A community-focused financial institution is seeking an Information Security Analyst to support a broad cybersecurity and technology-risk environment. This position combines hands-on security operations with vulnerability management, IAM, incident response, cloud and SaaS security, third-party risk, data protection, security governance, and regulatory support.
The analyst will also participate in the organization s evolving approach to AI and GenAI security, including assessment of new AI use cases and vendors, data and access risks, and appropriate controls, monitoring, and governance.
RESPONSIBILITIES- Investigate security events and alerts across endpoints, networks, identity systems, email, cloud services, and enterprise applications.
- Support vulnerability scanning, remediation prioritization, configuration reviews, penetration-test findings, and corrective-action tracking.
- Participate in cybersecurity incident response, root-cause reviews, evidence collection, tabletop exercises, and post-incident improvement.
- Support identity and access controls including MFA, role-based access, privileged access, service accounts, and periodic certifications.
- Review security risks associated with cloud/SaaS services, technology implementations, APIs, integrations, and third-party vendors.
- Support information-security policies, control evidence, risk registers, audit requests, security metrics, and regulatory activities.
- Assist with data-protection controls including classification, encryption, DLP, secure transfer, and sensitive-data handling.
- Help evaluate security considerations associated with AI and GenAI platforms and use cases.
Role Requirements- Bachelor s degree in cybersecurity, information technology, computer science, MIS, or a related discipline, or equivalent relevant professional experience.
- Relevant experience in information security, cybersecurity operations, technology risk, systems administration, IT audit, or GRC.
- Working knowledge of Windows, Linux, TCP/IP, DNS, firewalls, VPN technologies, identity systems, Microsoft 365, endpoints, and cloud/SaaS environments.
- Practical experience in multiple areas such as security monitoring, vulnerability management, incident response, IAM, third-party risk, security awareness, or GRC.
- Familiarity with cybersecurity control and risk frameworks such as NIST CSF, CIS Controls, or MITRE ATT&CK.
- Understanding of security and privacy requirements relevant to regulated environments.
- Working knowledge of AI/GenAI security concepts, including data exposure, access control, prompt-injection risk, logging, and human oversight.
- Strong communication and documentation skills.
PREFERRED EXPERIENCE- Banking, financial-services, or another regulated-industry background.
- Azure or AWS security experience.
- SQL, Power BI, Excel, PowerShell, Python, APIs, or security-workflow automation.
- Experience securing core business or financial applications.
- Security+, CySA+, SSCP, CISA, CISSP, GIAC, Microsoft, or AWS security certification.