Information Security Risk Analyst
Patelco Credit Union - Dublin, California, United States, 94568
Work at Patelco Credit Union
Overview
- View job
Overview
Patelco Credit Union is a not-for-profit credit union with a purpose to build financial health and wellbeing for our members. Since 1936, Patelco has grown from $500 in assets to over $9 billion in assets and is the 7th largest credit union in California with branches throughout Northern California.
We are here for our members throughout all their stages of life. Meeting them with the products and services to help them plan purposefully for their futures and to secure our life-long partnership as their trusted financial advocate. As one team, we are all committed to delivering service, empowering financial literacy, creating products, and providing new technology for our members.
We believe that work should be rewarding, challenging, and enjoyable. We're dedicated to creating a positive and supportive culture where our team members can thrive. If you're looking to use your skills and knowledge to make a difference in our members' lives, Patelco could be the perfect fit for you.
Overview
The Information Security Analyst is responsible for monitoring, assessing, and improving the credit union's information security posture. This role supports the implementation of security controls, risk assessments, threat monitoring, and compliance efforts to protect member data and critical systems. The analyst works closely with IT, risk, and compliance teams to identify vulnerabilities, mitigate InfoSec threats, and ensure adherence to NCUA, FFIEC, and industry leading standards.
Responsibilities
Monitor security alerts, logs, and events from SIEM (Security Information and Event Management) systems. Investigate and respond to InfoSec threats, suspicious activities, and security incidents in a timely manner. Help manage vulnerability scans and penetration testing to identify and remediate security gaps. Support incident response efforts, including containment, mitigation, and forensic analysis. Assist in security risk assessments to evaluate potential threats to critical business functions. Help ensure compliance with NCUA, FFIEC, GLBA, PCI-DSS, and other cybersecurity regulations. Participate in third-party vendor security assessments to evaluate related risks. Maintain and update security policies, procedures, and risk documentation. Support user access reviews, privileged access management (PAM), and authentication controls. Assist in monitoring and maintaining multi-factor authentication (MFA) and identity security solutions. Help ensure that proper role-based access control (RBAC) policies are enforced. Assist in the development of cybersecurity awareness programs for employees. Help conduct phishing simulations and security training to reduce social engineering risks. Provide guidance to employees on industry leading practices for password management, secure browsing, and email security. Work with IT to implement security controls for networks, applications, cloud environments, and endpoints. Assist in oversight of patch management and system updates to reduce vulnerabilities. Help ensure that firewalls, IDS/IPS, endpoint protection, and encryption technologies are properly configured and maintained. Strong understanding of Information Security and cyber threat intelligence, security event analysis, and vulnerability management. Proficiency in security tools such as Splunk, CrowdStrike, Qualys, Palo Alto, and Microsoft Defender. Knowledge of cloud security leading practices (AWS, Azure, or Google Cloud). Strong analytical and problem-solving skills with attention to detail. Ability to work collaboratively across teams and communicate technical risks to non-technical stakeholders. Qualifications
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field. 3+ years of experience in information security, cybersecurity operations, or IT security. Experience with security monitoring tools, firewalls, SIEM platforms, and endpoint protection solutions. Familiarity with cybersecurity frameworks such as NIST CSF, ISO 27001, CIS Controls, and FFIEC guidelines. Preferred Certifications: Certified Information Systems Security Professional (CISSP) Certified Ethical Hacker (CEH) CompTIA Security+ GIAC Security Essentials (GSEC) This role is based in Dubin HQ Target Base Pay
$118,658/year
Compensation at Patelco
Please note that the salary information is a general guideline only. Patelco Credit Union considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, education/training, key skills, internal peer equity, as well as market and business considerations when extending an offer. We offer a competitive total rewards package including a wide range of medical, dental, vision, financial, and other benefits.
We Offer
Physical Health:
Exceptional Medical, Dental, Vision, and Life Insurance benefits Onsite fitness center at HQ and rewards for completing wellness related activities Financial Health:
Competitive compensation packages with bonus opportunity 401(k) with 3% Safe Harbor and 5% employer match Discounts on loan products Tuition reimbursement Emotional Health:
Employee Assistance Program (EAP) PTO for part-time and full-time positions Paid holidays Personal Development:
On-the-job training and skills development Internal transfer opportunities for career growth Volunteer work
Flexible work arrangements available for specific positions
Patelco Credit Union is an Equal Opportunity Employer including individuals with disabilities and protected veterans
IND123