Information Security Analyst

Empeople Credit Union

• $75K — $113K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years in enterprise security document creation
  • Expertise in enterprise security architecture design
  • Hands-on experience with NIST-based Incident Handling
  • Knowledge of Firewalls, Intrusion Detection, LAN/WAN, Data Loss Prevention, and SIEM
  • Proficient with Vulnerability Management Tools like Nessus
  • Familiarity with command line utilities such as Nmap
  • Experience with cloud security, preferably Azure
  • Strong technical skills in Microsoft Windows Server, Active Directory, and Office Suite

Responsibilities

  • Review daily logs for security incidents and investigate anomalies
  • Process social engineering reports and communicate findings
  • Monitor and remediate security incidents in collaboration with the Incident Response Team
  • Conduct social engineering exercises and support remediation training
  • Administer the vulnerability management program and collaborate with IT on remediation
  • Oversee information security systems and tools
  • Contribute to security policies and implement the security strategy
  • Participate in Change Control Board to uphold security controls during system changes

Benefits

  • Comprehensive health, dental, and vision benefits
  • Bonus opportunities
  • 401(k) plan with match and profit sharing
  • Flexible time off for work-life balance
Full Job Description
OVERVIEW

The Information Security Analyst is responsible for contributing, implementing, and maintaining the credit union's cyber security program. Leveraging the required skills and experience, the Information Security Analyst will investigate and respond to security incidents, work closely with internal departments and/or third parties, and provide status updates to management.

QUALIFICATIONS

  • Experience in enterprise security document creation.
  • Experience in enterprise security architecture design.
  • Experience in NIST based Incident Handling
  • Working technical knowledge of Firewalls, Intrusion Detection, Networking technologies ( LAN / WAN ), Data Loss Prevention (DLP), Network Access Controls (NAC), Security Incident and Event Management Systems (SIEM), Email Security.
  • Vulnerability Management Tools (Nessus, Nexpose, Etc)
  • Command Line Utilities such as Nmap, netcat, etc.
  • Experience with security in cloud environments (Azure preferred) required.
  • Microsoft Windows Server, Active Directory, DNS and DHCP, etc.
  • Microsoft Windows 10 and later
  • Microsoft Office and Visio 2016 and later


Ability To:
  • Create and maintain detailed technical documentation
  • Proven analytical and problem-solving abilities.
  • Good written, oral, and interpersonal communication skills.
  • Ability to conduct research into IT security issues and products as required.
  • Ability to present ideas in business-friendly and user-friendly language.
  • Highly self-motivated and directed.
  • Team-oriented and skilled in working within a collaborative environment.


ESSENTIAL FUNCTIONS

  • Review daily log reports generated from information security systems and investigate anomalous behavior.
  • Process reported social engineering attempts to determine if a threat exists and communicate outcomes to involved parties.
  • Monitor, investigate, remediate, and report security incidents as they arise. Work with other members of the Incident Response Team, as needed.
  • Conduct social engineering exercises across the organization and assist with training remediation efforts.
  • Administer the organizations vulnerability management program to identify and prioritize vulnerabilities. Will also work closely with the Information Technology team and product owners to remediate discovered vulnerabilities.
  • Administer the credit union's information security systems and tools.
  • Contribute to the organizations security policies, procedures, and processes.
  • Implements the information security strategy and objectives, as approved by the Chief Information Security Officer, including strategies to monitor and address current and emerging risks.
  • Participates on the Change Control Board ensuring systems changes are made with appropriate Confidentiality, Availability, Integrity and Cyber Security design and controls
  • Participates in industry collaborative efforts to monitor, share, and discuss emerging security threats. Maintains up-to-date knowledge of the security industry including awareness of new or revised security solutions, improved security processes and the development of new attacks and threat vectors.
  • Contributes to the deployment, integration, and initial configuration of all new security solutions and of any enhancements to existing security solutions in accordance with standard best operating procedures generically and the enterprise's security documents specifically.
  • Champions security awareness and training programs.
    Participate in security NIST based incident response process including event handling, process reviews and tabletop exercises. Supervise all investigations into problematic activity and provide on-going communication and reports significant security events to the board, supervisory committee, and management as appropriate.
  • Responds to and complies with audit, regulatory, and credit union policies and procedures.
  • Monitor and respond to security related alerts during non-business hours.


REQUIRED EDUCATION AND EXPERIENCE

Education/Experience:
  • Bachelor's degree preferably in Information Systems or Computer Science
  • 3-5 years of relevant Information Technology or Information Security experience

License or Certification:
  • Security certifications such as Security+, CySA+, SSCP, etc.
  • Bondable
  • Acceptable Credit History


Pay Range

USD $75,786.00 - USD $113,628.00 /Yr.

Compensation & Benefits

  • Health, Dental & Vision Benefits
  • Bonus opportunity
  • 401(k) with match and profit sharing
  • Flexible Time Off


Similar Jobs

More Jobs at Empeople Credit Union

More Information Technology Jobs

Find similar Information Security Analyst jobs: