Cybersecurity Analyst
Financial Plus Credit UnionDescription
Job Title: Cybersecurity Analyst
Department: Information Technology
Reports to: Director of IT
Hours per Week: 40 hrs./week Salary Exempt
Company Summary
Welcome to Financial Plus Credit Union (FPCU)- The Place that brings Dreams within Reach.
At FPCU, our mission is simple but powerful: Empowering people and communities to strive for more through knowledge, innovation, and service that brings dreams within reach. We are more than a financial institution. We are a growth engine for our members, our teams, and our communities.
We are a purpose-driven organization grounded in five values: represent with purpose, empower through knowledge, appreciate and accept, champion new possibilities, and help make things easier.
FPCU is a team of high performers who care deeply, support each other, work hard, and continuously push forward. We don’t just show up, we represent our purpose every day and every time we interact with our members and teammates. We invest in our people, challenge them to grow, and support them in becoming the best version of themselves.
Joining FPCU means leveling up your career. If you are someone who thrives in a fast-paced, positive, and purpose-driven culture, and you’re ready to grow with an organization that is actively evolving, we want you to join the team!
Position Summary
Financial Plus Credit Union is seeking a hands-on Cybersecurity Analyst with a strong infrastructure background to help protect our members, systems, and data. This individual contributor will own day-to-day security operations across our endpoint, network, and cloud environments – including vulnerability management, patching, and hardening of Microsoft 365 and Azure. The ideal candidate blends deep infrastructure knowledge with practical security experience and thrives in a fast-paced financial services environment governed by regulatory and audit requirements.
Essential Functions & Primary Responsibilities
The candidate will own day-to-day security operations and help embed security across the credit union’s infrastructure, endpoint, network, and cloud environments.
This includes, but is not limited to:
· Administer, tune, and monitor the organization’s security stack (e.g., Cato SASE and/or CrowdStrike EDR/XDR), responding to alerts, investigating incidents, and driving remediation.
· Lead the vulnerability management lifecycle – scanning, triaging, prioritizing, and tracking remediation of vulnerabilities across servers, endpoints, and cloud workloads.
· Own and improve the patch management program, ensuring operating systems, applications, and infrastructure are consistently updated and compliant.
· Harden and secure Microsoft 365 (Exchange Online, SharePoint, Teams, Entra ID) using secure baselines, conditional access, and MFA.
· Administer and mature Microsoft Purview capabilities, including Data Loss Prevention (DLP), sensitivity labels, retention policies, audit logging, eDiscovery support, insider risk signals, and compliance evidence collection to protect member and organizational data.
· Manage Microsoft Intune endpoint security responsibilities, including device compliance policies, configuration profiles, security baselines, device enrollment, conditional access integration, and remediation of non-compliant endpoints.
· Configure, monitor, and secure Microsoft Azure resources, applying cloud security best practices, identity governance, and least-privilege access.
· Apply and enforce security best practices including network segmentation, endpoint protection, logging, monitoring, and configuration management.
· Administer and maintain firewall policies, including rule reviews, segmentation controls, VPN/security access, logging, and coordination of network security changes.
· Develop, review, and enforce Group Policy settings to support secure workstation and server configurations, hardening standards, and consistent endpoint controls.
· Manage email security controls, including phishing protection, attachment and URL defense, quarantine review, policy tuning, and investigation of suspicious messages.
· Coordinate security awareness training and phishing simulation activities, including user education, campaign support, reporting, and follow-up guidance for employees.
· Leverage APIs and base scripting in PowerShell, Bash, and Python to automate security operations, integrate tooling, extract and correlate data, and streamline repetitive tasks across on-premises and cloud environments.
· Support security audits, examinations, and assessments by gathering evidence, documenting controls, and helping remediate findings for regulatory and audit bodies.
· Contribute to security policies, standards, and procedures, and promote security awareness across the organization.
