Federal Reserve Bank

Incident Response Analyst - Overnight Shift

Federal Reserve Bank$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree or equivalent experience with 3+ years of relevant work experience
  • Expertise in SIEM/SOAR for security data analysis
  • Strong knowledge of incident response methodologies and the cyber threat landscape
  • Familiarity with attacker tactics, techniques, and procedures (TTPs)
  • Proficiency in analyzing data sources to identify potential compromises
  • Ability to effectively communicate complex security concepts
  • Relevant security certifications or equivalent expertise

Responsibilities

  • Perform security event triage and analysis
  • Analyze security event data to identify suspicious activity
  • Conduct postmortem analysis and network forensics
  • Respond to various attack vectors including malware and phishing
  • Develop scripts to enhance incident detection processes
  • Engage with NIRT customers and stakeholders
  • Complete projects related to security monitoring and incident response

Benefits

  • Flexibility to work remotely within a commutable distance
  • Eligible for shift differential for third shift work
  • Collaboration with a national incident response team
  • Opportunities to enhance skills through varied incident tasks
  • Potential for continuous consultation with industry experts
Full Job Description
Company
Federal Reserve Bank of Richmond

The Federal Reserve System (FRS) National Incident Response Team (NIRT) is seeking an Incident Response Analyst. The NIRT, a national service provider for the FRS, delivers effective intrusion detection, incident response, forensics, security intelligence, threat assessment, and penetration testing services.

The role is for an incident triage and response professional. You will be expected to be able to investigate and respond to security events within the FRS with minimal oversight. The ideal candidate will have some more specialized skills such as Security Operations Center (SOC) support, disk and/or memory forensics, phone forensics, malware analysis, and/or threat hunting skills.

Key Activities
  • Perform security event triage and analysis with knowledge in current security threats and techniques.
  • Analyze a large volume of security event data from multiple sources to identify suspicious and malicious activity.
  • Perform postmortem analysis of traffic flows.
  • Conduct network forensics.
  • Conduct follow up analysis throughout the incident life cycle.
  • Complete projects and tasks associated with security monitoring, detection, and incident response.
  • Analyze all relevant data sources for attack indicators and potential network and host compromises.
  • Respond to different attack vectors such as data exfiltration, DDoS, malware, insider risk, and phishing.
  • Develop scripts and tools to improve the efficiency of incident detection and response processes.
  • Interface with NIRT customers and stakeholders.


Qualifications
  • Bachelor's Degree or equivalent experience with 3+ years of relevant work experience.
  • In-depth understanding of a variety of information technologies and information security topics.
  • Specifically, this should include the following:
    • SIEM/SOAR utilization skills to analyze security events from multiple monitoring and logging sources to identify, investigate and confirm suspicious activity.
    • Knowledge of incident response and handling methodologies.
    • Knowledge of common adversary tactics, techniques, and procedures (TTPs).
    • Knowledge of cyber threats and vulnerabilities.
    • Knowledge of cyber-attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).
    • Knowledge of which system files (e.g., log files, registry files, configuration files) contain relevant information and where to find those system files).
    • Knowledge to analyze all relevant data sources for attack indicators and potential network and host compromises.
    • Knowledge of current security threats, techniques, and landscape, and a dedicated approach to research current information security landscape.
    • Understanding of IT Infrastructure designs, technologies, products, and services. This should include knowledge of networking protocols, firewall functionality, host and network intrusion detection systems, operating systems, databases, encryption, load balancing, and other technologies.
    • Hold one or more relevant security certifications/degrees and/or commensurate experience.
    • Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means, evaluate information for reliability, validity, and relevance, and function effectively in a dynamic, fast-paced environment.
    • Function in a collaborative environment, seeking continuous consultation with other analysts and experts-both internal and external to the organization-to leverage analytical and technical expertise, think critically and think like threat actors.
    • Ability to develop productive working relationships with a broad range of business and operational area professionals.


Additional Information

How We Work:
  • Location(s): Boston, MA- New York, NY- Philadelphia, PA- Cleveland, OH- Richmond, VA- Atlanta, GA- Chicago, IL- St. Louis, MO- Minneapolis, MN- Kansas City, MO- Dallas, TX- San Francisco, CA
  • This position will generally require working three (3) consecutive twelve (12) hour night shifts from 8:00pm - 8:00am ET, followed by four (4) days off. It may be required to shift days to ensure coverage when other team members are out.
  • This position will have the ability to work remotely, within a commutable distance to a Federal Reserve Bank location.
  • This position is eligible for a shift differential while working the 3rd shift.


Citizenship Requirements: United States citizenship is required for this position.

Screening Requirements: This position has additional screening requirements due to the information accessed while performing the job. These additional screenings would be initiated at the time of offer acceptance and could take up to a couple of months to complete. You can begin work before the screening is completed; however, continued employment is contingent on acceptable screening results. The areas screened may include education/employment verification, criminal history, credit history, and reference checks.

Sponsorship: The Federal Reserve Bank of Kansas City will not sponsor a new applicant for employment authorization for this positionApplicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future.

Full Time / Part Time
Full time

Regular / Temporary
Regular

Job Exempt (Yes / No)
Yes

Job Category
Information Technology Family Group

Work Shift
Third (United States of America)

About Federal Reserve Bank

Industry
Founded
1913

Similar Jobs

More Jobs at Federal Reserve Bank

More Information Technology Jobs

Find similar Incident Response Analyst - Overnight Shift jobs: