provide expertise to business and technology stakeholders in your role supporting cyber risk management activities throughout the Bank. Ideal candidates will have had previous experience with information security control and risk management frameworks such as NIST 800-53 and NIST 800-37. If you are a self-starter with a passion for identifying and assessing risks, and approaching mitigation from a holistic perspective, this position is for you.

This is not a remote position. The Minneapolis Fed believes in flexibility to balance the demands of work and life while also recognizing the necessity of connecting and collaborating with our colleagues in person.

Onsite work is an essential function of this position, and you are expected to be in the office at least one day per week for meetings and team collaboration.

Responsibilities:

  • Ensure that applicable IT security policies are implemented for assigned information systems and boundaries.

  • Ensure that applicable security risk management activities prescribed by the Bank’s risk management framework (e.g. SAFR Lifecycle) are followed including:

    • Providing guidance and expertise to effectively categorize information and information systems to ensure impact levels for the security objectives of Confidentiality, Integrity, and Availability are aligned appropriately. 

    • Supporting development and implementation of System Security Plans (SSPs) including selection of controls and  development of related artifacts, control procedures or related specification documents. 

    • Performing and/or facilitating assessment activities to validate security controls are implemented correctly, operating as intended, and producing the desired outcomes.

  • Ensure that applicable requirements for Information Security Continuous Monitoring are followed including:

    • Completing annual Security Assessments and Authorizations as well as assessments whenever there are significant changes to the information system.

    • Ensuring sure that an operational continuous monitoring plans are maintained and executed as part of the System Security Plan (SSP).

    • Ensuring the execution of risk assessments prior to the implementation of system changes to determine impacts to the security controls established for the system.

    • Ensuring that all Risk Acceptances and Plan of Action and Milestones (POA&Ms) are created, reviewed, and reported to key stakeholders such as the System Owner and Authorizing Official (AO).

  • Coordinate with the System Owner to update the SSP, manage and control changes to the system, and ensure that security impacts of proposed changes are evaluated by or reported to officials responsible for change control.

  • Ensure that all security documentation (e.g. System Security Plan, Contingency Plan, Configuration Management Plan, etc.) is properly maintained, approved, updated, and compliant with security program requirements.

  • Support refinement of the Information Security team backlog, as needed, ensuring clear requirements alignment in support the team’s mission or objective.

  • Support project initiatives by gathering, analyzing, and capturing input from customers, partners or stakeholders and synthesizing into clear and actionable requirements (user stories) for prioritization and execution.

  • Collaborate with business and technology teams on projects and key initiatives to ensure that security requirements are communicated and addressed throughout the project life cycle. Provide education to staff on applicable policies, procedures, and standards.

  • Collaborate with junior team members and assist with mentoring on risk assessment processes and documentation.

  • Identify, assess, track and report on IT/Security risks across the enterprise. Track risk decisions and remediation plans. Work closely with Enterprise Risk to communicate risks to both technical and non-technical audiences.

  • Conduct research and analysis on relevant security topics and prepare written or verbal reports or presentations stakeholders and management.

Qualifications:

  • Bachelor’s degree in computer science, information systems, computer engineering, cybersecurity, or a related field.

  • A minimum of nine (9) years of broad technical experience within IT or cybersecurity for Information Security Analyst – Advanced OR a minimum of nine (5) years

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Federal Reserve System

View company profile →