Cyber Security Engineer Principal

Federal Reserve SystemSt. Louis, MO
3dOnsite

About The Position

Federal Reserve Financial Services (FRFS) delivers a suite of payments services to financial institutions via FedLine® Solutions, Fedwire® Funds and Securities, the National Settlement Service (NSS), FedCash®1, FedACH®, Check Services, and the FedNow® Service. FRFS operates as a fully integrated organization with groups dedicated to customer experience, operations, technology, product and customer/industry management, enterprise services, payments system improvement, and one focused on the ongoing growth and development of the FedNow instant payment service. Our strategy defines our future direction, seeking to offer a fully integrated product suite that provides speed, resilience, and choice in meeting the payments needs of FRFS customers across the United States. Through our Enterprise structure, we strive to meet the needs of the marketplace for new products and services with speed and agility, seek to provide a robust and unified customer experience, and work to create career growth opportunities for FRFS staff. The FRFS Enterprise operates with a customer-first mindset, comprised of team members seeking to do the best work of their careers in pursuit of our important central bank mission. The position will be primarily on-site with residency commutable to one of our offices required. This position is responsible for helping to ensure the security and integrity of the FedNow organization across people, operations, and technology. This individual will directly support security engineering and operations. The individual will also be expected to provide cybersecurity expertise both through consultation and hands-on technical activities.

Requirements

  • Programming Languages relevant to web and API development such as Python, Java, GO is required
  • Experience security testing cloud workloads.
  • Strong understanding of web service protocols, REST principles, and client-server architecture is necessary
  • Strong understanding of API defense strategies and ability to implement
  • Foundational understanding of logging and monitoring tools to detect anomalies and respond to incidents in real-time
  • Strong attention to detail and creative problem-solving are essential for navigating complex security challenges
  • Ability to effectively communicate risks and solutions to both technical and non-technical stakeholders
  • Collaborating effectively within a team, including developers, platform architects, and project managers in a multi-district environment
  • 5+ years of experience in an object-oriented language (Python, Java, or Go preferably)
  • Experience working in a DevSecOps software development environment
  • 5+ years of experience in Cyber Security, with a focus on API gateway engineering
  • 5+ years of Cloud Native experience (AWS preferred)
  • Strong understanding of API Security, OWASP API Top 10, secure API design principles
  • Exposure to API gateway security tools (runtime protection, discovery, or posture mgmt.)
  • Proficiency in working with Infrastructure as Code (i.e Terraform, Pulumi)
  • Proven experience building and securing CI/CD pipelines (GitHub, GitLab CI, Jenkins, etc.)
  • Proficiency with container technologies (Docker, Kubernetes) and their security implications
  • Expertise with Cloud IAM configuration/policies, container orchestration/testing
  • Strong communication skills with ability to influence at all levels of the organization; ability to simplify complex security topics for consumption and critical decision making.
  • The ability to obtain security clearance
  • Be able to support on-call and work-rotation activities
  • Relevant certifications (e.g., CISSP, CISM, GIAC, AWS, AZURE).
  • All employees assigned to this position will be subject to FBI fingerprint/ criminal background and Patriot Act/ Office of Foreign Assets Control (OFAC) watch list checks at least once every five years.
  • All applicants must have resided in the United States for at least three (3) years
  • For this job, any offer of employment is contingent upon successfully passing a two-phase security screening.

Responsibilities

  • Develop code to automate security frameworks into functional, secure infrastructure and deploy security tooling using automation as a foundation.
  • Design and execute point-in-time security tests, automated or manually, against cloud workloads.
  • DevSecOps integration – enable automate static and dynamic API security checks using CI/CD tools.
  • Enforce governance gates during key lifecycle phases (eg. Design, Validate, Publish)
  • Partner with application, security, and platform teams to embed security into API design, development, and deployment.
  • Contribute to security architecture reviews, threat modeling, and technical design discussions
  • Define, configure, and enforce API gateway policies for authentication, authorization, encryption, and traffic-management controls
  • Monitor traffic and collaborate with security and engineering teams on incident response and remediation
  • Represent a technologist’s point of view in selecting tooling and solutions.
  • Proven ability to collaborate, build relationships and influence direct & in-direct team members in a matrix-management environment.
  • Present and debrief cybersecurity findings, risk posture, and control effectiveness to leadership and management audiences, translating technical security data into clear, actionable insights to support informed decision-making.
  • Actively seek to remove barriers and improve security across the program.
  • Document technical solutions developed and the supporting processes.
  • Identify and address the root causes of issues, focusing on solving problem categories rather than individual instances.
  • Engage early and comprehensively.
  • Lead and execute cyber incident response activities, including detection, analysis, containment, eradication, and recovery with a focus on senior-level responsibilities.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service