Federal Reserve Bank of Richmond
When you join the Federal Reserve-the nation's central bank-you'll play a key role, collaborating with leading tech professionals to strengthen and protect our economic, financial and payments systems. We invest in contemporary and emerging technology each year to support the Federal Reserve and our economy, and we're building a dynamic and diverse team for our future.
The Information Security & Policy portfolio collaborates with business areas to address current and future cybersecurity threats across the enterprise, enforce SAFR and security policy, provide strategic and cost-effective services to its stakeholders, and protect the availability, confidentiality and integrity of Federal Reserve assets.
The selected candidate will reside within a reasonable commuting distance, as defined by the employing Reserve Bank, and will work full-time onsite.
Eligible Locations for Hire: Boston, MA- New York, NY- Philadelphia, PA- Cleveland, OH- Richmond, VA- Atlanta, GA- Chicago, IL- St. Louis, MO- Minneapolis, MN- Kansas City, MO- Dallas, TX- San Francisco, CA
The Exposure Management Senior Advisor is responsible for continuously identifying, assessing, validating, and reducing the organization's cyber exposures across on-premises, cloud, and hybrid environments. This role integrates attack surface discovery, vulnerability insights, misconfiguration analysis, identity exposure review, and business context to provide a unified view of cyber risk. Working closely with the Product Manager, this role translates program strategy and user needs into actionable features, configurations, integrations, and workflows that enable the Exposure Management program.
Key Responsibilities
Platform Operations & Service Delivery
- Own the day-to-day operation and health of the Exposure Management SaaS platform, ensuring uptime, performance, and user access.
- Manage platform configurations, user roles, integrations, data feeds, and API connections to support continuous exposure visibility.
- Coordinate with vendors and internal IT teams to resolve technical issues, deploy updates, and maintain platform stability.
- Ensure the platform scales to support evolving environments (cloud, identity, SaaS, on-premises).
Data Integration & Workflow Optimization
- Coordinate integration of exposure data sources including vulnerability scanners, cloud security posture management (CSPM), cloud infrastructure entitlement management (CIEM), external attack surface management (EASM), asset inventories, and threat intelligence feeds.
- Design and optimize workflows for exposure discovery, risk scoring, validation, remediation assignment, and tracking to align with Exposure Management cycles.
Exposure Identification & Risk Analysis
- Discover, map, and inventory external and internal attack surfaces across cloud, on premise, network, application, and SaaS environments.
- Identify unknown, shadow, misconfigured, or abandoned assets that contribute to the organization's exposure.
- Monitor asset changes and ensure continuous visibility into evolving environments.
- Evaluate exposure severity using exploitability, threat intelligence, asset criticality, and potential business impact.
- Produce risk ratings and exposure narratives that business units can understand and act on.
Program Enablement & Governance
- Contribute to scoping CTEM cycles and defining focus areas (e.g., cloud posture, identity exposures, internet-facing risks).
- Maintain standards, processes, and documentation related to exposure management activities.
- Provide clear metrics and reporting to leadership on exposure trends, risk posture, and remediation progress.
- Support integration of exposure management into broader security architecture and operational security processes.
Vendor & Stakeholder Management
- Serve as a liaison with the SaaS platform vendor, managing support escalations, feature requests, and roadmap discussions.
- Represent organizational needs and use cases in vendor product development conversations.
- Collaborate with business and IT stakeholders to ensure platform configurations meet business, security, and governance requirements.
- Work with procurement and finance teams to manage licensing, usage optimization, and budget planning.
Required Skills & Qualifications
- Strong understanding of Exposure Management concepts including attack surface management, exposure prioritization, cloud security posture, identity risk, and Exposure Management principles.
- Experience with CTEM-aligned workflows or continuous risk-reduction programs.
- Ability to analyze complex exposure data and translate it into actionable risk insights.
- Experience with exposure, vulnerability, or ASM tooling (e.g., ASM platforms, CSPM, CIEM, VM scanners, EASM tools, attack path analysis).
- Experience managing SaaS platforms, including integrations, APIs, data pipelines, and vendor relationships.
- Strong communication and stakeholder management skills with ability to work across technical and business teams.
Salary:
- 136,600.00 - 222,000.00
*The listed salary is applicable to 5th District (Richmond). Final offers are determined by factors including the candidate's qualifications, internal alignment considerations, district assignment, and geographic location.
Full Time / Part Time
Full time
Regular / Temporary
Regular
Job Exempt (Yes / No)
Yes
Job Category
Information Technology Family Group
Work Shift
First (United States of America)
The Federal Reserve Banks are committed to equal employment opportunity for employees and job applicants in compliance with applicable law and to an environment where employees are valued for their differences.
Always verify and apply to jobs on Federal Reserve System Careers (https://rb.wd5.myworkdayjobs.com/FRS) or through verified Federal Reserve Bank social media channels.
Privacy Notice
Skills Required
- Strong understanding of Exposure Management, attack surface management, exposure prioritization, cloud security posture, identity risk, and related principles.
- Experience with CTEM-aligned workflows or continuous risk-reduction programs.
- Ability to analyze complex exposure data and translate it into actionable risk insights.
- Experience with exposure, vulnerability, or attack surface management tooling, including ASM platforms, CSPM, CIEM, vulnerability scanners, EASM tools, or attack path analysis.
- Experience managing SaaS platforms, including integrations, APIs, data pipelines, and vendor relationships.
- Strong communication and stakeholder management skills across technical and business teams.
Federal Reserve Bank of Boston Compensation & Benefits Highlights
-
Retirement Support — Official materials highlight a defined-benefit pension alongside a 401(k)-style Thrift Plan with employer contributions, and feedback suggests this combination is a standout strength over many private employers. The presence of both plans is repeatedly emphasized as a significant component of total compensation.
-
Healthcare Strength — Health coverage is described as broad—covering medical, dental, vision, and prescriptions—with FSA/HSA options and an employee assistance program. Feedback suggests the overall health offering is a notable positive of the package.
-
Leave & Time Off Breadth — Paid vacation, holidays, parental leave, family leave, and sick time are prominently advertised. Feedback suggests these work-life supports contribute meaningfully to overall satisfaction with the package.
Federal Reserve Bank of Boston Insights
What We Do
As part of the Central bank of the United States, the Boston Fed works to promote sound growth and financial stability in New England and the nation. We contribute to communities, the region, and the nation by conducting economic research, participating in monetary policy-making, supervising certain financial institutions, providing financial services and payments, playing a leadership role in the payments industry, and supporting economic well-being in communities through a variety of efforts.
Why Work With Us
At the Boston Fed, we strive to ensure that rigorous thinking and wide-ranging perspectives characterize our work and workplace. We also recognize that benefits and compensation play a central role in the employer you choose. We work to make sure our compensation package is competitive with those of top employers.
Gallery
Federal Reserve Bank of Boston Offices
OnSite Workspace
Positions are primarily in person, although some positions will allow employment based out of one of our twelve Banks nation-wide. Please see position description for specific location requirements.
















