What We Are Looking ForThe Information Security Analyst supports the Information Security Officer in operating Thread Bank's information security program. This role owns the recurring operational work of the program: user access reviews, findings and remediation tracking, vulnerability and cloud configuration monitoring, security awareness training, incident response support, and evidence collection for audits and regulatory examinations. The Analyst works across Thread's internal systems, cloud infrastructure, digital banking products, and the technology connections that support embedded banking programs, driving issues to a documented resolution.
What you'll doAccess governance and identity
- Execute quarterly user access reviews across Amazon Web Services accounts, Microsoft Entra ID, SharePoint, and other in-scope applications
- Reconcile system access against the HR roster, flag exceptions, drive them to correction, and obtain documented owner sign-off
- Perform segregation of duties checks and escalate conflicts to the ISO
- Maintain the privileged credential inventory, monitor rotation schedules, and review check-out activity for shared and administrative accounts
- Process access requests, transfers, and terminations against the Bank's approval requirements
Vulnerability and configuration management
- Run recurring vulnerability scans and cloud configuration assessments across the Bank's AWS organization and Microsoft 365 tenant
- Triage findings by severity, assign remediation owners, and track each finding against the Bank's established remediation schedule
- Verify that remediation closed the exposure and retain closure evidence
- Monitor the external attack surface, including certificates, exposed services, domains, and application programming interfaces
- Escalate overdue and recurring findings to the ISO with a recommended course of action
Monitoring and incident response
- Act as a first responder for security alerts, including tickets raised by the Bank's managed detection and response provider
- Support incident response activities: triage, containment support, evidence preservation, timeline construction, and after-action documentation
- Support analysis of incidents at technology providers and program partners where Thread data, systems, or connectivity may be affected
- Track regulatory and contractual notification timelines during an incident, and prepare the supporting record the ISO needs to make notification decisions
Risk assessment and control testing
- Assess controls against NIST CSF and NIST SP 800-53, document gaps, and recommend treatment
- Support security review of new products, applications, integrations, and infrastructure changes before production deployment
- Maintain the information asset inventory and data classification records in support of the Bank's Data Governance Policy
- Test the design and operating effectiveness of assigned controls, and document results so auditors and examiners can follow them
Audit, examination, and reporting
- Assemble and quality-check evidence for internal audit, external audit, and regulatory examinations
- Track audit and examination findings assigned to Information Security through to closure, with supporting documentation
- Produce recurring program metrics and reporting for the ISO, including material that supports management and Board reporting
- Maintain information security policies, standards, and procedures, and support the annual review cycle
Security awareness
- Run the phishing simulation program, track results, and report trends
- Administer annual security awareness training, monitor completion, and follow up on outstanding assignments
- Deliver targeted training to teams that handle sensitive customer information
- Perform additional responsibilities as assigned by the Information Security Officer or business needs
Qualifications- Located in Nashville, Tennessee In Office M-F
- Bachelor's degree in information security, information technology, computer science, or a related field, or equivalent practical experience
- Three or more years of experience in information security, IT risk, or security consulting
- Working knowledge of NIST CSF and NIST SP 800-53, with the ability to translate control language into specific technical checks and documented evidence
- Hands-on experience with vulnerability scanning, log review, and enterprise or cloud infrastructure security
- Practical experience with Windows, Linux, directory services such as Active Directory or Entra ID, and network fundamentals
- Strong written communication skills; this role produces documentation reviewed by auditors, examiners, and executives
- Demonstrated follow-through on remediation work, not assessment work alone
- Ability to handle confidential customer and Bank information appropriately and meet background screening requirements applicable to employees of a financial institution
- Experience at a bank, credit union, or other regulated financial institution
- Familiarity with GLBA Safeguards requirements, FFIEC Information Technology Examination Handbooks, and regulatory incident notification requirements
- AWS security experience, including IAM, GuardDuty, Security Hub, Inspector, and cloud posture management
- Microsoft 365 and Entra security experience, including Purview
- Master's degree in cybersecurity or a related field
- Industry certification such as CISSP, CISA, CRISC, a GIAC certification, CompTIA Security+, or AWS Certified Security
- Scripting ability in Python or PowerShell
- Experience supporting secure software development practices, including static analysis, dependency scanning, and secret detection