IT Security Analyst

St. Mary's Credit Union

• $80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in information security, cybersecurity, computer science, information systems, or equivalent experience.
  • 3+ years of hands-on experience in IT security or related roles.
  • Experience with vulnerability scanning tools and remediation processes.
  • Proven ability to triage security incidents and maintain documentation.
  • Familiarity with compliance and security concepts in regulated environments.

Responsibilities

  • Monitor and operate vulnerability scanning tools across various technology assets.
  • Review scan results and track remediation activities to closure.
  • Coordinate with IT and third-party vendors to address security vulnerabilities.
  • Investigate security events and escalate incidents according to procedures.
  • Process user access requests and manage security workflows effectively.

Benefits

  • Hybrid work environment in a supportive team.
  • Opportunities for professional development and training.
  • Contributions to local civic and charitable organizations.
  • Participation in security awareness activities and exercises.
  • Dynamic work with evolving security technologies and frameworks.
Full Job Description
St. Mary's Credit Union is currently hiring a IT Security Analyst role. This is a hybrid position based at our main office in Marlborough, MA

Job Summary

The IT Security Analyst is a hands-on member of the Credit Union's Information Technology team responsible for operating core security and compliance processes. Working with and receiving day-to-day guidance from the Senior IT Security Analyst, this role manages security scanning and remediation tracking, supports the investigation and response to security events and incidents, and administers security access changes and related workflows. The analyst also supports compliance activities, audit and risk assessment remediation, security documentation, control testing, and reporting. The successful candidate will bring practical IT security experience, strong process discipline, and the ability to coordinate work across IT, business units, and third-party providers in a regulated financial-services environment.

Essential Job Functions

Performs functions within the scope of authority and expertise to provide a high level of service and responsiveness to the members and employees served by the Credit Union.

Security Monitoring, Scanning and Vulnerability Management

  • Operate and monitor approved vulnerability scanning tools across servers, workstations, network devices, applications, and other in-scope technology assets.
  • Review and validate scan results; assess severity and business relevance; create, assign, track, and follow up on remediation activities through closure.
  • Coordinate with IT administrators, system owners, vendors, and independent testers to address vulnerabilities, configuration weaknesses, and security findings.
  • Maintain accurate vulnerability records, exceptions, evidence, aging information, and management reporting.
  • Monitor alerts and logs from security systems such as firewalls, endpoint protection, SIEM, identity platforms, email security, IDS/IPS, web filtering, and Microsoft security tools.
  • Support secure configuration and system-hardening activities for endpoints, servers, cloud services, network equipment, and business applications.


Security Event and Incident Management

  • Triage, investigate, document, escalate, and track security alerts, events, and suspected incidents in accordance with established procedures.
  • Collect and preserve relevant evidence; coordinate containment, remediation, recovery, and follow-up activities with the Senior IT Security Analyst, CIO, IT staff, business owners, and external providers.
  • Maintain incident tickets, timelines, decisions, communications, and supporting documentation sufficient for management, audit, regulatory, and lessons-learned purposes.
  • Participate in incident response exercises, tabletop activities, and post-incident reviews; help translate lessons learned into practical control and process improvements.
  • Support third-party security incident intake and tracking, including requests for information, impact analysis, and documentation of follow-up actions.


Identity, Access Changes and Security Workflows

  • Process and coordinate authorized user access requests, changes, removals, and periodic access reviews in accordance with least-privilege and segregation-of-duties principles.
  • Administer or coordinate security access workflows for employee onboarding, role changes, transfers, terminations, elevated access, shared accounts, service accounts, and vendor access.
  • Validate required approvals and supporting information before changes are completed; retain clear evidence of request, approval, implementation, and verification.
  • Identify incomplete, conflicting, excessive, or aging access and workflow items, and escalate exceptions or control concerns promptly.
  • Work with IT and business owners to improve the consistency, automation, documentation, and reporting of access-management workflows.


