Skip to content
← Back to job listings

Exposure Management Senior Advisor

05E Federal Reserve Bank of Richmond · Richmond, VA, United States

IT - Network / Systems / DB AdminExternal listingfull-timeabout 2 hours ago

About The Role

Federal Reserve Bank of Richmond

When you join the Federal Reserve—the nation's central bank—you’ll play a key role, collaborating with leading tech professionals to strengthen and protect our economic, financial and payments systems. We invest in contemporary and emerging technology each year to support the Federal Reserve and our economy, and we’re building a dynamic and diverse team for our future.

The Information Security & Policy portfolio collaborates with business areas to address current and future cybersecurity threats across the enterprise, enforce SAFR and security policy, provide strategic and cost-effective services to its stakeholders, and protect the availability, confidentiality and integrity of Federal Reserve assets.

The selected candidate will reside within a reasonable commuting distance, as defined by the employing Reserve Bank, and will work full-time onsite.

Eligible Locations for Hire: Boston, MA- New York, NY- Philadelphia, PA- Cleveland, OH- Richmond, VA- Atlanta, GA- Chicago, IL- St. Louis, MO- Minneapolis, MN- Kansas City, MO- Dallas, TX- San Francisco, CA

The Exposure Management Senior Advisor is responsible for continuously identifying, assessing, validating, and reducing the organization’s cyber exposures across on ‑ premises, cloud, and hybrid environments. This role integrates attack surface discovery, vulnerability insights, misconfiguration analysis, identity exposure review, and business context to provide a unified view of cyber risk. Working closely with the Product Manager, this role translates program strategy and user needs into actionable features, configurations, integrations, and workflows that enable the Exposure Management program.

Key Responsibilities

Platform Operations & Service Delivery

  • Own the day-to-day operation and health of the Exposure Management SaaS platform, ensuring uptime, performance, and user access.
  • Manage platform configurations, user roles, integrations, data feeds, and API connections to support continuous exposure visibility.
  • Coordinate with vendors and internal IT teams to resolve technical issues, deploy updates, and maintain platform stability.
  • Ensure the platform scales to support evolving environments (cloud, identity, SaaS, on-premises).

Data Integration & Workflow Optimization

  • Coordinate integration of exposure data sources including vulnerability scanners, cloud security posture management (CSPM), cloud infrastructure entitlement management (CIEM), external attack surface management (EASM), asset inventories, and threat intelligence feeds.
  • Design and optimize workflows for exposure discovery, risk scoring, validation, remediation assignment, and tracking to align with Exposure Management cycles.

Exposure Identification & Risk Analysis

  • Discover, map, and inventory external and internal attack surfaces across cloud, on premise, network, application, and SaaS environments.
  • Identify unknown, shadow, misconfigured, or abandoned assets that contribute to the organization’s exposure.
  • Monitor asset changes and ensure continuous visibility into evolving environments .
  • Evaluate exposure severity using exploitability, threat intelligence, asset criticality, and potential business impact.
  • Produce risk ratings and exposure narratives that business units can understand and act on.

Program Enablement & Governance

  • Contribute to scoping CTEM cycles and defining focus areas (e.g., cloud posture, identity exposures, internet-facing risks).
  • Maintain standards, processes, and documentation related to exposure management activities.
  • Provide clear metrics and reporting to leadership on exposure trends, risk posture, and remediation progress.
  • Support integration of exposure management into broader security architecture and operational security processes.

Vendor & Stakeholder Management

  • Serve as a l iaison with the SaaS platform vendor, managing support escalations, feature requests, and roadmap discussions.
  • Represent organizational needs and use cases in vendor product development conversations.
  • Collaborate with business and IT stakeholders to ensure platform configurations meet business, security, and governance requirements.
  • Work with procurement and finance teams to manage licensing, usage optimization, and budget planning.

Required Skills & Qualifications

  • Strong understanding of Exposure Management concepts including attack surface management, exposure prioritization, cloud security posture, identity risk, and Exposure Management principles.
  • Experience with CTEM-aligned workflows or continuous risk-reduction programs.
  • Ability to analyze complex exposure data and translate it into actionable risk insights.
  • Experience with exposure, vulnerability, or ASM tooling (e.g., ASM platforms, CSPM, CIEM, VM scanners, EASM tools, attack path analysis).
  • Experience managing SaaS platforms, including integrations, APIs, data pipelines, and vendor relationships.
  • Strong communication and stakeholder management skills with ability to work across technical and business teams.

Salary

  • 136,600.00 - 222,000.00

*The listed salary is applicable to 5th District (Richmond). Final offers are determined by factors including the candidate’s qualifications, internal alignment considerations, district assignment, and geographic location.

Full Time / Part Time

Full time

Regular / Temporary

Regular

Job Exempt (Yes / No)

Yes

Job Category

Information Technology Family Group

Work Shift

First (United States of America)

The Federal Reserve Banks are committed to equal employment opportunity for employees and job applicants in compliance with applicable law and to an environment where employees are valued for their differences.

Always verify and apply to jobs on Federal Reserve System Careers ( https://rb.wd5.myworkdayjobs.com/FRS )

This is an external listing. JobSpring does not represent or verify the employer. Report this listing