As an Information Security Analyst, you will be NuMark Credit Union's hands-on defender. You will monitor and respond to security events, run the vulnerability management program, manage third-party security risk, and produce the evidence and documentation our examiners and auditors rely on. You will work closely with IT operations, our managed detection and response partner, and business units across the credit union. This role suits someone who likes both technical investigation and turning findings into lasting fixes.
What You'll Do:- Triage and investigate alerts in Microsoft Defender XDR (Endpoint, Identity, Office 365, Cloud Apps) and escalations from our managed SOC/MDR provider.
- Lead or support incident response activities: containment, evidence collection, root-cause analysis, and post-incident reporting in line with NuMark's Incident Response Plan and NCUA notification requirements.
- Analyze phishing and email threats, including user-reported messages, and tune email security controls.
- Hunt proactively for threats using KQL and available telemetry.
- Run the vulnerability management program: scanning, risk-based prioritization, remediation tracking, and exception handling.
- Track penetration test and audit findings through to verified closure.
- Monitor secure configuration across endpoints (Intune), identities (Entra ID), and cloud resources (Azure, Defender for Cloud).
- Prepare evidence and documentation for IT examinations, internal and external audits, and regulatory reviews (NCUA, FFIEC, GLBA / NCUA Part 748).
- Maintain security policies, standards, and procedures, and track the security exception register.
- Support data protection efforts, including Microsoft Purview sensitivity labeling and DLP.
- Contribute security metrics and reporting for the Information Security Committee.
- Review SOC reports for exceptions and complementary user entity controls (CUECs), and confirm that NuMark has the matching controls in place.
- Work with contract owners to include appropriate security, data protection, breach notification, and right-to-audit provisions in vendor agreements.
- Keep the vendor inventory accurate and produce third-party risk documentation for examiners, auditors, and the Information Security Committee, following NCUA and FFIEC outsourcing guidance.
- Help run security awareness training and phishing simulations.
- Advise IT and business teams on secure design for new projects, vendors, and technologies.
- Take part in business continuity and disaster recovery testing.
Qualifications:- At least three years of experience in information security, security operations, or systems or network administration with significant security responsibilities required.
- Hands-on experience with Microsoft security tools, including Defender XDR, Entra ID, and Intune required.
- Working knowledge of networking, firewalls (Palo Alto preferred), DNS, and TCP/IP required.
- Understanding of incident response, vulnerability management, and common attack techniques (MITRE ATT&CK) required.
- Strong written communication skills, including the ability to document findings clearly for technical staff, leadership, and examiners required.
- Ability to handle confidential information with discretion required.
- Experience in a credit union, bank, or other regulated financial institution preferred.
- Familiarity with the FFIEC CAT / CISA CPGs, NIST CSF, or CIS Controls preferred.
- Experience with third-party risk management programs or platforms (e.g., Nvendor, Venminder) preferred.
- KQL, PowerShell, or other scripting experience preferred.
- Experience with Azure security (Defender for Cloud, Azure Firewall, networking) preferred.
- Exposure to Microsoft Purview, Zscaler, or Mimecast preferred.
- Certifications such as Security+, CySA+, SC-200, GCIH, or CISSP (or progress toward one) preferred.
Benefits:We want to make sure you're taken care of, which is why we strive to offer competitive and cost-conscious benefits for you and your family. Full Time Employees can choose between several plans from Blue Cross Blue Shield (HMO, Options or PPO), Dental, Vision, 3 weeks of Paid Time Off, Paid Holidays Off, Company Lunches and Parties, Birthday Holidays, Life Insurance (Company Paid), Short and Long Term Disability (Company Reimbursed), 401(k) Savings Plan with Company Match & Profit Sharing, Flex Spending Account, Accident Insurance Plans, Education Reimbursement for Bachelor or Master's Degrees, Employee Assistance Program, Paid Community Volunteer Time, and Career Advancement Opportunities.
Compensation Range (exempt): $85,000 - $105,000 annually. Employees are eligible for yearly merit increases based on performance.