The Information Security & Policy portfolio collaborates with business areas to address current and future cybersecurity threats across the enterprise, enforce SAFR and security policy, provide strategic and cost-effective services to its stakeholders, and protect the availability, confidentiality and integrity of Federal Reserve assets.
The selected candidate will reside within a reasonable commuting distance, as defined by the employing Reserve Bank, and will work full-time onsite.
Eligible Locations for Hire: Boston, MA- New York, NY- Philadelphia, PA- Cleveland, OH- Richmond, VA- Atlanta, GA- Chicago, IL- St. Louis, MO- Minneapolis, MN- Kansas City, MO- Dallas, TX- San Francisco, CA
The Exposure Management Senior Advisor is responsible for continuously identifying, assessing, validating, and reducing the organization’s cyber exposures across on‑premises, cloud, and hybrid environments. This role integrates attack surface discovery, vulnerability insights, misconfiguration analysis, identity exposure review, and business context to provide a unified view of cyber risk. Working closely with the Product Manager, this role translates program strategy and user needs into actionable features, configurations, integrations, and workflows that enable the Exposure Management program.
Key Responsibilities
Platform Operations & Service Delivery
Own the day-to-day operation and health of the Exposure Management SaaS platform, ensuring uptime, performance, and user access.
Manage platform configurations, user roles, integrations, data feeds, and API connections to support continuous exposure visibility.
Coordinate with vendors and internal IT teams to resolve technical issues, deploy updates, and maintain platform stability.
Ensure the platform scales to support evolving environments (cloud, identity, SaaS, on-premises).
Data Integration & Workflow Optimization
Coordinate integration of exposure data sources including vulnerability scanners, cloud security posture management (CSPM), cloud infrastructure entitlement management (CIEM), external attack surface management (EASM), asset inventories, and threat intelligence feeds.
Design and optimize workflows for exposure discovery, risk scoring, validation, remediation assignment, and tracking to align with Exposure Management cycles.
Exposure Identification & Risk Analysis
Discover, map, and inventory external and internal attack surfaces across cloud, on premise, network, application, and SaaS environments.
Identify unknown, shadow, misconfigured, or abandoned assets that contribute to the organization’s exposure.
Monitor asset changes and ensure continuous visibility into evolving environments.
Evaluate exposure severity using exploitability, threat intelligence, asset criticality, and potential business impact.
Produce risk ratings and exposure narratives that business units can understand and act on.
Program Enablement & Governance
Contribute to scoping CTEM cycles and defining focus areas (e.g., cloud posture, identity exposures, internet-facing risks).
Maintain standards, processes, and documentation related to exposure management activities.
Provide clear metrics and reporting to leadership on exposure trends, risk posture, and remediation progress.
Support integration of exposure management into broader security architecture and operational security processes.
Vendor & Stakeholder Management
Serve as a liaison with the SaaS platform vendor, managing support escalations, feature requests, and roadmap discussions.
Represent organizational needs and use cases in vendor product development conversations.
Collaborate with business and IT stakeholders to ensure platform configurations meet business, security, and governance requirements.
Work with procurement and finance teams to manage licensing, usage optimization, and budget planning.
Required Skills & Qualifications
Strong understanding of Exposure Management concepts including attack surface management, exposure prioritization, cloud security posture, identity risk, and Exposure Management principles.
Experience with CTEM-aligned workflows or continuous risk-reduction programs.
Ability to analyze complex exposure data and translate it into actionable risk insights.
Experience with exposure, vulnerability, or ASM tooling (e.g., ASM platforms, CSPM, CIEM, VM scanners, EASM tools, attack path analysis).
Experience managing SaaS platforms, including integrations, APIs, data pipelines, and vendor relationships.
Strong communication and stakeholder management skills with ability to work across technical and business teams.
Salary:
- 136,600.00 - 222,000.00
*The listed salary is applicable to 5th District (Richmond). Final offers are determined by factors including the candidate’s qualifications, internal alignment considerations, district assignment, and geographic location.
The Federal Reserve Banks are committed to equal employment opportunity for employees and job applicants in compliance with applicable law and to an environment where employees are valued for their differences.
Always verify and apply to jobs on Federal Reserve System Careers (https://rb.wd5.myworkdayjobs.com/FRS) or through verified Federal Reserve Bank social media channels.
Privacy Notice
Similar Jobs
What you need to know about the San Francisco Tech Scene
Key Facts About San Francisco Tech
- Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Google, Apple, Salesforce, Meta
- Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
- Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
- Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine
