Cyber Security Engineer Principal
Listed on 2026-07-27
-
IT/Tech
Cybersecurity
Cyber Security Engineer – Principal
Location:
Boston, MA, US
Company:
Federal Reserve Bank of Boston / Federal Reserve Financial Services (FRFS). FRFS delivers a suite of payments services to financial institutions, including Fed Line, Fedwire Funds and Securities, the National Settlement Service, Fed Cash, FedACH, Check Services, and the Fed Now Service. FRFS operates as a fully integrated organization with dedicated teams for customer experience, operations, technology, product, enterprise services, and payments system improvement.
This on‑site role ensures the security and integrity of the Fed Now organization across people, operations, and technology. The incumbent will directly support security engineering and operations, providing cybersecurity expertise through consultation and hands‑on technical activities.
Responsibilities- Develop code to automate security frameworks into functional infrastructure and deploy security tooling using automation.
- Design and execute point‑in‑time security tests, automated or manual, against cloud workloads.
- Integrate Dev Sec Ops , enabling automated static and dynamic API security checks in CI/CD pipelines.
- Enforce governance gates during key lifecycle phases (design, validate, publish).
- Partner with application, security, and platform teams to embed security into API design, development, and deployment.
- Contribute to security architecture reviews, threat modeling, and technical design discussions.
- Define, configure, and enforce API gateway policies for authentication, authorization, encryption, and traffic‑management controls.
- Monitor traffic and collaborate with security and engineering teams on incident response and remediation.
- Represent a technologist’s point of view in selecting tooling and solutions.
- Present and debrief cybersecurity findings, risk posture, and control effectiveness to leadership, translating technical data into actionable insights.
- Document technical solutions and supporting processes.
- Identify and address root causes of issues, focusing on solving problem categories rather than individual instances.
- Engage early and comprehensively to remove barriers and improve security across the program.
- 5+ years experience in an object‑oriented language (Python, Java, or Go).
- Experience working in a Dev Sec Ops software development environment.
- 5+ years in cyber security, focusing on API gateway engineering.
- 5+ years of Cloud Native experience (AWS preferred).
- Strong understanding of API security, OWASP API Top 10, and secure API design principles.
- Exposure to API gateway security tools (runtime protection, discovery, posture management).
- Proficiency with Infrastructure as Code (Terraform, Pulumi).
- Experience building and securing CI/CD pipelines (Git Hub, Git Lab CI, Jenkins).
- Proficiency with container technologies (Docker, Kubernetes) and their security implications.
- Expertise in Cloud IAM configuration and policies, container orchestration, and testing.
- Lead and execute cyber incident response activities, including detection, analysis, containment, eradication, and recovery.
- Strong communication skills and ability to influence at all levels.
- Relevant certifications (CISSP, CISM, GIAC, AWS, AZURE) are a plus.
- Ability to obtain a security clearance.
- Support on‑call and work‑rotation activities.
- Full‑time, in‑office at the Boston Fed.
- Salary range: $170,200 – $252,700 (depending on background, skills, and market data).
The Federal Reserve System is committed to a diverse and inclusive workplace and provides equal employment opportunities to all persons without regard to race, color, religion, national origin, sex, sexual orientation, gender identity, age, genetic information, disability, or military service. All employees assigned to this position will be subject to FBI fingerprint/ criminal background and Patriot Act/Office of Foreign Assets Control (OFAC) watch‑list checks at least once every five years.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).