Senior Cybersecurity Analyst
Salary: $73,000 - 94,000 per year
Requirements:
We ask for 7–9 years of experience in cybersecurity governance, risk management, security architecture, security assurance, vulnerability management, or a closely related area. We need a solid grasp of cybersecurity frameworks and standards, including NIST CSF, NIST SP 800-53, FFIEC ACET, and CIS Controls. We expect experience performing cybersecurity risk assessments and judging the effectiveness of controls. We require knowledge of secure design principles across cloud, network, application, and identity environments. We look for understanding of threat intelligence, vulnerability management, and cybersecurity risk analysis methods. We need experience supporting audits, regulatory reviews, and compliance efforts. Strong analytical, communication, presentation, and report-writing abilities are essential. You must be able to work in a consumer office setting using standard equipment such as a PC, copier, and telephone. You must be able to lift at least 25 lbs. Occasional travel is required. A BA/BS degree in Cybersecurity, Information Technology, Information Systems, Risk Management, or a related discipline is preferred. Experience in financial services, credit unions, or other highly regulated sectors is preferred. Familiarity with threat intelligence frameworks, MITRE ATT&CK, CVSS, and EPSS is preferred. Experience preparing board-level or executive cybersecurity reporting is preferred. Professional certifications such as CISSP, CRISC, CISM, CGRC, CISA, or GIAC credentials are preferred.
Responsibilities:
We conduct independent, risk-based reviews of system, network, application, cloud, and third-party architectures to identify cyber risks and confirm alignment with our policies, standards, and secure-by-design practices. We provide governance oversight for network segmentation, identity management, cloud security, and infrastructure security initiatives, identifying risks and recommending effective controls. We participate in project governance and the system development lifecycle to ensure cybersecurity risks are identified, assessed, and addressed throughout technology work. We carry out cybersecurity risk assessments for technology initiatives, applications, infrastructure changes, and third-party services, evaluating threats, vulnerabilities, control strength, and residual risk. We support risk acceptance, exception handling, and remediation tracking, making sure cyber risks are documented, communicated, and managed within our risk tolerance. We contribute to enterprise and operational risk management through analysis, reporting, and clear communication. We monitor threat intelligence and industry activity to spot emerging cyber threats and assess their potential impact on our risk exposure. We turn threat intelligence into practical recommendations for control improvements, mitigation strategies, and cybersecurity planning. We oversee the vulnerability management program independently, including review of prioritization methods and validation of remediation plans for critical and high-risk vulnerabilities. We track remediation performance against service level objectives and report on vulnerability trends, exposure metrics, program effectiveness, and significant risk conditions. We coordinate and oversee penetration testing, red team exercises, and independent security reviews, ensuring findings are evaluated and remediated appropriately. We develop and maintain cybersecurity metrics, dashboards, risk reports, policies, standards, and control frameworks, while supporting strategy, maturity improvement efforts, and governance committee work as a subject matter expert. We work collaboratively in a team-oriented environment and communicate, delegate, and adapt with integrity, self-awareness, courage, respect, and a commitment to learning.
Technologies:
Cloud Support Network Security
More:
We are an organization that believes we all do well by doing good. We value diverse perspectives, prioritize the well-being and success of our employees, and see every team member as part of our mission to support a healthy environment and shared prosperity. We offer a dynamic workplace with opportunities for professional growth and individual development. The Senior Cybersecurity Governance Analyst plays a key second-line oversight role in our cybersecurity risk management program, advising technology, business, and risk stakeholders and helping strengthen our overall security posture.
last updated 30 week of 2026



