Vice President - Product and Platform Security
About the role
Company Federal Reserve Bank of Chicago For external candidates, this role will be hired only in Chicago, Kansas City, or New York. Candidates must reside within a reasonable commuting distance of one of these Reserve Bank locations. When you join the Federal Reserve—the nation's central bank—you’ll play a key role, collaborating with leading tech professionals to strengthen and protect our economic, financial and payments systems.
We invest in contemporary and emerging technology each year to support the Federal Reserve and our economy, and we’re building a dynamic and diverse team for our future. The Federal Reserve Financial Services portfolio provides technology capabilities that power the U.S. payment systems infrastructure. This portfolio enables critical payment services that are foundational to the nation's financial system, focusing on delivering speed, resilience, and choice to meet evolving marketplace needs.
The Vice President of Product and Platform Security is a strategic leadership role responsible for establishing and overseeing the security architecture and engineering for all Federal Reserve Financial Services (FRFS) products and platforms. This role requires a unique combination of deep technical security expertise and strategic leadership capabilities to ensure FRFS products are designed, developed, and operated with security as a foundational element. The VP will lead a team who embeds security throughout the product’s lifecycle from concept through retirement.
This position serves as the primary security advisor for FRFS product and platform initiatives, partnering closely with product managers, product owners, software engineering, solutions architecture, and business stakeholders to balance security requirements with operational needs and innovation. The VP must be an influential communicator who can operate at both strategic and technical levels, articulating security concepts to diverse audiences while maintaining sufficient technical depth to evaluate complex security architectures, threat models, and risk scenarios.
Your Responsibilities Develop and maintain comprehensive security architecture for all FRFS products and platforms, ensuring compliance with Federal Reserve System (FRS) security standards and effective risk mitigation Oversee secure reference architectures, design patterns, and technical standards for FRFS products; ensure security architecture reviews for all new products, major enhancements, and technology changes Establish and mature secure software development lifecycle (SSDLC) practices, integrating threat modeling and secure coding into Agile/DevSecOps workflows Guide evaluation and
adoption of security technologies, tools, and controls; drive DevSecOps practices, security automation, and shift-left security principles across product teams, partnering with System IT colleagues to implement Frontier AI where appropriate Identify, assess, and communicate security risks to stakeholders in collaboration with the FRFS Cyber Strategy, Risk, Resiliency Department to facilitate risk-based decisions on security controls, risk acceptance, and compliance requirements Lead, mentor, and develop the Product and Platform Security team, fostering a culture of excellence, collaboration,
and continuous learning while ensuring appropriate resource allocation Build and maintain strong partnerships with FRFS product management, software engineering, architecture, and operations teams, serving as a trusted security advisor; establish similar relationships with System IT partners such as Architecture of the Enterprise Provide strategic security guidance for FRFS product roadmaps, architecture decisions, and technology investments; partner with senior leadership on strategic planning Represent FRFS product and platform security interests in Federal Reserve System forums,
committees, and working groups Your Background Bachelor's degree in Computer Science, Information Security, Engineering, or related technical field required; Master's degree and professional security certifications (CISSP, CSSLP, CEH, GIAC) preferred, or equivalent experience.
