Manage vulnerability management program at the Federal Reserve Bank of Chicago. Collaborate on security observability processes and participate in cyber incident response activities.
Responsibilities
Manages and maintains the organization’s vulnerability management program, compiling metrics and performance across the enterprise and its products;
Improving and maintaining processes to categorize vulnerabilities and route to appropriate implementation teams for resolution;
Supporting FRFS cyber risk assessment, evaluation and tolerance processes;
Tracking and ongoing reporting of key performance and risk indicators;
Serving as a liaison between FRFS IS and other key internal and external stakeholders.
Establishes and maintains end-to-end observability processes and improvements, defining key alerts and monitors to support an effective incident response process;
Collaborating with other shared services teams to bring the vision to reality in iterative and incremental fashion.
Key participant in cyber incident response processes and maintainer of associated processes and procedures.
Maintains relationships with business areas that interact with FRFS, District, and National governance processes.
Supports the collection and tracking of cybersecurity and threat intelligence information via open-source and private partnerships.
Requirements
Bachelor's degree in computer science, information systems, business, or a related field; or the equivalent combination of education and experience.
3+ years of demonstrated experience in program management, workflow automation, and/or incident response within an IT enterprise.
Experience in end-to-end monitoring and alerting solutions, SIEMs, and equivalent technologies in support of anomalous activity monitoring/escalation/triage.
Familiarity with Splunk, DataDog, and related SIEM tools.
Familiarity with contemporary scripting tools such as Powershell, Unix shells, etc.
Familiarity with security orchestration and data transformation processes.
Experience collaborating with senior management to define, track and manage key risk indicators (KRIs).
Experience collaborating in cross-functional teams to implement industry best practices such as least-privilege enforcement, infrastructure segmentation, DNSSEC, and zero trust architecture.
Familiarity with cryptographic and public key technologies including, but not limited to, TLS, PKI, Multi-factor Authentication solutions, RSA, and Elliptic Curve Cryptography.
Familiarity in low-code/no-code workflow solutions and application lifecycle management solutions.
Strong oral and written communication skills to support engagement across technical and business stakeholders.
Existing SECRET security clearance or must meet eligibility requirements to apply for clearance.
Benefits
Comprehensive benefits package include medical, dental, vision, prescription drug coverage, 401k savings plan, retirement plan, paid time off, transit benefit, onsite gym and subsidized cafeteria
A continuous learning environment with opportunities to gain new skills and grow your career
The Chicago Fed offers benefits to support overall health and financial security.
Systems Administrator managing IT support and compliance activities in a tech - oriented company. Leading infrastructure design and security measures while collaborating with managed service providers.
Cyber Security Expert supporting project teams with structured risk assessments and compliance documentation at Nordex wind farms. Collaborating closely with Information Security to ensure secure operations.
OT Cybersecurity Engineer enhancing cybersecurity in industrial environments. Ensuring compliance with cybersecurity standards and collaborating across engineering, IT, and product teams.
Information Security Analyst implementing security solutions at one of Brazil's largest banks. Focus on information security and compliance with internal policies and best practices.
Security Intern collaborating with security teams to ensure compliance and develop secure processes in fintech environment. Engaging in hands - on experience with application security and risk management.
Senior Manager of Cybersecurity application and cloud security at Medtronic. Leading teams to enhance security in cloud - native environments and software development.
Security Engineer designing and implementing secure architecture solutions for Disney's global technology ecosystem. Collaborating with teams to assess threats and secure AI/ML implementations and technologies.
Head of Information Security at Thndr, leading security strategy and governance across Egypt, UAE, and KSA. Responsible for managing risk and building trusted security function.
Security Lead responsible for security across product, cloud infrastructure, and internal systems. Aiming to enhance security measures and practices within a SaaS environment.