Security Compliance, Risk and Audit Support

  • Assist with operation and documentation of controls aligned with the Credit Union's Information Security Program, selected security framework, policies, and regulatory expectations.
  • Gather, organize, and retain evidence for audits, risk assessments, control testing, regulatory reviews, penetration testing, and independent security assessments.
  • Track findings, management responses, action plans, due dates, supporting evidence, and closure status; follow up with responsible parties and escalate delays.
  • Help maintain security policies, standards, procedures, playbooks, control narratives, inventories, metrics, and compliance records.
  • Complete assigned activities within the Information Security Plan and support applicable cybersecurity assessments and risk-management tools.
  • Assist with third-party security and compliance reviews, including due-diligence evidence, risk issues, remediation tracking, and ongoing monitoring for assigned vendors.
  • Prepare clear security and compliance metrics, status summaries, and supporting analysis for IT leadership and governance reporting.


Security Program and Team Support

  • Work collaboratively with the Senior IT Security Analyst, who serves as the senior analyst and provides technical and operational guidance for analyst activities.
  • Maintain assigned procedures, recurring tasks, work queues, tickets, and dashboards so that security work is visible, prioritized, and completed on schedule.
  • Participate in evaluating, implementing, configuring, and improving approved security products, tools, and services.
  • Support employee security-awareness activities, phishing exercises, and targeted communications in coordination with internal stakeholders.
  • Share knowledge, document repeatable processes, and cross-train to support continuity of security operations.


Other Duties

  • Ability to travel throughout the retail branch network; a valid driver's license is required.
  • Attend staff, departmental, and other required meetings and training.
  • Travel to conferences, professional-development events, vendor locations, or other business locations when required.
  • Provide service to membership communities by volunteering time to local civic and charitable organizations.
  • Act as vendor owner for assigned third-party relationships, including applicable vendor-management processes and reviews.
  • Perform other duties as assigned.


Qualifications, Experience and Education

  • Bachelor's degree in information security, Cybersecurity, Computer Science, Information Systems, or a related field, or an equivalent combination of relevant education and practical experience.
  • Three or more years of hands-on experience in IT security, cybersecurity operations, security compliance, IT audit, or a closely related role.
  • Demonstrated experience operating vulnerability or configuration scanning tools and managing findings through remediation and closure.
  • Demonstrated experience triaging security alerts or incidents and maintaining complete incident documentation.
  • Experience administering or coordinating identity and access changes, approvals, periodic reviews, and workflow records.
  • Working knowledge of security and compliance concepts applicable to regulated organizations, including risk assessments, control evidence, policy and procedure management, audit remediation, least privilege, and segregation of duties.
  • Experience in banking, credit unions, financial services, or another regulated industry is strongly preferred.
  • Security certification such as Security+, SSCP, GSEC, CySA+, or a comparable certification is preferred.
  • Strong written communication, analytical thinking, organization, follow-through, and attention to detail.
  • Ability to handle confidential security, employee, vendor, and member information with sound judgment.


Technical Knowledge and Skills

  • Vulnerability management, endpoint security, firewalls, SIEM and log review, IDS/IPS, email security, web filtering, identity and access management, and multifactor authentication.
  • Microsoft technologies including Active Directory, Entra ID, Group Policy, Microsoft 365, Windows security, and related security administration concepts.
  • Security ticketing, case management, workflow, evidence collection, reporting, and documentation practices.
  • General understanding of networks, cloud services, endpoints, servers, authentication, common protocols, and secure configuration practices.
  • Familiarity with widely used security and control frameworks, such as NIST Cybersecurity Framework and CIS Controls.
  • Proficiency with Outlook, Word, Excel, PowerPoint, Teams, and web-based business applications.


Core Competencies

Accountability; adaptability; analytical judgment; collaboration; communication; customer service; improvement and innovation; job knowledge; organizational awareness; process discipline; and self-development.

Work Environment and Physical Demands

Usual office working conditions with occasional exposure to noise. While performing the duties of this position, the individual is required to use hands to handle objects, tools, or controls; reach with hands and arms; talk and hear; and frequently stand, walk, and sit. The individual may occasionally stoop, kneel, crouch, or lift up to fifteen pounds. Specific vision abilities include close, distance, color, peripheral, and depth vision, and the ability to adjust focus. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the position.

Similar Jobs

More Information Technology Jobs

Find similar IT Security Analyst jobs: