Information Security Analyst II (GRC)

Meritrust Credit Union

Wichita, Broomfield (KS, CO)

On-site

USD 78,068 - 97,585

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Comprehensive medical insurance plan
Dental and vision insurance
Generous paid‑time‑off
12 paid holidays
Annual discretionary bonus based on组织
401(k) plan
Wellness program
Tuition assistance
Employee loan discount
Employee Assistance Program (EAP)
Life and disability coverage

Job summary

Meritrust Credit Union seeks an experienced Governance, Risk, and Compliance (GRC) professional to lead information security initiatives within the MCU Information Security team. The role reports to the AVP, Security Analysis and collaborates with Risk and Compliance to meet regulatory requirements and risk tolerance.

You will oversee security training, policy reviews, controls, and risk assessments, ensuring MCU assets and member data are safeguarded while aligning with FFIEC, NIST, ISO, PCI

Qualifications

  • Associate’s or Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent experience
  • Entry level security certifications such as CompTIA Security+, SSCP, or similar preferred or willingness to obtain
  • Basic understanding of information security concepts, principles, and best practices
  • Familiarity with security frameworks and standards such as PCI DSS, NIST, CIS, and OWASP
  • Basic knowledge of Microsoft Windows desktop and server environments
  • Introductory knowledge of Linux operating systems
  • Fundamental understanding of networking concepts and protocols
  • Awareness of common cybersecurity threats, vulnerabilities, and attack methods
  • 0 to 2 years of experience in IT, cybersecurity, or a related technical role
  • Experience supporting IT systems, help desk, infrastructure, or security operations preferred
  • Exposure to regulated environments (financial services preferred) is a plus
  • Learning Orientation: Willingness to learn and grow within the information security field
  • Technical Skills: Basic experience with security tools such as endpoint protection, vulnerability scanners, or log monitoring platforms preferred
  • Documentation Skills: Ability to follow established procedures and document work accurately
  • Analytical Skills: Strong analytical and troubleshooting skills
  • Communication Skills: Good written and verbal communication skills
  • Service Orientation: Strong customer service mindset and ability to work collaboratively with others
  • Organizational Skills: Ability to manage multiple tasks and prioritize work effectively

Responsibilities

  • Stay current with Financial Regulations such as FFIEC guidelines, NCUA requirements, and other compliance regulations
  • Familiar with Information Security Frameworks such as PCI DSS, NIST=800-53, FedRAMP, ISO=27001, CIS, MITRE ATTCK, OWASP Top 10, etc.
  • Build and integrate the security frameworks into the MCU Information Security Program, ensuring organizational compliance
  • Develop, implement, and maintain policies, standards, and procedures to ensure alignment with MCU security objectives and industry best practices
  • Design and conduct employee training on compliance, information security, and risk management topics with a focus on safeguarding MCU assets, including member data
  • Perform risk assessments to identify and mitigate risks related to member data, application security, and security tool health checks
  • Analyze and document identified risks, providing actionable mitigation recommendations
  • Support the Information Security Incident Response Plan (ISIRP), Business Continuity and Disaster Recovery (BC/DR) plans and assist tabletop exercises to ensure operational resilience
  • Monitor and support compliance efforts related to regulations and frameworks such as NCUA, NIST, ISO, PCI DSS, CIS, MITRE ATTCK, OWASP Top 10, and other relevant frameworks
  • Assist with internal and external audits and regulatory examinations, providing required evidence and ensuring timely remediation of findings
  • Conduct regular testing of controls in security policies to ensure effectiveness and alignment with regulatory requirements
  • Manage findings from audits, risk assessments, security policies control testing, documenting resolutions and tracking remediation progress
  • Participate in the exceptions management process, conducting documentation, risk acceptance, and periodic reviews of exceptions
  • Monitor phishing reports and InfoSec tickets submitted by employees, ensuring proper investigation, resolution, and follow-up
  • Collaborate with IT, compliance/risk management, and operational teams to align cybersecurity objectives with MCU security goals
  • Provide regular reporting to leadership on the cybersecurity program status, compliance gaps, and risk trends specific to the credit union sector
  • Design, implement, and update InfoSec performance metrics and key risk indicators (KRIs) to measure the maturity and effectiveness of the security program
  • Act as a resource for employees on GRC‑related inquiries to promote a culture of compliance and security awareness

Skills

Learning Orientation
Technical Skills
Documentation Skills
Analytical Skills
Communication Skills
Service Orientation
Organizational Skills

Education

Bachelor's degree in CS/IT/Cybersecurity
Security Certifications preferred

Tools

Endpoint protection
Vulnerability scanners
Log monitoring platforms

Job description

Job Details
  • Level: Experienced
  • Location: BROOMFIELD, CO 80021
  • Position Type: Full Time
  • Education Level: 4 Year Degree
  • Salary Range: $78,068.04 - $97,585.05
  • Travel Percentage: Negligible
  • Job Shift: Day
  • Job Category: Banking
Benefits
  • Comprehensive medical insurance plan
  • Dental and vision insurance
  • Generous paid‑time‑off
  • 12 paid holidays
  • Annual discretionary bonus based on achievement of organizational scorecard results
  • 401(k) plan
  • Wellness program
  • Tuition assistance
  • Employee loan discount
  • Employee Assistance Program (EAP)
  • Life and disability coverage
What Sets Us Apart
  • Career development and pathing opportunities to move into leadership roles or other lines of business within MCU such as Commercial Lending, Finance, Marketing, Underwriting, Member Solutions, Training, Human Resources, and more
  • Supportive and engaging work environment
  • A wellness and sustainable work culture that puts family, our community, and your health first
  • Work environment that encourages personal as much as professional growth, teamwork to make the dream work, and treating everyone equally
  • We are most interested in finding the best candidate, and encourage applications even if you do not meet every qualification listed
Employment Details

This is a full‑time position working 40 hours a week, Monday‑Friday 8:00am – 5:00pm.

Position Summary

Responsible for executing the Governance, Risk, and Compliance (GRC) program within Information Security team for Meritrust Credit Union (MCU). The position reports to the AVP, Security Analysis. The role works closely with the Risk and Compliance department to ensure MCU meets regulatory requirements and organizational risk tolerance. This position maintains all operational tasks within the information security portfolio including security training, building and reviewing security policies and controls, conducting risk reviews of systems and ensuring compliance with information security best practices.

Essential Functions
Governance
  • Stay current with Financial Regulations such as FFIEC guidelines, NCUA requirements, and other compliance regulations
  • Familiar with Information Security Frameworks such as PCI DSS, NIST=800-53, FedRAMP, ISO=27001, CIS, MITRE&ATTCK, OWASP Top 10, etc.
  • Build and integrate the security frameworks into the MCU Information Security Program, ensuring organizational compliance
  • Develop, implement, and maintain policies, standards, and procedures to ensure alignment with MCU security objectives and industry best practices
  • Design and conduct employee training on compliance, information security, and risk management topics with a focus on safeguarding MCU assets, including member data
Risk Management
  • Perform risk assessments to identify and mitigate risks related to member data, application security, and security tool health checks
  • Analyze and document identified risks, providing actionable mitigation recommendations
  • Support the Information Security Incident Response Plan (ISIRP), Business Continuity and Disaster Recovery (BC/DR) plans and assist tabletop exercises to ensure operational resilience
Compliance
  • Monitor and support compliance efforts related to regulations and frameworks such as NCUA, NIST, ISO, PCI DSS, CIS, MITRE&ATTCK, OWASP Top 10, and other relevant frameworks
  • Assist with internal and external audits and regulatory examinations, providing required evidence and ensuring timely remediation of findings
  • Conduct regular testing of controls in security policies to ensure effectiveness and alignment with regulatory requirements
  • Manage findings from audits, risk assessments, security policies control testing, documenting resolutions and tracking remediation progress
  • Participate in the exceptions management process, conducting documentation, risk acceptance, and periodic reviews of exceptions
  • Monitor phishing reports and InfoSec tickets submitted by employees, ensuring proper investigation, resolution, and follow-up
Collaboration & Reporting
  • Collaborate with IT, compliance/risk management, and operational teams to align cybersecurity objectives with MCU security goals
  • Provide regular reporting to leadership on the cybersecurity program status, compliance gaps, and risk trends specific to the credit union sector
  • Design, implement, and update InfoSec performance metrics and key risk indicators (KRIs) to measure the maturity and effectiveness of the security program
  • Act as a resource for employees on GRC‑related inquiries to promote a culture of compliance and security awareness
Qualifications

Education/Certification:

  • Associate’s or Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent experience
  • Entry level security certifications such as CompTIA Security+, SSCP, or similar preferred or willingness to obtain

Required Knowledge:

  • Basic understanding of information security concepts, principles, and best practices
  • Familiarity with security frameworks and standards such as PCI DSS, NIST, CIS, and OWASP
  • Basic knowledge of Microsoft Windows desktop and server environments
  • Introductory knowledge of Linux operating systems
  • Fundamental understanding of networking concepts and protocols
  • Awareness of common cybersecurity threats, vulnerabilities, and attack methods

Experience Required:

  • 0 to 2 years of experience in IT, cybersecurity, or a related technical role
  • Experience supporting IT systems, help desk, infrastructure, or security operations preferred
  • Exposure to regulated environments (financial services preferred) is a plus

Hard / Technical Skills & Abilities:

  • Learning Orientation: Willingness to learn and grow within the information security field
  • Technical Skills: Basic experience with security tools such as endpoint protection, vulnerability scanners, or log monitoring platforms preferred
  • Documentation Skills: Ability to follow established procedures and document work accurately
  • Analytical Skills: Strong analytical and troubleshooting skills
  • Communication Skills: Good written and verbal communication skills
  • Service Orientation: Strong customer service mindset and ability to work collaboratively with others
  • Organizational Skills: Ability to manage multiple tasks and prioritize work effectively
Working Conditions
  • Standard office conditions
  • Low to moderate noise
  • Limited lifting up to 30 lbs
Additional Information

This description has been reviewed to ensure that only essential functions and basic duties have been included. Peripheral tasks, only incidentally related to each position, have been excluded. Essential functions, requirements, skills, and abilities included have been determined to be the minimal standards required to successfully perform the positions. In no instance, however, should the duties, responsibilities, and requirements delineated be interpreted as all inclusive. Additional functions and requirements may be assigned by supervisors as deemed appropriate.

In accordance with the Americans with Disabilities Act, it is possible that requirements may be modified to reasonably accommodate disabled individuals. However, no accommodations will be made which may pose serious health or safety risks to the employee or others or which impose undue hardships on the organization.

The Credit Union believes that each employee makes a significant contribution to our success. That contribution should not be limited by the assigned responsibilities. Therefore, this job description is designed to outline primary duties, qualifications, and job scope, but not limit the incumbent. It is our expectation that each employee will offer his/her services wherever and whenever necessary to ensure the success of our endeavors.

Job descriptions are not intended as and do not create employment contracts. The organization maintains its status as an at‑will employer. Employees can be terminated for any reason not prohibited by law.

Final Compensation for this position will be determined by various factors such as relevant work experience, specific skills and competencies, education, certifications, and internal pay equity.

We anticipate this position to close within 30 days of posting. Please submit your application at your earliest convenience to be considered.

You may not check every box, or your experience may look a little different from what we've outlined, but if you think you can bring value to Meritrust Credit Union, we encourage you to apply!

Thank you for your interest in Meritrust Credit Union.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Administrator
Security Administrator

SAFE FCU • Sumter (SC)

On-site
USD 60,000 - 80,000
GRC Cybersecurity Analyst III
GRC Cybersecurity Analyst III

ICCU • Meridian (ID), Chubbuck (ID)

On-site
USD 105,000 - 150,000
GRC Security Analyst II — Risk & Compliance
GRC Security Analyst II — Risk & Compliance

Meritrust Credit Union • Wichita (KS), Broomfield (CO)

On-site
USD 78,000 - 98,000
Comprehensive medical insurance plan
Dental and vision insurance
Generous paid‑time‑off
+8
IT GRC Analyst II
IT GRC Analyst II

State Employees' Credit Union • Raleigh (NC)

On-site
USD 90,000 - 120,000
IT GRC Analyst II
IT GRC Analyst II

SECU • North Carolina

On-site
USD 80,000 - 110,000
Member Consultant - Boulder Gunbarrel
Member Consultant - Boulder Gunbarrel

Meritrust Credit Union • Boulder (CO)

On-site
Comprehensive medical insurance plan
Dental and vision insurance
Generous paid-time-off
+7
Sr. Cybersecurity Engineer
Sr. Cybersecurity Engineer

TEKsystems • Winston-Salem (NC)

Hybrid
USD 69,000 - 83,000
Medical, dental & vision
401(k) Retirement Plan
Life Insurance
+4
Security Engineer
Security Engineer

Sierra Central Credit Union • Yuba City (CA)

On-site
USD 120,000 - 145,000
Medical, Dental & Vision Insurance
Voluntary hospital indemnity, accident
Company Paid HRA
+6
Security Operations Manager - REMOTE
Security Operations Manager - REMOTE

Quorumfcu • Northern (KY)

Hybrid
USD 130,000 - 170,000
Health insurance
Life insurance
401k match
+6
Information Security Engineer
Information Security Engineer

Affinity Plus Federal Credit Union • Saint Paul (MN)

On-site
USD 93,000 - 121,000
Low-cost health insurance
401K matching 5%
Paid leave options
+1