JDXpert Jobs
     
HRTMS Job Description Management

Senior Information Security Analyst

J  o  b    D  e  s  c  r  i  p  t  i  o  n

 

 

 

THE DETAILS


 

Job Code:

11227

Grade:

21S

Status:

Exempt


POSITION AND PURPOSE


 

The Senior Information Security Analyst provides subject matter expertise in a broad range of information security disciplines and configuration monitoring for securing the Golden 1's information, infrastructure, and member non-public information. Ensures information security best practices are integrated into the change and configuration management processes and ensures systems are configured for optimal support security monitoring. Actively looks for and discovers new potential cyber threats and vulnerabilities and participates in security incident response activities. Regular participant to provide internal security consultancy, as well as analyzes, supports, and assists resolve system security issues and concerns to Golden 1 internal and external business environments, and others.


WHO WE ARE


 

Golden 1 Credit Union is among the top credit unions in the country. As a member-owned, not-for-profit cooperative, Golden 1 is guided by the credit union philosophy of “people helping people.” We are committed to empowering our members and uplifting our communities as we create a more equitable and financially inclusive California. We welcome all who embrace our Core Values.


WHO YOU ARE


 

You are a security-focused technology professional with expertise in information security, vulnerability management, threat detection, and risk mitigation.

You have a proven ability to partner with technical and business teams to strengthen security controls, lead incident response and threat hunting activities, and ensure compliance with regulatory and organizational requirements.

Your experience includes improving security monitoring, managing vulnerabilities, evaluating security solutions, supporting audits, and driving secure configuration and change management practices. You are passionate about protecting sensitive information, mentoring teams, and delivering practical, business-aligned security strategies that reduce risk while enabling innovation.


THE WORK


 

Lead ongoing vulnerability management activities and identification of potential threats. Coordinate and direct technology staff in the identification and remediation of system vulnerabilities across the computing environment. Escalate any immediate and severe issues accordingly to the attention of the Manager – Information Security and appropriate reporting to senior leadership.

 

Maintain, improve, and develop vendor supported and customized organizational processes supporting information security monitoring of asset, patch, network, vulnerability, change and configuration management.

 

Prepares for and participates in threat hunting and security incident response activities. This includes working with Golden 1 IT and Information support teams to develop response readiness.

 

Provide consultative support for technical and non-technical Golden 1 projects and initiatives requiring Information Security oversight to ensure policies, procedures and standards are met

 

Define and evaluate functional requirements and specifications of security systems for both internal and external business environments.

 

Partners with IT Development and Support teams to ensure appropriate procedures and processes are in place to provide optimal security monitoring of on-premises and cloud system environments as well as in establishing and managing a functional anti-virus/malware/DLP policy.

 

Monitor, measure, test and report on the effectiveness and efficiency of information security controls as well as compliance with information security policies and procedure.

 

Recommend new security solutions as well as effective improvements to existing security controls that do not negatively impact business innovation.

 

Train colleagues on new Tactics, Techniques, and Procedures (TTP) of cyber-attacks and mentor junior teammates.

 

Keep management updated on outstanding issues that are not resolved in a timely manner in accordance with established escalation procedures.

 

Work with internal and external auditors during examinations providing support and assistance in addressing audit recommendations.

 

Maintains a thorough understanding of state and federal laws and regulations related to credit union compliance including bank secrecy and anti-money laundering laws appropriate to the position.

 

Performs other job-related duties as necessary.

 

Develop and maintain an understanding of the pertinent regulatory requirements and risks inherent to job responsibilities, establish, and maintain control activities that mitigate those risks consistent with the Credit Union’s risk appetite, and ensure operational integrity and compliance with applicable regulations.


QUALIFICATIONS


 


EDUCATION:

Bachelor’s Degree of Science in Computer Science, Management Information Systems, Information Security Information Assurance, or equivalent industry experience required


EXPERIENCE:

5+ years hands on experience in the management, configuration, administration, installation, and evaluation of network or operating systems software (Microsoft, Linux desired), hardware and applications required

3+ years experience in organizational information security, information assurance or providing security consulting services required


KNOWLEDGE/SKILLS:

Demonstrates strong ability to investigate, handle and track incidents, analyze incident logs, assess malware, and understand vulnerabilities and exploits, along with strong operating systems knowledge.

Working knowledge in SIEM, intrusion detection and prevention systems (IDS/IPS), threat intelligence platforms and security orchestration, automation, and response (SOAR) solutions to centralize and manage incident and remediation workflow

Applicable knowledge of adversary tactics, techniques, and procedures (TTPs), MITRE ATT&ACK framework, CVSS, open-source intelligence (OSINT) and deception techniques.

Applicable knowledge of the NIST Cybersecurity Framework (CSF).

Demonstrates working knowledge of information security principles, risk assessment methodologies, security system standards including but not limited to network topology threats, vulnerabilities, filtering, tunneling, authenticating, access control, cryptography, system, and network hardening.

Demonstrates working knowledge of business, network systems, hardware concepts, and applications including DNS, authentication, virtualization, Database design/hardening, E-mail/secure messaging, Data Loss Prevention, and end point protection.

Strong sense of ethics, integrity, trustworthiness, and high level of professionalism.

Demonstrates the ability to articulate methodologies and concepts; communicate effectively in providing technical guidance and expertise to management and other staff.


LICENSES AND CERITIFCATIONS:

Possession of a valid California Driver’s License required

Holds or working toward one or more including: CEH, Security+, SSCP, SANS GSEC, GCIA (and related) required


CORE COMPETENCIES:

Solves Problems Proactively - Tackles complex issues independently

Innovates and Applies Insights - Suggests improvements

Delivers Results with Agility - Maintains quality during change 

Collaborates Across Teams - Works effectively with peers 

Influences and Persuades - Shares expertise to guide others 


 


ORGANIZATIONAL CONTACTS AND RELATIONSHIPS


 

INTERNAL:

All levels of staff and management

EXTERNAL:

Vendors, service providers, organizational groups, and other financial institutions as needed.


WORKING CONDITIONS


 

Work time includes weekend and after-hours time, based on organizational needs. This position works in-office where working conditions, lighting, temperature, audio, and workspace are all sufficient.


PHYSICAL REQUIREMENTS


 

Work requires the ability to constantly operate a computer and the ability to read, type, and communicate. Work may require the ability to move work-related supplies weighing up to 10-15 pounds.


DISCLAIMER/INTENT AND FUNCTION OF JOB DESCRIPTIONS


 

The above information on this description has been designed to indicate the general nature and level of work performed by team members within this classification. Because the nature of positions and job functions can change over time, this job description is not designed to contain or be interpreted as a comprehensive inventory of all essential functions, duties, responsibilities and qualifications requirements of team members assigned to this job. Job duties may be changed or modified in the Credit Union’s discretion. The Credit Union will keep team members updated on key functions, duties, and requirements of their position by communications from the Credit Union and by updating the job description from time to time. Any team member with questions about the nature of their job duties is encouraged to consult with their supervisor.


DECLARATION/ACKNOWLEDGEMENT


 

This job description outlines the essential functions and physical/mental requirements necessary to perform this role. Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions.