| Location | Provo, Utah |
| Website | https://www.uccu.com/home |
Ambition: Become a vibrant $10B institution by 2033, fueled by talented, purposeful people.
Mission: Help people improve their financial strength, achieve their dreams, and love where they bank.
What You'll Do
The Blue Team Manager is responsible and accountable for the full defensive security lifecycle at UCCU: detection engineering, continuous monitoring, incident response, and cyber recovery. This role leads the team that protects member data and credit union operations day to day, owns UCCU's logging and monitoring program, and serves as the primary operational commander during active security incidents. The Blue Team Manager also owns UCCU's response and recovery capabilities under NIST CSF 2.0 (RS and RC functions), including NCUA incident notification, stakeholder communications, BCP/DR coordination for cyber events, and post-incident regulatory follow-up, ensuring that every incident is closed with documented lessons learned and that the program measurably improves over time.
Detection Engineering and Continuous Monitoring
• Operate and mature the detection stack (SIEM, SOAR, EDR, NDR): define and maintain baselines, correlation rules, alert thresholds, detection use cases, and ATT&CK coverage; document and test all detection logic.
• Own the logging program: define what to log, where, and how; ensure reliable ingestion, field normalization, and retention in alignment with UCCU's Records Retention Schedule; perform routine completeness reviews, onboard new log sources, and provide evidence for audits and examinations.
• Coordinate day-to-day with the outsourced SOC: manage the triage handoff process, review escalations, drive the false-positive and missed-detection feedback loop, and participate in regular SOC review calls.
• Run DLP and integrity controls to prevent exfiltration and validate software, firmware, and data integrity; coordinate with system owners for remediation of identified gaps.
• Operationalize cyber threat intelligence: feed threat data into risk determinations, detection content, and threat hunt hypotheses; maintain awareness of adversary TTPs relevant to financial institutions and credit unions.
• Direct and oversee threat hunting operations: assign hunt hypotheses, review findings, and translate outcomes into new or improved detection rules.
Incident Management and Response (CSF 2.0: RS.MA, RS.AN, RS.MI)
• Serve as incident commander during active security events: lead triage, scoping, forensic analysis, impact assessment, containment, mitigation, and eradication; make real-time decisions on response actions and resource deployment.
• Design incident investigation frameworks: define scope, establish investigative hypotheses, assign workstreams to IR Analysts, and drive investigations to documented root cause conclusions.
• Provide structured, timely updates to the CISO and relevant stakeholders throughout active incidents, including current status, confirmed findings, open questions, and defined next steps.
• Ensure all incident documentation is complete and examiner-ready from initial detection through post-incident review (PIR); own the PIR process and integration of lessons learned into detection and process improvements.
• Manage all incident-related work in the team's designated ticketing system; ensure tickets reflect current status at every handoff and shift change.
• Oversee malware triage and digital forensics work performed by IR Analysts; maintain chain of custody for evidence that may support legal or regulatory action.
Incident Response Reporting and Communication (CSF 2.0: RS.CO)
• Support UCCU's NCUA 72-hour cyber incident notification process in coordination with Compliance and Legal: assess incidents against reporting thresholds, prepare required documentation, and maintain records of all regulatory communications.
• Coordinate member breach notification logistics with Compliance and Legal when applicable; ensure notifications meet content and timing requirements under applicable law.
• Support crisis communications during active incidents: in coordination with the CISO, Marketing, and Compliance, ensure that internal and external messaging is accurate, timely, consistent, and does not create additional legal or reputational risk; maintain a running communications log throughout the incident lifecycle.
• Manage voluntary external information sharing during incidents (e.g., FS-ISAC, law enforcement, peer institutions) in accordance with UCCU's incident response plans.
• Provide accurate, timely situational awareness to the CISO throughout active incidents; support the CISO in serving as the primary InfoSec liaison to Legal, Compliance, and senior leadership.
• Coordinate post-incident regulatory follow-up with the CISO: prepare supplemental documentation, respond to examiner inquiries, and track open regulatory items through to closure.
Cyber Recovery and Business Continuity Coordination (CSF 2.0: RC.RP, RC.CO)
• Maintain and execute cyber-specific recovery plans: lead the transition from containment to recovery, verify eradication, oversee system restoration, and confirm return to normal operations.
• Coordinate with IT and business line owners on BCP/DR activities for cyber events: ensure that cyber recovery scenarios are embedded in UCCU's BCP/DR planning, tested annually, and updated after each significant incident.
• Own post-incident member and stakeholder communication in coordination with Marketing and Compliance: ensure that recovery messaging is accurate, appropriately timed, and does not create additional legal or reputational risk.
• Conduct post-recovery reviews with all involved parties; document recovery timeline, gaps in recovery capability, and improvements required; track remediation items to closure.
• Maintain recovery capability metrics and report them to the CISO on a defined cadence.
Team Leadership and Continuous Improvement
• Hire, develop, and evaluate Blue Team staff including IR Analysts; set clear performance expectations aligned to team KPIs and CSF 2.0 function coverage.
• Manage team workload through established project management and ticketing platforms (e.g., monday.com, Jira, or equivalent); maintain visibility into all open incidents, projects, and improvement initiatives.
• Drive a formal program improvement cycle: collect lessons learned from incidents, purple team exercises, and audits; convert findings into prioritized improvement tasks tracked through to completion.
• Plan and execute purple team exercises in coordination with the Red Team; translate outcomes into detection improvements, updated playbooks, and updated training materials.
• Author, maintain, and version-control runbooks, playbooks, and IR procedures; ensure documentation is in a state of ongoing examiner readiness.
• Support CISO preparation for board and supervisory committee presentations related to Blue Team operations, incident metrics, and detection program maturity.
Who We Are (UCCU)
In 1955, a BYU faculty member discovered a concept that would change everything: a financial institution owned not by stockholders, but by the people it served. He and six colleagues each put in $5 from their own pockets. They could not afford office space, so they set up a table on a stair landing in a campus building. They had no vault, so they kept their assets in a cast-iron tub. From those humble beginnings, Utah Community Credit Union was born.
Seventy years later, UCCU has grown into one of the fastest-growing credit unions in the nation, serving more than 185,000 members across the Wasatch Front and beyond, with over $3 billion in assets and a clear ambition to reach $10 billion by 2033. What has never changed is the founding philosophy: people helping people. UCCU is still not-for-profit, still member-owned, and still driven by a mission to help members improve their financial strength, achieve their goals and dreams, and love where they bank.
UCCU's growth today is both organic and strategic. The recent acquisition of TransWest Credit Union added four branches to the network. Membership in the Allpoint ATM network expanded reach beyond its physical footprint. A landmark $7 million partnership with Utah Tech University deepened UCCU's roots in higher education and community investment. CEO Justin Olson, who has served UCCU for more than two decades in roles including CIO before stepping into the top seat, has set a clear vision for where the organization is going: “We envision UCCU as a vibrant, $10 billion institution by 2033, fueled by talented, purposeful people. Our members are at the heart of everything we do.”
Why UCCU
UCCU is building something special. The organization is in a deliberate, well-resourced growth phase with a long-term strategy, a strong balance sheet, and leadership that has earned the trust of both members and employees over decades. For the right leader, this is not a role where you come in to manage steady state. It is a role where you help build the defensive security capability that protects members and fuels the next chapter.
Our commitment is to create an experience where employees say, “I LOVE working here because I LOVE who I'm becoming while inspiring people to LOVE where they bank.” We invest in helping you become a better leader, from the boardroom to the family room and bank to the backyard.
UCCU holds itself to a high standard of honesty, professionalism, and integrity. Its culture is built on commitment to outstanding service, respect for others, and fiscal responsibility. Leaders here are expected to model the culture, invest in people, and lead with both strategic vision and executional discipline.
Information security sits at the center of member trust. As UCCU grows in members, assets, and digital reach, the Blue Team is the function that keeps member data safe and operations resilient. The Blue Team Manager is one of the most consequential operational security roles in the organization, and one of the most visible opportunities for a leader who wants to make a real difference in protecting the institution and the people it serves.
Who You Are
Education
• Bachelor's degree in information security, computer science, cybersecurity, or a related field is preferred; equivalent professional experience will be considered in lieu of a degree.
Experience
• 8 or more years of progressive experience in security operations, incident response, detection engineering, SOC, blue team, or threat hunting, with at least 3 years in a lead or management role.
• Demonstrated experience leading incident response operations, including serving as incident commander during significant events.
• Demonstrated experience authoring detections, building parsing/normalization, and performing threat hunts.
• Proven execution of IR playbooks and recovery activities, including cross-functional and external coordination.
• Experience with NCUA, FFIEC, or other financial institution regulatory reporting requirements for cybersecurity incidents is strongly preferred.
• Hands-on experience with SIEM platforms (Splunk, Microsoft Sentinel, or equivalent), EDR, and SOAR tooling.
• Experience managing or coordinating with an outsourced SOC or MSSP.
• Experience with digital forensics, malware analysis, and evidence chain of custody.
• Experience managing work through ticketing and project management platforms (ServiceNow, Jira, monday.com, or equivalent).
• Familiarity with BCP/DR planning and cyber recovery coordination is preferred.
Certifications (Preferred)
• GIAC Certified Incident Handler (GCIH)
• GIAC Certified Enterprise Defender (GCED) or GIAC Certified Forensic Analyst (GCFA)
• GIAC Security Leadership (GSLC) or equivalent management-level security credential
• CISSP
• CompTIA CySA+ or Security+ (or equivalent)
• MITRE ATT&CK Defender (MAD) certification
Knowledge, Skills, and Abilities
• Deep working knowledge of MITRE ATT&CK and its application to detection engineering, threat hunting, and purple team planning.
• Strong understanding of NIST CSF 2.0 Detect, Respond, and Recover functions, and the NIST SP 800-53 control families relevant to Blue Team operations, and their practical application in a regulated financial institution.
• Defensive security expertise across Windows, Linux, and macOS.
• Working knowledge of network protocols and packet/flow analysis.
• Familiarity with cloud logging and controls.
• Ability to make sound, time-pressured decisions during active incidents and communicate them clearly to leadership.
• Ability to write and interpret queries in at least one SIEM query language (SPL, KQL, or similar).
• Familiarity with log management concepts: source onboarding, field normalization, ingestion health monitoring, and retention policy enforcement.
• Strong written and verbal communication skills; able to produce examiner-ready documentation and brief senior leadership clearly and concisely, including clear and direct conversations with the CEO, executives, and upper management during a crisis.
• Comfort using ticketing and project management tools as a daily leadership discipline.
• Probabilistic reasoning: ability to assess likelihood of attacker activity, weigh incomplete evidence, and communicate confidence levels appropriately to leadership and examiners.
• Precision in reviewing logs, alerts, and configurations to avoid false positives or missed threats.
• Adaptability to evolving threats, new tools, and changing priorities; keeps up with emerging threats, new attack techniques, and defensive technologies.
• Ability to stay calm and focused during high-pressure incidents.
• Handles sensitive data responsibly and maintains trustworthiness in all actions.
• Ability to develop and mentor staff, set measurable expectations, and build a high-performing team culture.
What Success Looks Like
Success in this role is measured against the following performance measurements:
• % of critical systems and applications with confirmed, healthy log ingestion into SIEM
• % of MITRE ATT&CK techniques with at least one validated detection
• True positive rate for high-severity alerts
• Reduction in false positives over time on analyst-owned detection rules
• Average time from compromise to detection (mean dwell time)
• Time from alert to analyst acknowledgment
• % of incidents with complete, examiner-ready documentation through PIR
• % of high-severity incidents with NCUA 72-hour notification filed on time (where threshold is met)
• % of cyber recovery scenarios tested in BCP/DR exercises annually
• Number of purple team exercises completed per year with findings tracked to remediation
• % of post-incident improvement items closed within committed timeframes
• % of repeatable response tasks automated via SOAR
• Staff performance review completion and development plan currency
Working Conditions, Physical and Mental Requirements
Working Conditions
None: No hazardous or significantly unpleasant conditions (such as in a typical office). The position requires on-call availability and the ability to respond to and lead incident response activities outside of standard business hours. Works a regular and predictable schedule and must be sufficiently fluent in English to process work and business transactions.
Physical Activities and Requirements
Typical office environment with no unusual physical demands. Specifically: frequent talking, especially where one must convey detailed or important instructions or ideas accurately, loudly, or quickly; average hearing sufficient for normal conversation; repetitive motion of the wrists, hands, and/or fingers; average visual acuity necessary to prepare or inspect documents or a computer screen; and sedentary physical strength, sitting most of the time and exerting up to 10 lbs. of force occasionally.
Mental Activities and Requirements
• Probabilistic reasoning: estimates likelihood of attack success, scenario weighting, and Bayesian updating as new evidence emerges during investigations.
• High-stakes decision making under time pressure and incomplete information during active incidents.
• Ability to hold multiple concurrent investigations and team management responsibilities without loss of accuracy or judgment.
• Sustained analytical focus during complex, multi-day incident investigations.
• Reasoning ability: interpret large volumes of log and alert data, identify anomalies, and determine root causes; anticipate attacker tactics and design defensive measures proactively; detect subtle indicators of compromise across diverse data sources; prioritize response actions based on business impact and threat severity.
• Mathematics ability: use averages, standard deviation, and variance to detect anomalies; compute event rates (e.g., failed logins per second), throughput, and error percentages; read and interpret charts, dashboards, and KPIs; perform simple ROI or risk-reduction calculations for security improvements.
• Language ability: write clear incident reports, playbooks, and detection logic documentation; translate technical findings into concise, business-friendly language for leadership; understand and apply security policies, regulatory requirements, and compliance language; communicate effectively during incident response calls and cross-team coordination; create knowledge base articles and contribute to team learning.
Compensation
Compensation will be based on experience, qualifications, and market alignment. The total package includes a competitive base salary, annual incentive opportunity tied to personal and organizational performance, and comprehensive benefits consistent with UCCU's commitment to its employees.
Equal Opportunity Statement
UCCU is an Equal Opportunity Employer. We are committed to providing equal employment opportunities to all individuals without regard to race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, gender identity, or any other characteristic protected by applicable law.