Position:
Security Analyst IILocation:
Lakewood, WAThis position is on-site and hybrid eligible after completing successful introductory period.What You'll Do:- Monitor, investigate, and respond to security alerts, incidents, vulnerabilities, and emerging threats to protect Harborstone's systems, data, and information assets.
- Maintain and improve cybersecurity controls, policies, procedures, reporting, and documentation in alignment with regulatory requirements and industry standards.
- Partner with IT Leadership on security architecture, vendor risk reviews, disaster recovery planning, awareness training, and recommendations that strengthen the organization's overall security posture.
Key Responsibilities:- Lead day-to-day cybersecurity operations by monitoring security tools, investigating alerts and incidents, coordinating response efforts, and protecting Harborstone's systems, data, and information assets.
- Manage vulnerability, risk, and control activities by supporting assessments, penetration testing, remediation recommendations, vendor security reviews, and disaster recovery planning.
- Maintain and strengthen the security program through policy and procedure documentation, regulatory compliance support, leadership reporting, security awareness coordination, and continuous improvement of security controls.
What We're Looking For:- Experienced security professional with strong hands-on knowledge of incident response, vulnerability management, security monitoring, and cybersecurity tools.
- Strong communicator and problem solver who can translate complex security risks into clear, actionable recommendations for leadership and business partners.
- Self-motivated, adaptable teammate who demonstrates sound judgment, protects confidential information, supports compliance expectations, and continuously improves Harborstone's security posture.
Why Join Our Team?Enjoy competitive wages, unique benefits, and a workplace culture that supports your growth and happiness.
- Competitive pay: $102,332.39 - $153,498.59* annually dependent on experience
- 401(k) with generous employer match
- Medical, dental, and vision coverage
- Employer contribution toward dependent medical premiums
- Generous paid time off and holidays
- Professional development and career growth opportunities
- Employee appreciation and recognition programs
- Discounted employee financial products
- A mission-driven culture focused on helping members and communities thrive
- A collaborative, supportive culture that values work-life balance and employee well-being
* Starting salary is based on experience and qualifications and will likely not exceed mid-point of range to allow for development and future increases.Position SummaryFLSA: Salary Exempt The Security Analyst II performs core functions of day-to-day operations for in-place security solutions and the monitoring, identification, investigation, and resolution of security incidents detected by those systems to protect the organization's information assets. Secondary tasks include involvement in the implementation of new security solutions, participation in the creation and or maintenance of policies, standards, baselines, guidelines, and procedures as well as conducting vulnerability audits and assessments. The position works closely with IT Leadership to design, implement, and management of the aforementioned. The position is also expected to be fully aware of Harborstone's security goals as established by stated policies, procedures, and guidelines and to actively work towards upholding those goals. The position reports indirectly to the SVP/Chief Information Officer to ensure appropriate segregation of security responsibilities.
Key ResponsibilitiesCyber Security Management- Ensure the confidentiality, integrity, and availability of the data residing on or transmitted to/from/through the organizations workstations, laptops, servers, and other systems and in databases and other data repositories
- Monitoring and analysis of security alerts and incidents, conduct investigations, collaborate with leadership and coordinate response efforts to mitigate threats
- Use security tools and technologies to monitor for suspicious activity and potential threats
- Oversee and respond to regular vulnerability assessments, penetration testing, identification of potential security risks, and collaborate with IT Leadership to recommend remediation
- Produce, maintain, document, and enforce; security policies, procedures, incident response reports, root cause analysis, and standards to protect information assets
- In support of the Vendor Management Program, review and document SOC reports, disaster recovery, and similar documentation of current and potential business partners. Provide feedback and recommendations to IT Leadership
- Participate in planning and design of business continuity and disaster recovery plan
- Other job-related duties as assigned
Oversight and Development- Keep current with and ensure proactive and timely compliance with relevant regulations and standards, such as PCI-DSS, NCUA, DFI, FFIEC, and other regulatory guidelines
- Prepare and present detailed reports on security incidents, findings, and recommendations to IT Leadership
- Prepare reports for Cybersecurity Committee regarding current and potential threats
- Assist IT Leadership in development of Annual Cybersecurity Report to the Board of Directors
- Coordinate with IT Leadership and Training and Development to promote a comprehensive and cohesive approach to security and security awareness training programs
- Collaborate with IT Leadership on security architecture and systems to protect critical infrastructure and sensitive data
- Stay up to date on the latest cybersecurity threats, trends, and technologies, ensuring the organization's defenses are continuously improved
- Ensure continuous maturity of appropriate security controls, policies, and procedures in compliance with industry standards (NIST, CIS 18, etc.)
Other Responsibilities- Keep current with FS-ISAC, ISC2, and other sources
- Upholds legal, regulatory and compliance requirements unique to the role, in addition to Bank Secrecy Act, Anti-Money Laundering, OFAC, and Information Security policies and procedures.
- Completes annually required compliance related courses and required Product and Process Knowledge competency testing, in addition to job related courses.
- You may be expected to perform other duties as assigned
QualificationsEducation:- Bachelor's degree in computer science, Information Security, or related field
- Experience:
- 5-7 years or more experience in information security, with a focus on incident response, vulnerability management, and security monitoring software, required. Maintain strict confidentiality and utmost discretion handling sensitive information and security incidents, ensuring all data and findings are protected and shared only with authorized personnel
- Experience in the financial services industry, particularly within credit unions
- 10 years or more experience in information security, with a focus on incident response, vulnerability management, and security monitoring software, preferred
Technical Skills:- Advanced knowledge of Windows Desktop/Server Operating Systems, Active Directory, Patch Management, Security Information and Event Management, Endpoint Detect and Response, Network Access Control, Vulnerability Scanning, and Network Administration
- Knowledge of regulatory requirements and industry standards related to information security
- Ability to provide guidance to junior security analysts and other team members
- PowerShell or other scripting language/automation skills
Soft Skills:- Ability to work non-standard hours as necessary to address incidents
- Proven analytical and problem-solving skills, ability to learn new systems, and proficiency with security tools and technologies
- Highly adaptable and flexible; able to adjust quickly and effectively prioritize and execute tasks
- Strong customer service orientation with excellent written and oral communication skills to communicate complex issues clearly and concisely in business-friendly and user-friendly language
- Highly self-motivated and willing to learn and adapt to rapidly changing technology and share knowledge with other team members
- Certifications/Additional Qualifications (if applicable):
- Hold one or more of the following certifications: Security+, GIAC Information Security Fundamentals, Microsoft Certified Systems Administrator: Security, or CISSP, required
- Must be bondable
- Hold one or more of the following certifications: CCSP, CISA, or CISM, preferred
Physical Considerations- Ability to communicate effectively in verbal, written, and electronic formats with internal and external stakeholders.
- Ability to read, comprehend, and respond to written and verbal instructions and information.
- May be required to sit or stand for extended periods, depending on job duties.
- May involve repetitive motions, including keyboarding and handling office equipment.
- May require stooping, bending, squatting, or reaching occasionally.
- May be required to lift and carry items weighing up to 20 pounds.
- Ability to navigate office environments, including walking between workstations, meeting rooms, and member service areas.
- Travel may be required as needed to support business operations and organizational needs.
If this sounds like the perfect job for you, we'd love to hear from you!