Washington, DC, USA
6 days ago
Sr Vulnerability Analyst - Division of Information Technology

Remarks:

This internship position will:

Support 13 economists (within Policy Research Analysis) with their independent research. Research topics may vary widely.When priorities necessitate, support Policy High Priority initiatives.

The ideal hire will possess:

Some prior experience with databases or SQL.Some familiarity with statistics software (ex: SAS, R, STATA).



US Citizenship is required for all Board internships

Applicants must be current students enrolled in a degree seeking program

This position requires a combination of hybrid and in-person presence in our Washington DC office

Learn more about our internship program: https://www.federalreserve.gov/careers-internships.htm

US Citizenship is required for all Board internships and applicants must be current graduate-level students, graduating from their program Spring 2026 or later.

About the Team

The Workforce and Workplace Management (WWM) team in the Division of Supervision and Regulation aligns workforce development strategies and talent management programs with the strategic plans and priorities of the Division and Federal Reserve Board.

The WWM team’s mission is to support strategic initiatives within SR and the System by overseeing the implementation of various Board workforce planning and human resources programs. These programs include conflicts of interest (COFI), performance management, position management, rewards and recognition, teleworking and alternative work schedule programs, job rotation programs, student internships, onboarding programs and workforce analytics. Additionally, WWM's role focuses on providing strategic consultation to SR management team(s) and ensuring that these programs are implemented based on industry best practices and in line with the Board's policies.

About the Role

The WWM team is seeking a year-round graduate student intern to help support and manage several projects, research and administrative work in the Division of Supervision Regulation. The intern will primarily focus on the administration of the conflicts of interest (COFI) program. This is a great opportunity for a graduate student with an academic focus in law, finance, public policy or public administration. The selected individual will complete assignments pertaining to conflicts of interest and all aspects of an embedded talent management team.

Responsibilities include:

Provide support to the cross-sectional Conflicts of Interest (COFI) program.Assist the program manager and designated ethics officer in addressing specific conflicts of interest and compliance matters within the Board and Federal Reserve Banks.Support the administration of ethics and conflicts of interest training and maintain necessary training materials, procedures, FAQ’s.Support the review of confidential financial disclosure reports and related documents and assist financial disclosure filers to ensure reporting requirements are understood and necessary information is reported accurately.Process credentials for staff conducting bank examinations/inspections and facilitate conflicts checks for Board and Federal Reserve Banks.

Talent management support, including but not limited to the following areas:

Recruitment/onboardingRewards recognitionInternship programmingPerformance managementWorkday data entry and talent management administrationDrafting communications, research of best talent management practices, program improvement, and evaluation.Managing various SharePoint sites, lists, and librariesParticipation in special projects as assigned; may implement project recommendations.

Over the course of the internship, the student will:

Improve upon written and presentation skills;Improve upon analytical skills;Participate in creating leadership and staff development recommendations;Suggest process, policy and program enhancements;Gain experience in both COFI and talent management programming.

Suggested Education/Major: Pursuing graduate level degree in human resources, law, finance, public policy, public administration, business management, or related field.

Required Skills/Knowledge

Exceptional organizational skills and attention to detail;Strong verbal and written communication skills;Ability to work collaboratively in teams;Strong critical thinking, analytical, and problem-solving skillsExcellent time management and organizational skills;Ability to exercise a high degree of confidentiality in all areas of responsibilities.Demonstrated interest in Ethics, Compliance, and Legal matters.

Preferred Skills/Knowledge:

Proficiency in Microsoft Office Suite

Additional Notes

Anticipated Work Hours: During the summer, 40 hours per week; during the school semesters, min 15-20 hours per weekAnticipated Start Date: January 2025Anticipated Work Environment: This internship can be completed fully remote OR in a hybrid capacity in Washington, DC.

Qualifications

Requires organizational, time management, and communication skills, and learning agility normally acquired through completion of HSD/GED or equivalent and five years of experience (FR-22), six years of experience (FR-23) or a bachelor’s degree or equivalent experience and four years’ experience providing support in a training environment. Must be proficient in Microsoft Office and Adobe Pro and requires ability to learn specialized software applications. Must be customer service focused and able to work effectively with at all levels.

The Examiner Education Office of FFIEC administers the many facets of training programs for federal and state financial institution examiners.

Though a hybrid schedule is driven by the role, this position will require an on-site presence in Arlington, VA at the L. William Siedman Center as needed for in-person classes.

About the Team Role

The Research Library at the Federal Reserve Board is offering a paid summer internship for graduate-level library or information science students to advance several projects that will improve library services to the Board research and professional community. We offer a full array of customized library services to staff members throughout the Board, with particular focus on data-intensive research, data acquisitions and cataloging, research curation, and metadata and taxonomy.

To enhance discovery and use of the Board’s valuable resources and research, projects will focus on data- and metadata-related efforts. Depending on the intern’s skills and interests, they will work on several of the following projects that represent a variety of the library’s responsibilities supporting the Board:

§ Data Catalog Maintenance and Expansion Support

Projects may include supporting: cataloging data assets in line with national, international, and local standards; metadata maintenance and clean up; and quality checks among systems.

§ Technology, Software, and Process Improvements

Projects may include assisting with migration to new systems, including a new Library Services Platform, data catalog, and subscription management software, and documentation of code and processes.

§ Scholarly Research and Communications
Projects may include: Enhance and maintain metadata for DOIs through Crossref; citation reports enhancements; progress in use of researcher IDs (ORCID).

§ Metadata and Taxonomy Standardization and Enhancement

Interns may assist with taxonomy and authority control development to support interoperability of the Federal Reserve Subject Taxonomy (FRST) and Federal Reserve Authority of Names (FRAN) that are used multiple Fed downstream applications.

§ Research

Research and prepare a report on findings of library and information systems best practices in support of the Research Library's strategic plan.

§ Outreach and Marketing

Assist the library’s Outreach/Training Team with implementing library marketing plan, awareness campaigns to promote utilization of the Board’s research and data assets and develop and update training materials.

Qualifications/Skills:

U.S. citizenship requiredEnrolled in a Master’s degree program in library or information science at an ALA-accredited institution (MLS)Graduating fall 2025 or laterKnowledge and interest in library technologyEvidence of interest in the field of library and information science; have completed a minimum of 10 credits in foundational library and/or information science coursework by the start of the internship.Must have attention to detail, initiative, and good communication skills.Should have a basic understanding of metadata.Python and/or coding skills are a plus, but not required. Students with prior course work in cataloging and metadata is preferred, but not required.

Attach to your profile before submission:

cover letterresumeundergraduate graduate unofficial transcripts

Open to students interested in working hybrid or 100% virtual.

About the Team

The Administration team (Admin) within Research Statistics generally provides guidance and support to staff and management within the areas of human resources, training and development, budget, compensation, recruitment, and outreach. The team is seeking to hire a graduate intern interested in human resources, more specifically recruiting, outreach, and learning and development. This internship is designed to be both educational and practical, ideal for HR, management, organizational development and leadership, or related degree seekers.

About the Role

The intern will partner with the team in the areas of onboarding, internal training and development, outreach recruiting, and engagement. In addition, there is the opportunity to support communications, budgeting and forecasting, contracting, compensation, and space management.

Examples of possible projects include:

Event Execution: Coordinate logistics for onboarding and learning sessions, assist with externally facing informational sessions through task management, scheduling, post-event surveys, and correspondence for over 20 events.Collect and analyze data: support the evaluation and measurement of programs using Qualtrics and Forms. Conduct analysis of various types of survey responses to enhance and drive organizational change.Program support: research and recommend new program initiatives, evaluate procedures and recommend changes and participate in development of new guidelines.Training and Development: contribute to development of engaging and creative content and methods of delivery.Additional Organizational Development (OD) projects: Assist in preparation for staff and management training and programming, collaborate with other interns in executing internally facing learning sessions, support with externally facing materials and events as needed.

Qualifications/Skills

Ability to work on-site 2-3 days a week in our offices in downtown Washington, D.C.Currently enrolled in a graduate degree program in a field related to Organizational Development, Industrial/Organizational Psychology, Organizational Behavior, Management, Finance, Human Resources or Business.Graduating fall 2025 or laterSome experience with developing and delivering training contentSome experience with survey tools, such as Qualtrics or Microsoft FormsEffective communication skills (written and verbal)Action orientedAbility to adapt and continuously learnComfortable collaborating and working across functions or teams

Duties and Responsibilities

· With extensive guidance, performs data analysis to ensure the quality (conformity, consistency, completeness, accuracy, and timeliness) of financial data, banking structure data, survey data, contextual information data, and business data used for monetary, supervisory, research, and organizational decision-making purposes.

· Participates in providing data support services to end users, which includes data quality assurance activities (conformity, consistency, completeness, accuracy, and timeliness) and troubleshooting and researching datarelated questions. Participates in relevant internal task forces and committees that impact data management support.

· Shadows more senior staff to learn how to develop business requirements and report requirements for programmers to use in developing applications or automated programs to support analytical work, collect and make data accessible, and allow for the release of public information. With extensive guidance, ensures key security, regulatory, and policy requirements are adhered to with own work.

· Applies foundational level knowledge of the Board’s statistics requirements to ensure Reserve Banks’ adherence to policies, procedures, and best practices of data management services and status reporting. Participates in projects to establish or strengthen the data management program, data governance framework, methodologies, and data quality program.

· Shadows more senior staff to learn how to conduct product owner tasks such as monitoring product schedules and keeping stakeholders informed on the development and maintenance of systems, tools and platforms supporting operational capabilities.

· Shadows more senior staff to learn how to document test cases and identify issues in systems used to facilitate data management work.

· Supports gathering and analyzing data on the current business architecture and processes to identify root causes of issues, trends, patterns, and opportunities that impact the business line and stakeholders; reviews existing business processes and establishes metrics to improve processes.

· Conducts research on reporting requirements and guidance based on foundational knowledge of financial markets and institutions, and regulatory/monetary/structure data reporting for use by Board, Reserve Bank staff, and reporting institutions.

· Participates in developing metrics (e.g., on services, staff utilization, and performance) and creating documentation (e.g., strategic plan, policies, procedures, reports, charters, evaluations) for the national Statistics business line.

FR – 23 Minimum Qualifications:

Requires a bachelor’s degree in business, economics, finance, mathematics, computer science, information technology, or related field and one year of experience. Must have novice to foundational knowledge in the following areas: systems automation, project coordination, financial analysis, data flow management, data collection, consulting, business process improvement, risk management, technical writing, technical communication, presentation skills, and administration. Must be able to work effectively with more senior staff. Must be able to support more senior staff with one or more of the following: data analysis; conducting research in areas relevant to division or Board needs; and/or developing and implementing data collection and analysis tools.

FR – 24 Minimum Qualifications:

Requires a bachelor’s degree in business, economics, finance, mathematics, computer science, information technology, or related field and three years of experience. Must have foundational to intermediate knowledge in the following areas: systems automation, project coordination, financial analysis, data flow management, data collection, consulting, business process improvement, risk management, technical writing, technical communication, presentation skills, and administration. Must be able to work effectively with more senior staff. Must be able to support more senior staff with one or more of the following: data analysis; conducting research in areas relevant to division or Board needs; and/or developing and implementing data collection and analysis tools.

FR – 25 Minimum Qualifications:

Requires a bachelor’s degree in business, economics, finance, mathematics, computer science, information technology, or related field and four years of experience. Must have intermediate knowledge in the following areas: systems automation, project coordination, financial analysis, data flow management, data collection, consulting, business process improvement, risk management, technical writing, technical communication, presentation skills, and administration. Must be able to work effectively with more senior staff. Must be able to assist more senior staff with one or more of the following: data analysis; conducting research in areas relevant to division or Board needs; and/or developing and implementing data collection and analysis tools.

This position is for the Statistics Function Management Office within Board IT Statistics whose main responsibility is supporting the national Statistics Function- a business line that collects financial, banking structure, survey, and business data and provides data management services to ensure information is fit for use. New employees may participate in a local Board IT Statistics rotation program that would provide the employee an in-depth engagement with all Board IT Statistics units to develop their knowledge and expertise of the Statistics business line. A new employee’s exposure and engagement within Board IT Statistics would ensure a thorough knowledge and understanding of Board Statistics’ processes and procedures for providing services to stakeholders, performing program management support, and directing the national business line.

The Statistics Function Management Office (FMO) provides oversight and support for the function’s communications, governance, strategic initiatives, engagement models, and resource and demand management frameworks. The Statistics Data Management Analyst will be responsible for a wide range of business analysis activities, and must have exceptional critical thinking and problem-solving skills, and a strong ability to develop actionable plans and processes to address complex problems. Strong oral and written communication skills, interpersonal skills, and the ability to prepare professional and effective deliverables tailored for staff at all levels is required. The ability to make sound decisions, communicate effectively and exhibit good judgment even under high pressure or difficult situations is also required.

Demonstrated experience in strategic planning or strategy execution, project management, program management, risk management, data management and/or communications is strongly preferred. Experience creating data visualizations and developing tools and processes to manage data sets is preferred.

This position is hybrid, requiring a combination of telework and in-office presence in Washington, DC.

Duties and Responsibilities

· Leads and/or participates in implementing cybersecurity tools such as firewalls, proxies, intrusion detection, intrusion prevention, endpoint protection, and data analysis platforms as part of an integrated defense in depth solution with a central security information and event management (SIEM) system and security orchestration tools. Leads technical and analytical assessments to support information security engineering decisions to ensure Board information and systems are adequately protected. Ability to characterize and manage moderately complex risks to mitigate cyber threats.

· With some guidance, proactively supports analysis of threat intelligence from a variety of sources to understand the nature of the threat, extract the information that informs threat hunt operations, and uses that information to investigate Board IT assets for evidence of an intrusion or compromise.

· With some guidance, emulates threat actor tactics, techniques, and procedures in a controlled and/or production environment to demonstrate and observe the technical aspects of the emulated activity. Leads and/or develops adequate detection strategies and develops mitigations as needed to address the specific details of the threat.

· Leads the development of programs that apply statistical models, mathematical principles, and other analytic tradecraft to a variety of IT network-generated data for the purposes of identifying anomalous activity, suspicious network activity, and ultimately leads to the discovery of intrusions and/or compromises.

· With some guidance, identifies and analyzes system-generated logs and capture forensic images of a variety of systems for the purposes of fully analyzing a cybersecurity intrusion and/or compromise. Includes use of advanced knowledge to perform root cause analysis and develop timelines to show the actions taken by a cyber threat actor in an environment. Leads the completion of all phases of the incident response process including identification, containment, eradication, and remediation.

· Leads implementation of vulnerability scans and ensures operational systems are adequately patched to protect the Board from potential cyber threat actors. Leads the analysis of vulnerabilities and proof of concept code as it becomes available to assess the technical implications of a given threat and ensure that the Board’s defenses are sufficient. Maintains advanced knowledge of ethical hacking principles to apply the skills to the management of vulnerabilities and mitigation of technical risk. Ensures that vulnerabilities are managed and patched according to Board policies and procedures.

· Leads the development of and/or develops data analytic software and cybersecurity scripts using a variety of programming and scripting languages to enable cybersecurity activities designed to defend the Board’s IT assets. With limited guidance, develops programs, software, and scripts that automate the cybersecurity process. With limited guidance, develops data queries and scheduled jobs designed to correlate data for further analysis. With limited guidance, integrates tools and systems for advanced analysis of relevant data.

· With moderate guidance, manages cybersecurity projects focused on developing and instrumenting moderately complex approaches to detect, prevent, and respond to cybersecurity intrusions and/or compromises. Authors documents and oversees the execution of project plans, schedules, requirements, risks, assumptions, cost, performance, and resource utilization with minimal supervision.

Position Requirements

FR-26 Minimal Qualifications

Requires a bachelor’s degree in computer science, information technology, cybersecurity or a related business technology field and five years of experience. Must have advanced knowledge in in at least one of the following areas: general cybersecurity fundamentals, cyber threat analysis, data science principles, digital forensics, incident handling, incident management, incident response, vulnerability management, security engineering, automation and programming, project management, and relevant technologies and programming languages. Must be able to work effectively with staff. Must be familiar with relevant policies, procedures, and be able to work with TOP SECRET / SENSITIVE COMPARTMENTED INFORMATION. Must be able to support one or more of the following: providing threat assessments, recommending cybersecurity technologies for intrusion detection and prevention, assessing technical vulnerabilities, identifying automation opportunities, investigating, and resolving security breaches, technical writing, and communication.

FR-27 Minimal Qualifications

Requires a bachelor’s degree in computer science, information technology, cybersecurity or a related business technology field and six years of experience. Must have expert knowledge in the in at least one of the following areas: general cybersecurity fundamentals, cyber threat analysis, data science principles, digital forensics, incident handling, incident management, incident response, vulnerability management, security engineering, automation and programming, project management, and relevant technologies and programming languages. Must be able to work effectively with staff. Must be familiar with relevant policies, procedures, and be able to work with TOP SECRET / SENSITIVE COMPARTMENTED INFORMATION. Must be able to lead one or more of the following: providing threat assessments, recommending cybersecurity technologies for intrusion detection and prevention, assessing technical vulnerabilities, identifying automation opportunities, investigating, and resolving security breaches, technical writing, and communication.