· Assist with incident response activities, including detection, containment, eradication, recovery, and post-incident reporting.
· Collaborate with infrastructure and application teams to embed security into projects, migrations, and new technology rollouts.
· Must be flexible and able to work unusual and variable hours/schedules, without supervision, including but not limited to holidays, evenings or weekends.
· Enforces compliance with all federal and state laws and regulations, including the Bank Secrecy Act (BSA), Patriot Act, and Office of Foreign Asset Controls (OFAC) requirements, and should request legal interpretation as necessary to identify compliance concerns.
· Adhere to applicable federal and state laws, regulations, and internal compliance with standard polices relevant to their roles and responsibilities.
· Perform other duties as assigned.
Requirements
Education & Qualifications
· 5+ years of experience in an infrastructure or security role, with a heavy infrastructure background (servers, networking, endpoints, identity).
· Hands-on experience with a modern security stack such as Cato Networks (SASE/SSE) or CrowdStrike (EDR/XDR).
· Base scripting proficiency in PowerShell, Bash, and Python for automation, data parsing, and security tooling.
· Demonstrated experience with vulnerability management and patch management programs and tooling.
· Working knowledge of Microsoft 365 administration and security hardening.
· Hands-on experience securing and administering Microsoft Azure.
· Solid understanding of security best practices, frameworks, and controls across on-premises and cloud environments.
· Strong analytical, documentation, and communication skills with the ability to work independently as an individual contributor.
Preferred Qualifications:
· Experience in financial services and familiarity with related audit and regulatory bodies (e.g., NCUA, state examiners, external auditors).
· CompTIA Security+ certification (or equivalent security certification).
· Experience securing artificial intelligence (AI) tools, services, and data – including responsible AI usage and governance.
· Experience assessing risk and creating qualitative and quantitative risk assessments to evaluate and prioritize security exposures.
· Additional certifications such as Microsoft SC-200/AZ-500, CrowdStrike, or Cato administration credentials.
Skills and Abilities
· Infrastructure and cloud security across on-premises, Microsoft 365, and Azure environments.
· Vulnerability and patch management, including scanning, prioritization, and remediation tracking.
· Endpoint and network defense, including EDR/XDR, SASE/SSE, firewall, and segmentation controls.
· Microsoft security tooling, including Purview (DLP, sensitivity labels), Intune, and Entra ID.
· SIEM administration, log monitoring, and correlation to support detection and incident response.
· Base scripting and automation with PowerShell, Bash, and Python.
· Detail-oriented and self-directed, with a strong audit and compliance mindset.
· Clear documentation and communication skills across technical and non-technical audiences.
· Represents FPCU with professionalism and purpose, communicating with members through respectful and solution-focused verbal and written communications that support a member-focused experience.
· Engages in effective interpersonal communication, diplomacy, and collaboration skills to develop productive relationships, encourage cooperation, and support positive member and employee experiences. Maintains compliance with all applicable policies, demonstrating integrity, respect, and accountability while handling sensitive information and complying with FPCU policies, regulatory expectations, and confidentiality requirements.
· Ability to apply logistical reasoning, analytical skills, and professional judgment to define and solve problems with effective and compliant solutions.
· Adaptable, resilient, and comfortable navigating change in a fast-moving environment
· Embraces innovation and continuously seeks better ways to serve members and support teams
Physical Demands & Work Environment
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. The work environment characteristics described here are representative of those an employee encounters while performing the essential functions. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
· Sedentary work; sitting most of the time. May occasionally exert up to 50+ pounds of force.
· The noise level in the work environment is professional and typically moderate.
Additional Information
This job description is not a complete statement of duties and responsibilities. Responsibilities may evolve based on opportunities and development for business growth.
At Financial Plus Credit Union, everything we do is a commitment to representing, appreciating, and empowering every member and employee—every day, every time. If you are a high performer who is ready to grow, contribute, and be part of something bigger, we invite you to level up your career with us.