Jobs and Careers
FE

Portfolio Coordination Group (PCG) Senior Risk Specialist

Federal Reserve System
United Statesfull_timeVerifiedPosted 15 Feb 2024

About the role

Company

Federal Reserve Bank of Atlanta

The Federal Banking Agencies (FBAs) jointly conduct the supervision of technology services provided by certain third-party service providers under the authority provided in the Bank Service Company Act (BSCA). The Service Provider Program currently includes third-party service providers that are deemed particularly systemically important (i.e., Significant Service Providers, or SSPs) and the ones that are deemed less so (Regional Service Providers, or RSPs). Oversight of the Federal Reserve’s supervision of SSPs will be conducted by the SSP Management Group (MG).

The SSP portfolio is looking for highly motivated individuals to join the Portfolio Coordination Group (PCG), which supports the SSP MG in carrying out the MG’s governance and oversight responsibilities over the Federal Reserve’s SSP portfolio. The PCG coordinates supervisory program execution to ensure portfolio-wide transparency and consistency in a manner aligned with the strategic direction, priorities and plans set forth by the SSP MG. The PCG Senior Risk Specialist will report functionally to the PCG Lead. Administrative reporting will be through the Federal Reserve Bank of Atlanta.

*This position can be located in Atlanta, GA OR any branch of the Federal Reserve Bank where you can meet the hybrid work requirement.

Key Responsibilities:

  • Contributes to review of cybersecurity and/or cloud security examinations to determine the effectiveness of a FI’s and SSP’s cybersecurity posture and validate remediation efforts of identified issues.
  • Contributes on Federal Reserve System and local cyber security and/or cloud security initiatives related to training, committees, and development of policy statements to enhance the supervision of FIs and SSPs.
  • Supports review of supervisory plans for relevant cybersecurity and/or cloud security areas and effective risk-based supervision factoring in size and complexity of target firms.
  • Conduct horizontal (second-level) reviews of key Central Point of Contact’s (CPC’s) work products such as supervisory plans / strategies, exam scopes, conclusion memos, supervisory letters and reports of examination, findings and ratings, vetting deliverables following first-level review by the Responsible Reserve Bank.
  • Lead initiatives that modernize SSP supervision and assist with the vetting preparation of supervisory strategies, significant findings, and ratings.
  • Conduct and contribute to cross-entity work (e.g., scenario-developed analysis)
  • Identify, develop, and execute horizontal review topics
  • Implement SSP program enhancements or policy changes
  • Develop quarterly portfolio-level continuous monitoring topics
  • Develop portfolio-level analytics packages and dashboards
  • Coordinate incident response, threat and vulnerability monitoring
  • In coordination with the Reserve Bank Managers and Reserve Bank Partner(s) responsible for overseeing SSP CPCs and SSP cyber resources
  • Contribute to OASiS implementation and enhancements
  • Other duties as assigned

Desired Skillset:

  • Strong knowledge of supervision and the examination process to drive change and manage risk
  • Strong understanding of operational and cyber resilience, cloud security, third-party risk management and legal and policy mandates in the financial sector that pertain to third-party risk management and cybersecurity risks and industry standards and guidance (i.e., FFIEC IT Handbook and NIST CSF)
  • Previous SSP CPC experience and examiner commission a plus
  • Strong critical thinking, analytical and data analysis skills
  • Proven ability to effectively influence outcomes and build consensus across multiple stakeholders    
  • Ability to combine risk analysis with sound judgement in proposing recommendations 
  • Ability to engage and influence cross-functional teams and work collaboratively with internal and external teams
  • Excellent oral and written communications skills
  • Ability to lead, juggle and effectively prioritize multiple projects simultaneously while meeting critical deadlines and stakeholder expectations
  • Sound judgment, tact and diplomacy as well as keen political savvy and experience navigating complex third-party risk and cybersecurity issues.

Experience:

Minimum 5 years of experience in at least some of the following domains:

  • Cyber Security and IT Risk management
  • Cloud Security
  • Cybersecurity response and resilience
  • IT Audit and/or IT examination or supervision
  • Change and Configuration Management
  • Asset and Lifecycle Management
  • Vendor risk management
  • Cybersecurity response and resilience
  • Data governance and security
  • Endpoint and server technologies

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Federal Reserve System

View company profile →