Demo

Sr. Cybersecurity Analyst II (Sr Vulnerability Analyst) - Information Technology

Federal Reserve Board
Washington, DC Full Time
POSTED ON 6/7/2026
AVAILABLE BEFORE 7/13/2026
Position Description

Minimum Education

Bachelor's degree or equivalent experience

Minimum Experience

6

Summary

Oversees and/or participates in the instrumentation and administration of cybersecurity tools, appliances, and measures to protect the Board’s IT assets and ensure the Board’s ability to conduct its mission. Utilizes cybersecurity tools such as firewalls, proxies, intrusion detection, intrusion prevention, endpoint protection, and data analysis platforms as part of an integrated, defense in depth solution with a central security information and event management (SIEM) system and security orchestration tools. Develops an expert understanding of system architecture and the ability to identify security weaknesses that can be exploited to compromise a variety of systems used by the Board. Develops technical products and presents highly technical subjects to a variety of audiences ranging from non-technical senior leaders to highly technical subject matter experts. Oversees collaboration with other cybersecurity professionals to develop and implement cybersecurity solutions that enable threat hunt activities. With limited guidance provides technical and analytical assessments to support information security engineering decisions to ensure Board information and systems are adequately protected.

Duties And Responsibilities

  • Oversees and/or participates in implementing cybersecurity tools such as firewalls, proxies, intrusion detection, intrusion prevention, endpoint protection, and data analysis platforms as part of an integrated defense in depth solution with a central security information and event management (SIEM) system and security orchestration tools. Oversees the development of technical and analytical assessments to support information security engineering decisions to ensure Board information and systems are adequately protected. Able to characterize and manage complex risks to mitigate cyber threats.
  • With limited guidance, proactively supports analysis of threat intelligence from a variety of sources to understand the nature of the threat, extract the information that informs threat hunt operations, and uses that information to investigate Board IT assets for evidence of an intrusion or compromise.
  • With limited guidance, emulates threat actor tactics, techniques, and procedures in a controlled and/or production environment to demonstrate and observe the technical aspects of the emulated activity. Oversees and/or develops adequate detection strategies and development of mitigations as needed to address the specific details of the threat.
  • Oversees the development of programs that apply statistical models, mathematical principles, and other analytic tradecraft to a variety of IT network-generated data for the purposes of identifying anomalous activity, suspicious network activity, and ultimately leads to the discovery of intrusions and/or compromises.
  • With limited guidance, identifies and analyzes system-generated logs and captures forensic images of a variety of systems for the purposes of fully analyzing a cybersecurity intrusion and/or compromise. Includes use of expert knowledge to perform root cause analysis and develop timelines to show the actions taken by a cyber threat actor in an environment. Oversees the completion of all phases of the incident response process including identification, containment, eradication, and remediation.
  • Oversees implementation of vulnerability scans and ensures operational systems are adequately patched to protect the Board from potential cyber threat actors. Oversees the analysis of vulnerabilities and proof of concept code as it becomes available to assess the technical implications of a given threat and ensure that the Board’s defenses are sufficient. Maintains expert knowledge of ethical hacking principles to apply the skills to the management of vulnerabilities and mitigation of technical risk. Ensures that vulnerabilities are managed and patched according to Board policies and procedures.
  • Oversees the development of and/or develops the development of data analytic software and cybersecurity scripts using a variety of programming and scripting languages to enable cybersecurity activities designed to defend the Board’s IT assets. Independently develops programs, software, and scripts that automate the cybersecurity process. Independently develops data queries and scheduled jobs designed to correlate data for further analysis. Independently integrates tools and systems for advanced analysis of relevant data.
  • With limited guidance, manages cybersecurity projects focused on developing and instrumenting complex approaches to detect, prevent, and respond to cybersecurity intrusions and/or compromises. Authors documents and oversees the execution of project plans, schedules, requirements, risks, assumptions, cost, performance, and resource utilization with minimal supervision.

