Information Security Analyst

Cybersecurity Jobs

Nashville (TN)

On-site

USD 85,000 - 125,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Thread Bank seeks an Information Security Analyst to operate the information security program onsite in Nashville, focusing on identity and access governance, vulnerability monitoring, incident response support, risk assessment, and audit evidence. The role covers AWS, Entra ID, and Microsoft 365, with a strong emphasis on documenting remediation and closure.

The candidate will support security outcomes across internal systems, cloud, digital banking products, and embedded banking connections,

Qualifications

  • Bachelor’s degree in information security, IT, computer science, or a related field is required or equivalent practical experience.
  • Three or more years of experience in information security, IT risk, or security consulting.
  • Knowledge of NIST CSF and NIST SP 800-53, translating control language into technical checks and evidence.
  • Hands-on experience with vulnerability scanning, log review, and cloud/infrastructure security.
  • Experience with Windows, Linux, directory services like Active Directory or Entra ID, and network fundamentals.

Responsibilities

  • Execute quarterly user access reviews across AWS accounts, Entra ID, SharePoint, and in-scope apps.
  • Reconcile system access with HR roster, flag exceptions, drive corrections, and obtain owner sign-off.
  • Perform segregation of duties checks and escalate conflicts to the ISO.
  • Maintain privileged credential inventory, monitor rotation, and review shared/admin accounts.
  • Process access requests, transfers, and terminations per Bank approvals.
  • Run recurring vulnerability scans and cloud configuration assessments across AWS and MS 365.
  • Triage findings by severity, assign remediation owners, and track against remediation schedule.
  • Verify remediation closed exposure and retain closure evidence.
  • Monitor external attack surface (certificates, exposed services, domains, APIs).
  • Escalate overdue findings to ISO with recommended actions.
  • Act as first responder for security alerts and mgmt detection providers.
  • Support incident response activities: triage, containment, evidence preservation, timelines, after-action.
  • Support incident analysis at providers/partners where Thread data/systems may be affected.
  • Track regulatory notification timelines during incidents and prepare records for ISO decisions.
  • Assess controls against NIST CSF and NIST SP 800-53; document gaps and treatment.
  • Support security review of new products, apps, integrations, infra changes pre-production.
  • Maintain information asset inventory and data classification records.
  • Test design and operating effectiveness of controls; document results for auditors/examiners.
  • Assemble and quality-check evidence for internal/external audits and regulatory exams.
  • Track audit findings through closure, with supporting docs.
  • Produce recurring program metrics and Board reporting materials.
  • Maintain information security policies and annual review cycles.
  • Run phishing simulations, report trends; deliver security awareness training and track completion.
  • Provide targeted training to teams handling sensitive customer information.
  • Perform additional responsibilities as directed by ISO.

Skills

NIST CSF
NIST SP 800-53
Vulnerability scanning
Log review
Cloud security
Windows
Linux
Active Directory / Entra ID

Education

Bachelor’s degree in information security, IT, CS, or related field
Master’s degree in cybersecurity or related field
CISSP
CISA
CRISC
GIAC Security+
AWS Certified Security

Tools

AWS IAM
GuardDuty
Security Hub
Inspector
Cloud posture management
Purview
Microsoft Entra ID

Job description

Thread Bank is seeking an Information Security Analyst to help operate the organization’s information security program under the direction of the Information Security Officer. This Nashville, TN onsite role focuses on recurring operational security work across identity and access governance, vulnerability and configuration monitoring, incident response support, risk assessment and control testing, audit evidence, and security awareness activities.

The position supports security outcomes across internal systems, cloud infrastructure, digital banking products, and technology connections for embedded banking programs, with an emphasis on driving issues through to documented closure.

