Cyber Security Risk Analyst

The Federal Reserve

Confirmed live 2 days ago High trust

Quick summary

Work type
On-site
Location
Chicago, IL
Posted
136 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

How this pay compares to similar roles

Similar $153k
$107k most similar roles pay here $197k

This listing doesn't post a salary. Most similar roles pay $123,875–$181,270.

Based on 239 similar postings.

Employer

About The Federal Reserve

The Federal Reserve is the central bank of the United States—one of the world's most influential, trusted and prestigious financial organizations.

The Federal Reserve currently has 23 open roles on FindRole.

Listed pay typically runs $133,350–$174,450 across 16 roles with salary data.

Most-posted roles

View all roles at The Federal Reserve

At a glance

TL;DR · Cyber Security Risk Analyst

The Cyber Security Risk Analyst joins the Cyber Security Assurance Department within the Information Security function. As an individual contributor, you will perform risk assessments, cloud mitigations, threat modeling, and security design reviews to manage risks associated with third-party vendors, IoT devices, and infrastructure. You will be embedded within development squads to provide security advice during the development lifecycle and integrate security tooling into the CI/CD pipeline. Key responsibilities include conducting application security testing for cloud migration workloads supporting mission-critical markets operations and evaluating generative AI systems. Required expertise includes NIST 800-53 risk management, DevSecOps practices in agile environments, and assessing third-party SaaS solutions. You will ensure only compliant workloads move to the cloud while managing security findings and protecting data across various technology processes and outsourcing arrangements.

What you'll do

  • Perform cloud application security risk assessments for mission-critical systems and migration workloads.
  • Conduct application security testing to ensure only compliant workloads move to the cloud.
  • Embed within development squads to provide real-time security advice during the development process.
  • Integrate security tooling into the CI/CD pipeline as part of DevSecOps methodologies.
  • Evaluate third-party vendors, SaaS solutions, and IoT devices for data protection risks.
  • Perform threat modeling and security design reviews for information systems.
  • Manage and resolve security findings within an Agile management practice.
  • Evaluate and secure Generative AI systems using internal and embedded models.

What we're looking for

  • Experience executing risk assessments in the cloud and against third-party SaaS solutions.
  • Expert knowledge of performing risk management based on NIST 800-53.
  • Ability to link risk management programs to critical business strategies and processes.
  • Experience working within a DevSecOps culture and agile environments.
  • Expert level application security testing skills supporting CI/CD pipelines.
  • Proven ability evaluating and securing Gen AI systems with internal and embedded models.
  • Experience evaluating third-party vendors with a focus on data protection.
  • Must possess or be able to obtain a National Security Clearance, which requires U.S. citizenship.

More like this

Similar roles

Information Security Specialist

The Federal Reserve

New York, NY 45 days ago
DevSecOps CI/CD Application Security Testing NIST 800-53 SaaS Gen AI Agile Risk Management Vulnerability Remediation Information Systems Risk Management IoT ICS

Cyber Security Analyst

Leidos

Adelphi, MD 17 days ago $87,100$157,450
SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Incident Response Cyber Kill Chain SaaS Security+ CE CSSP-Infrastructure Support Vulnerability Management Network Security
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 17 days ago $87,100$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 17 days ago $87,100$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Fort Belvoir, VA 17 days ago $87,100$157,450
SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Incident Response Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp

Information Security Risk Analyst

Lam Research

Tualatin, OR 68 days ago
SIEM Microsoft Sentinel Splunk KQL SPL SQL Python PowerShell MITRE ATT&CK UEBA Azure AWS Cloud Platform Entra ID Logic Apps STIX/TAXII MISP Threat Hunting Incident Response
Hybrid