Position Requirements

FR-27 Minimal Qualifications

Requires a bachelor’s degree, preferably in computer science, information technology, cybersecurity or a related business technology field and six years of experience. With limited guidance, manages cybersecurity projects focused on developing and instrumenting complex approaches to detect, prevent, and respond to cybersecurity intrusions and/or compromises. Authors documents and oversees the execution of project plans, schedules, requirements, risks, assumptions, cost, performance, and resource utilization with minimal supervision. Must have expert knowledge in at least one of the following areas: general cybersecurity fundamentals, cyber threat analysis, data science principles, digital forensics, incident handling, incident management, incident response, vulnerability management, security engineering, automation and programming, project management, and relevant technologies and programming languages. Must be able to work effectively with staff. Must be familiar with relevant policies, procedures, and be able to work with TOP SECRET / SENSITIVE COMPARTMENTED INFORMATION. Must be able to lead one or more of the following: providing threat assessments, recommending cybersecurity technologies for intrusion detection and prevention, assessing technical vulnerabilities, identifying automation opportunities, investigating, and resolving security breaches, technical writing, and communication.

FR-28 Minimal Qualifications

Requires a bachelor’s degree in computer science, information technology, cybersecurity or a related business technology field and eight years of experience. Must have expert knowledge in the in at least one of the following areas: general cybersecurity fundamentals, cyber threat analysis, data science principles, digital forensics, incident handling, incident management, incident response, vulnerability management, security engineering, automation and programming, project management, and relevant technologies and programming languages. Must be able to work effectively with staff. Must be familiar with relevant policies, procedures, and be able to work with TOP SECRET / SENSITIVE COMPARTMENTED INFORMATION. Must be able to direct one or more of the following: providing threat assessments, recommending cybersecurity technologies for intrusion detection and prevention, assessing technical vulnerabilities, identifying automation opportunities, investigating, and resolving security breaches, technical writing, and communication.

Remarks: The Sr. Cybersecurity Analyst II (Sr. Vulnerability Analyst) is an individual contributor position responsible for supporting the enterprise vulnerability management program for the Board. The Sr. Cybersecurity Analyst II (Sr. Vulnerability Analyst) possesses knowledge of policies and best practices pertinent to vulnerability management and has the ability to operationalize that information in the form of organizational governance and technical process (NIST, DHS/CISA, OWASP, NVD, SEI, etc.). The Sr. Cybersecurity Analyst II (Sr. Vulnerability Analyst) consumes cyber threat intelligence that describes new and emerging vulnerabilities and translates that information into active defense and preventive measures. The Sr. Cybersecurity Analyst II (Sr. Vulnerability Analyst) analyzes systems for potential weaknesses and/or vulnerabilities and proposes solutions to mitigate those risks. The Sr. Cybersecurity Analyst II (Sr. Vulnerability Analyst) establishes and oversees patch management operations for all kinds of assets in the environment and designs mitigations where patching is impractical or impossible. The Sr. Cybersecurity Analyst II (Sr. Vulnerability Analyst) establishes and implements a risk management approach for vulnerabilities including thresholds, mitigations, and risk tolerances that drives other vulnerability response actions. The Sr. Cybersecurity Analyst II (Sr. Vulnerability Analyst) provides services including static and dynamic application security testing, web application vulnerability scanning, vulnerability analysis, enterprise patch management, and proposing mitigations for specific threats. The Sr. Cybersecurity Analyst II (Sr. Vulnerability Analyst) develops technical products and presents highly technical subjects to a variety of audiences, ranging from non-technical senior leaders to highly technical subject matter experts. The Sr. Cybersecurity Analyst II (Sr. Vulnerability Analyst) collaborates with other vulnerability management professionals in the Federal space and throughout the Federal Reserve System to develop and implement cybersecurity solutions that enable vulnerability management activities. The Sr. Cybersecurity Analyst II (Sr. Vulnerability Analyst) provides technical and analytical vulnerability assessments to support information security engineering decisions to ensure Board information and systems are adequately protected.

