Cyber Security Analyst III/Senior

Federal Reserve Bank of PhiladelphiaCleveland, OH
Onsite

About The Position

The Federal Reserve Bank of Cleveland is seeking a Cyber Security Analyst III/Senior to support the Cybersecurity Analytics Support Team (CAST). This role involves actively working with CAST personnel, supervisory staff, and Board of Governors’ staff on ongoing cyber incidents within supervised institutions and emerging threats impacting the U.S. financial sector. The position requires expertise in multiple cybersecurity subject matter areas, including frameworks like NIST 800-53 and CSF, assessing threats and vulnerabilities, recommending mitigations, tracking threat actor groups, understanding cloud services (AWS, Azure, GCP), incident management, and security architecture. Access to confidential supervisory information requires candidates to be "Protected Individuals" as defined by U.S. federal immigration law. Candidates who are not U.S. citizens or permanent residents may be eligible for sponsorship and must declare their intent to become a U.S. citizen. All candidates will undergo an enhanced background check.

Requirements

  • Analyst III: Bachelor’s degree in computer science, Management Information Systems or related field and 7+ years of related work experience required OR Master's Degree and 5+ years of professional work experience.
  • Senior Analyst: Bachelor’s degree in computer science, Management Information Systems or related field and 10+ years of related work experience required OR Master's Degree and 7+ years of professional work experience.
  • Advanced ability to perform independent research and provide written reports summarizing findings and analysis.
  • Intermediate knowledge of regulations, procedures, and practices of a specific discipline (e.g., bank examinations, information security, cyber intelligence).
  • Advanced problem solving and analytical thinking.
  • Advanced specialized operational/technical skills in cyber intelligence and information security.
  • Intermediate knowledge of Microsoft Office; general proficiency in Word, PowerPoint and Excel.
  • Intermediate knowledge of project management.
  • Intermediate ability to analyze information and demonstrate findings with written reports, data visualizations, graphs/charts, or presentations.
  • Expert knowledge of regulations, procedures and practices of a specific discipline (e.g. information security, cyber intelligence).
  • Advanced knowledge of intelligence concepts; intelligence lifecycle, diamond method, structured analytic techniques (red team, devil's advocate, analysis of competing hypothesis).
  • Advanced knowledge in: NIST, ITIL, COBIT, guidelines, security analytics, network architecture / perimeter security, network monitoring and analysis, threat intelligence and advanced threats, authentication, secure coding / application development, penetration testing, cyber incident response, web based attacks and mitigations, cyber risk assessment and strategic analysis, vulnerability detection and assessment, mobile device management, and digital forensics and advanced security tools (e.g. DDoS, malware, DLP, MFA, SIEM, vulnerability scanning and patching).
  • Advanced knowledge in areas of technology governance, technology risk management/GRC, internal audit, vendor/third-party management, business resiliency and fraud.
  • Security operations concepts; perimeter defense, BYOD, data loss protection, insider threat, kill chain, risk assessment, etc.
  • Relevant IT certifications (CISA, CISSP, CGEIT, CRISC, CRMA).
  • Expert problem solving and analytical skills.
  • Expert specialized operational/technical skills in cyber intelligence and information security.
  • Advanced written and verbal communication.
  • Advanced presentation skills.
  • Advanced public speaking skills.
  • Advanced strategic thinking/planning skills.

Nice To Haves

  • Cybersecurity related frameworks such as NIST 800-53, NIST Cybersecurity Framework (CSF), IS 27001, MITRE ATT&CK, etc.
  • Assessing cybersecurity threats, vulnerabilities, and related exploitation activity; recommending related mitigations to manage risk to computing environments.
  • Tracking and reporting on threat actor groups that potentially pose a threat to the United States financial sector.
  • Cloud services and providers such as Amazon Web Services, Microsoft Azure, and Google Cloud Platform.
  • Incident management and response activities related to cybersecurity events.
  • Security architecture and design implementation to mitigate threats against confidentiality, integrity, and availability.

Responsibilities

  • Conducts analysis and interpreting of cybersecurity threats to identify trends and emerging risks.
  • Provide input and insight into response activities during cyber incidents to include best practices from regulatory bodies, cybersecurity organizations, and NIST.
  • Conducts formal assessments to determine the severity of reported cybersecurity incidents at financial institutions.
  • Prepares in written form research, analysis, and assessments for key internal stakeholders as needed or requested.
  • Analysis supports recommendations regarding cybersecurity threats, threat vectors, threat actors and threat trends.
  • Demonstrates knowledge of cybersecurity threats within the broader financial sector and related industries.
  • Assist bank supervision examination teams, the central point of contact teams, and examiners-in-charge during active cybersecurity incidents at regulated banking/financial institutions.
  • Build and maintain relationships with central points of contact teams, examiners, and board staff across the Federal Reserve System.
  • Communicate appropriate information to the Supervision & Regulation staff at the Federal Reserve Bank and Board levels to maintain a comprehensive understanding of ongoing incidents and ensure appropriate steps are taken to isolate any potential residual effects from a cyber incident.
  • Participates in knowledge sharing forums related to key cybersecurity risks and emerging issues.
  • Participates in efforts to advance Reserve Bank or System strategic initiatives.
  • Provides leadership, coaching, and mentoring for less experienced analysts on processes and procedures related to internal matters and the supervisory process.
  • Weekend on-call support is part of the position on a rotating basis (generally once every 12 weeks).
  • Performs other duties as assigned or requested.

Benefits

  • Benefits to support overall health and financial security.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service