Responsibilities
  • Execute quarterly user access reviews across Amazon Web Services accounts, Microsoft Entra ID, SharePoint, and other in-scope applications
  • Reconcile system access against the HR roster, flag exceptions, drive corrections, and obtain documented owner sign-off
  • Perform segregation of duties checks and elevate conflicts to the ISO
  • Maintain the privileged credential inventory, monitor rotation schedules, and review check-out activity for shared and administrative accounts
  • Process access requests, transfers, and terminations according to the Bank’s approval requirements
  • Run recurring vulnerability scans and cloud configuration assessments across the Bank’s AWS organization and Microsoft 365 tenant
  • Triage findings by severity, assign remediation owners, and track each finding against the Bank’s remediation schedule
  • Verify remediation closed the exposure and retain closure evidence
  • Monitor the external attack surface, including certificates, exposed services, domains, and application programming interfaces
  • Escalate overdue and recurring findings to the ISO with a recommended course of action
  • Act as a first responder for security alerts, including tickets raised by the Bank’s managed detection and response provider
  • Support incident response activities such as triage, containment support, evidence preservation, timeline construction, and after-action documentation
  • Support incident analysis at technology providers and program partners where Thread data, systems, or connectivity may be affected
  • Track regulatory and contractual notification timelines during an incident and prepare supporting records for ISO notification decisions
  • Assess controls against NIST CSF and NIST SP 800-53, document gaps, and recommend treatment
  • Support security review of new products, applications, integrations, and infrastructure changes before production deployment
  • Maintain the information asset inventory and data classification records in support of the Bank’s Data Governance Policy
  • Test the design and operating effectiveness of assigned controls and document results for auditors and examiners
  • Assemble and quality-check evidence for internal audit, external audit, and regulatory examinations
  • Track audit and examination findings assigned to Information Security through to closure, including supporting documentation
  • Produce recurring program metrics and reporting for the ISO, including material supporting management and Board reporting
  • Maintain information security policies, standards, and procedures and support the annual review cycle
  • Run the phishing simulation program, track results, and report trends
  • Administer annual security awareness training, monitor completion, and follow up on outstanding assignments
  • Deliver targeted training to teams that handle sensitive customer information
  • Perform additional responsibilities assigned by the Information Security Officer or based on business needs
Requirements
  • Located in Nashville, Tennessee, In Office, M-F
  • Bachelor’s degree in information security, information technology, computer science, or a related field, or equivalent practical experience
  • Three or more years of experience in information security, IT risk, or security consulting
  • Working knowledge of NIST CSF and NIST SP 800-53, with the ability to translate control language into specific technical checks and documented evidence
  • Hands-on experience with vulnerability scanning, log review, and enterprise or cloud infrastructure security
  • Practical experience with Windows, Linux, directory services such as Active Directory or Entra ID, and network fundamentals
  • Strong written communication skills to produce documentation reviewed by auditors, examiners, and executives
  • Demonstrated follow-through on remediation work, not assessment work alone
  • Ability to handle confidential customer and Bank information appropriately and meet background screening requirements applicable to employees of a financial institution
  • Experience at a bank, credit union, or other regulated financial institution
  • Familiarity with GLBA Safeguards requirements, FFIEC Information Technology Examination Handbooks, and regulatory incident notification requirements
  • AWS security experience, including IAM, GuardDuty, Security Hub, Inspector, and cloud posture management
  • Microsoft 365 and Entra security experience, including Purview
  • Master’s degree in cybersecurity or a related field
  • Industry certification such as CISSP, CISA, CRISC, a GIAC certification, CompTIA Security+, or AWS Certified Security
  • Scripting ability in Python or PowerShell
  • Experience supporting secure software development practices, including static analysis, dependency scanning, and secret detection
Technologies
  • Amazon Web Services (AWS)
  • Microsoft Entra ID
  • SharePoint
  • Microsoft 365
  • Active Directory
  • NIST CSF
  • NIST SP 800-53
  • AWS IAM
  • AWS GuardDuty
  • AWS Security Hub
  • AWS Inspector
  • Cloud posture management
  • Purview
  • Windows
  • Linux
  • Python
  • PowerShell
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Officer
Information Security Officer

City First Bank • Inglewood (CA)

On-site
USD 100,000 - 140,000
InfoSec Analyst — Cloud, IAM & Incident Response
InfoSec Analyst — Cloud, IAM & Incident Response

Cybersecurity Jobs • Nashville (TN)

On-site
USD 85,000 - 125,000
Information Security Officer
Information Security Officer

City First Bank • Washington

On-site
USD 120,000 - 170,000
Information Systems Security Professional
Information Systems Security Professional

Vytwo • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Cyber Threat Intelligence Analyst I
Cyber Threat Intelligence Analyst I

BankUnited • Town of Florida (NY)

On-site
USD 120,000 - 180,000
Cyber Threat Intelligence Analyst I
Cyber Threat Intelligence Analyst I

bankunitedexternal • Town of Florida (NY)

On-site
USD 100,000 - 150,000
Principal Cyber Security Engineer - SSO/IAM (Remote)
Principal Cyber Security Engineer - SSO/IAM (Remote)

First Citizens Bank • Raleigh (NC)

On-site
USD 120,000 - 180,000
Security Analyst
Security Analyst

Koitecc Solutions • Atlanta (GA), Northern (KY)

Hybrid
USD 90,000 - 125,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

On-site
USD 80,000 - 110,000
Cyber Security Engineer III
Cyber Security Engineer III

First Citizens Bank • North Carolina

On-site
USD 110,000 - 150,000