Highly Desirable

  • At least 5-7 years of full-time experience supporting a vulnerability management program.
  • Experience applying industry standards and best practices in an operational environment to adequately manage risk and mitigate vulnerabilities as part of an enterprise service.
  • Experience with a variety of vulnerability and patch management technologies including, but not limited to, Qualys, Tenable, Nessus, Invicti, Fortify, CrowdStrike Falcon Spotlight, Microsoft Defender Vulnerability Management, etc.
  • Experience applying expert knowledge of adversary tactics, techniques, and procedures to identify, prioritize, and ultimately respond to vulnerabilities identified within the Board’s enterprise network.
  • Knowledge of artificial intelligence models applicable to vulnerability analysis.
  • Experience mentoring less experienced team members in vulnerability management and response activities.
  • Experience in vulnerability analysis, threat modeling, and designing mitigation and remediation strategies.
  • Experience managing vulnerabilities in on-premises systems, mobile devices, and in cloud environments, (e.g. Amazon Web Services, Microsoft Azure, Google Cloud, and Data Centers).
  • Experience developing programs and/or automated tools using programming / scripting languages (e.g. Python, PowerShell, etc.).
  • Experience integrating APIs and security tooling workflow preferred
  • Familiarity with relevant policies, procedures, and able to work with TOP SECRET / SENSITIVE COMPARTMENTED INFORMATION.
  • Demonstrated resourcefulness and advanced critical thinking skills to independently direct, analyze, and implement solutions for all the various complex problems that arise in the administrative and operations area.
  • Expert technical writing and communications skills. Contacts are often with division leadership, but also with staff at all levels; a significant degree of coordination and contact with other units/sections/divisions may also be required.
  • Ability to construct clear and concise written work and applies an increasingly advanced understanding of grammar, sentence structure, and intended audience(s) to the process of writing and editing such work.
  • Ability to explain to cross-team or cross-divisional partners items of high levels of complexity.
  • Possess skills in negotiation and persuasion in performing duties and influencing support for change.

The expected salary range for this role is $140,500 - $210,000, which spans all the posted grades. Final offers are based on the grade for which you minimally qualify and are determined by experience and education, as well as internal and external factors.

This position requires an in-office presence in Washington, DC

Primary Location

DC-Washington

Employee Status

Regular

Overtime Status

Exempt

Job Type

Standard

Relocation Provided

Yes

Compensation Grade Low

FR PAY GRADE 27

Compensation Grade High

FR PAY GRADE 28

Minimum Salary

$140,500.00

Maximum Salary

$210,500.00

Posting Date

May 14, 2026

Salary : $140,500 - $210,500

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Sr. Cybersecurity Analyst II (Sr Vulnerability Analyst) - Information Technology?

Sign up to receive alerts about other jobs on the Sr. Cybersecurity Analyst II (Sr Vulnerability Analyst) - Information Technology career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$79,882 - $99,769
Income Estimation: 
$105,207 - $132,120
Income Estimation: 
$94,567 - $126,847
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Federal Reserve Board

  • Federal Reserve Board Washington, DC
  • Position Description Minimum Education Bachelor's degree or equivalent experience Minimum Experience 6 Summary The Executive Recruiting Specialist leads th... more
  • 4 Days Ago

  • Federal Reserve Board Boston, MA
  • Company Federal Reserve Bank of Boston Federal Reserve Financial Services (FRFS) delivers a suite of payments services to financial institutions via FedLin... more
  • 4 Days Ago

  • Federal Reserve Board Washington, DC
  • Position Description Minimum Education Enrolled in an undergraduate or graduate degree program at an accredited university and returning to continue studie... more
  • 6 Days Ago

  • Federal Reserve Board Washington, DC
  • Position Description Minimum Education Bachelor's Degree or Equivalent Experience Minimum Experience 6 Summary Under the general direction of the managing ... more
  • 6 Days Ago


Not the job you're looking for? Here are some other Sr. Cybersecurity Analyst II (Sr Vulnerability Analyst) - Information Technology jobs in the Washington, DC area that may be a better fit.

  • Creative Information Technology, Inc Falls, VA
  • Title: ETL Developer / Data conversion / Data Migration Location: Remote Job Description The Data Conversion Specialist is responsible for the design, deve... more
  • 1 Month Ago

  • INFORMATION TECHNOLOGY STRATEGIES INC Ashburn, VA
  • Information Technology Strategies, Inc. is a government IT solutions provider servicing commercial and government initiative in various parts of the United... more
  • 14 Days Ago

AI Assistant is available now!

Feel free to start your new journey!