FR-28 Minimal Qualifications

Requires a bachelor’s degree in computer science, information technology, cybersecurity or a related business technology field and eight years of experience. Must have expert knowledge in the in at least one of the following areas: general cybersecurity fundamentals, cyber threat analysis, data science principles, digital forensics, incident handling, incident management, incident response, vulnerability management, security engineering, automation and programming, project management, and relevant technologies and programming languages. Must be able to work effectively with staff. Must be familiar with relevant policies, procedures, and be able to work with TOP SECRET / SENSITIVE COMPARTMENTED INFORMATION. Must be able to direct one or more of the following: providing threat assessments, recommending cybersecurity technologies for intrusion detection and prevention, assessing technical vulnerabilities, identifying automation opportunities, investigating, and resolving security breaches, technical writing, and communication.

Remarks: The Sr. Vulnerability Analyst (Sr. Cybersecurity Analyst) is an individual contributor position responsible for leading the enterprise vulnerability management program for the Board. The Sr. Vulnerability Analyst (Sr. Cybersecurity Analyst) possesses knowledge of policies and best practices pertinent to vulnerability management and has the ability to operationalize that information in the form of organizational governance and technical process (NIST, DHS/CISA, OWASP, NVD, SEI, etc.). The Sr. Vulnerability Analyst (Sr. Cybersecurity Analyst) consumes cyber threat intelligence that describes new and emerging vulnerabilities and translates that information into active defense and preventive measures. The Sr. Vulnerability Analyst (Sr. Cybersecurity Analyst) analyzes systems for potential weaknesses and/or vulnerabilities and proposes solutions to mitigate those risks. The Sr. Vulnerability Analyst (Sr. Cybersecurity Analyst) establishes and oversees patch management operations for all kinds of assets in the environment and designs mitigations where patching is impractical or impossible. The Sr. Vulnerability Analyst (Sr. Cybersecurity Analyst) establishes and implements a risk management approach for vulnerabilities including thresholds, mitigations, and risk tolerances that drives other vulnerability response actions. The Sr. Vulnerability Analyst (Sr. Cybersecurity Analyst) provides services including static and dynamic application security testing, web application vulnerability scanning, vulnerability analysis, enterprise patch management, and proposing mitigations for specific threats. The Sr. Vulnerability Analyst (Sr. Cybersecurity Analyst) develops technical products and presents highly technical subjects to a variety of audiences ranging from non-technical senior leaders to highly technical subject matter experts. The Sr. Vulnerability Analyst (Sr. Cybersecurity Analyst) collaborates with other vulnerability management professionals in the Federal space and throughout the Federal Reserve System to develop and implement cybersecurity solutions that enable vulnerability management activities. The Sr. Vulnerability Analyst (Sr. Cybersecurity Analyst) provides technical and analytical vulnerability assessments to support information security engineering decisions to ensure Board information and systems are adequately protected.

Highly Desirable:

· At least 5-7 years of full-time experience supporting a vulnerability management program.

· Experience applying industry standards and best practices in an operational environment to adequately manage risk and mitigate vulnerabilities as part of an enterprise service.

· Experience with a variety of vulnerability and patch management technologies including, but not limited to, Qualys, Tenable, Nessus, Invicti, Fortify, CrowdStrike Falcon Spotlight, Microsoft Defender Vulnerability Management, etc.

· Experience applying expert knowledge of adversary tactics, techniques, and procedures to identify, prioritize, and ultimately respond to vulnerabilities identified within the Board’s enterprise network.

· Experience mentoring less experienced team members in vulnerability management and response activities.

· Experience in vulnerability analysis, threat modeling, and designing mitigation and remediation strategies.

· Experience managing vulnerabilities in on-premises systems, mobile devices, and in cloud environments, (e.g. Amazon Web Services, Microsoft Azure, Google Cloud, and Data Centers).

· Experience developing programs and/or automated tools using a programming / scripting languages (e.g. Python, PowerShell, etc.).

· Familiarity with relevant policies, procedures, and be able to work with TOP SECRET / SENSITIVE COMPARTMENTED INFORMATION.

· Demonstrated resourcefulness and advanced critical thinking skills to independently direct, analyze, and implement solutions for all the various complex problems that arise in the administrative and operations area.

· Expert technical writing and communications skills. Contacts are often with division leadership, but also with staff at all levels; a significant degree of coordination and contact with other units/sections/divisions may also be required.

· Ability to construct clear and concise written work and applies an increasingly advanced understanding of grammar, sentence structure, and intended audience(s) to the process of writing and editing such work.

· Ability to explain to cross-team or cross-divisional partners items of high levels of complexity.

· Possess skills in negotiation and persuasion in performing duties and influencing support for change.

This position is hybrid, requiring a combination of telework and in-office presence in Washington, DC with the option for full remote.

Confirm your E-mail: Send Email