10+ years of progressive experience in information security with at least 5 years in application/product security or secure development; 5+ years leading security teams in large, complex organizations (preferably financial services, government, or highly regulated industries) Deep technical understanding of application security principles, secure design patterns, NIST frameworks and standards, SSDLC practices, DevSecOps methodologies, threat modeling, security testing approaches (SAST, DAST, IAST, SCA, penetration testing), and common vulnerability classes Strong knowledge of modern
application architectures (microservices, APIs, containers, cloud-native), cloud security (AWS, Azure, GCP), security frameworks and standards, and cryptography/authentication protocols Technical acumen to evaluate complex security architectures while maintaining strategic perspective on business objectives and risk management Ability to translate business objectives into security strategies, influence change without direct authority, and navigate complex organizational dynamics Exceptional communication and presentation skills with ability to explain complex technical security concepts to
diverse audiences from developers to executive leadership, facilitating discussions that balance security requirements with business needs and user experience Ability to manage competing priorities, adapt to ambiguity and changing requirements, and drive initiatives to completion while balancing security rigor with practical implementation Willingness to travel occasionally (10-15%); commitment to staying current with evolving threats, technologies, and security practice Ability to obtain and maintain national security clearance; must be able to complete a favorably adjudicated enhanced
background screening What we Offer Comprehensive benefits package includes medical, dental, vision, prescription drug coverage, 401k savings plan, retirement plan, paid time off, transit benefit, onsite gym and subsidized cafeteria A learning environment with opportunities to gain new skills and grow your career Additional Information Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future. This position has additional screening requirements due to the information accessed while performing the job.
These additional screenings would be initiated at the time of offer acceptance and can take approximately two months to be completed. The screening covers areas such as education/employment verification, criminal history, credit history, and reaches out to your references and people that know you well.
As a condition of employment, Federal Reserve Bank of Chicago employees must comply with the Bank’s ethics rules, which generally prohibit employees, their spouses/domestic partners, and minor children from owning securities, such as stock, of banks or savings associations or their affiliates, such as bank holding companies and savings and loan holding companies.
If you or your spouse/domestic partner or minor child own such securities and would not be willing or able to divest them if you accepted an offer of Bank employment, you should raise this issue with the recruiter for this posting, who can provide you contact information for our ethics official if necessary. The expected starting salary range for this position is between $308,700 and $365,100 annually in addition to annual performance-based discretionary bonuses.
Final salary and offer will be determined based on the applicant’s home bank, relevant experience, skills, internal equity, and alignment with geographic and other market data. The Chicago Fed offers benefits to support overall health and financial security. Learn more about our benefits here: https://www.chicagofed.org/careers/thebenefits We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender, gender identity or expression, or veteran status.
Full Time / Part Time Full time Regular / Temporary Regular Job Exempt (Yes / No) Yes Job Category Work Shift First (United States of America) The Federal Reserve Banks are committed to equal employment opportunity for employees and job applicants in compliance with applicable law and to an environment where employees are valued for their differences. Always verify and apply to jobs on Federal Reserve System Careers (https://rb.wd5.myworkdayjobs.com/FRS) or through verified Federal Reserve Bank social media channels.
Privacy Notice OUR BANK has one of the most recognizable brands around the world. The Federal Reserve is the central bank of the United States—one of the world's most influential, trusted and prestigious financial organizations. The Federal Reserve is charged with the important mission of promoting a strong economy and a stable financial system and fulfills this responsibility by formulating national monetary policy, supervising and regulating banks and bank holding companies, and providing financial services for banks and the U.S. government.
OUR PEOPLE are diverse in background and ideas, which allows for ongoing creativity and innovation. Ultimately, they are the ones who push our high-performance, exchange-driven culture forward. Why Our People Choose Us: Our reputation precedes us There will always be room for personal growth Our people are first You’ll find the right balance Your responsibilities will be meaningful We hope that you will be our future colleague. Always verify and apply to jobs on Federal Reserve System Careers or through verified Federal Reserve Bank social media channels.
Please check back later for more information on available job opportunities.
Minimum requirements
- Bachelor's degree in Computer Science, Information Security, Engineering, or related field; 10+ years in information security with 5+ years in application/product security and 5+ years leading security teams.
- Deep expertise in application security, SSDLC, DevSecOps, cloud security, and security frameworks; ability to evaluate complex security architectures.
- Authorized to work in the U.S. without visa sponsorship; ability to obtain and maintain national security clearance; reside near Chicago, Kansas City, or New York.
This listing was parsed by AI and may not be complete. Check the official posting on Federal Reserve Bank of Chicago's site for the most accurate information.