Information Security Analyst II (GRC)
Meritrust Credit Union · Broomfield, CO · 2 wk ago
On-siteInformation TechnologyFull-time
Benefits
- Comprehensive medical insurance plan
- Dental and vision insurance
- Generous paid-time-off
- 12 paid holidays
- Annual discretionary bonus based on achievement of organizational scorecard results
- 401(k) plan
- Wellness program
- Tuition assistance
- Employee loan discount
- Employee Assistance Program (EAP)
- Life and disability coverage
What Sets Meritrust Apart
- Career development and pathing opportunities to move into leadership roles or other lines of business within Meritrust Credit Union, such as Commercial Lending, Finance, Marketing, Underwriting, Member Solutions, Training, and Human Resources
- Supportive and engaging work environment
- Wellness and sustainable work culture that prioritizes family, community, and health
- Work environment encouraging personal and professional growth, teamwork, and equal treatment
Schedule
Full-time position, 40 hours per week, Monday–Friday, 8:00 AM–5:00 PM.
Responsibilities
Governance
- Stay current with financial regulations such as FFIEC guidelines, NCUA requirements, and other compliance regulations
- Familiar with information security frameworks such as PCI DSS, NIST 800-53, FedRAMP, ISO 27001, CIS, MITRE ATT&CK, OWASP Top 10, etc.
- Build and integrate security frameworks into the Meritrust Credit Union (MCU) Information Security Program, ensuring organizational compliance
- Develop, implement, and maintain policies, standards, and procedures to align with MCU security objectives and industry best practices
- Design and conduct employee training on compliance, information security, and risk management topics, focusing on safeguarding MCU assets, including member data
Risk Management
- Perform risk assessments to identify and mitigate risks related to member data, application security, and security tool health checks
- Analyze and document identified risks, providing actionable mitigation recommendations
- Support the Information Security Incident Response Plan (ISIRP), Business Continuity and Disaster Recovery (BC/DR) plans, and assist in tabletop exercises to ensure operational resilience
Compliance
- Monitor and support compliance efforts related to regulations and frameworks such as NCUA, NIST, ISO, PCI DSS, CIS, MITRE ATT&CK, OWASP Top 10, and other relevant frameworks
- Assist with internal and external audits and regulatory examinations, providing required evidence and ensuring timely remediation of findings
- Conduct regular testing of controls in security policies to ensure effectiveness and alignment with regulatory requirements
- Manage findings from audits, risk assessments, and security policy control testing, documenting resolutions and tracking remediation progress
- Participate in the exceptions management process, conducting documentation, risk acceptance, and periodic reviews of exceptions
- Monitor phishing reports and InfoSec tickets submitted by employees, ensuring proper investigation, resolution, and follow-up
Collaboration & Reporting
- Collaborate with IT, compliance/risk management, and operational teams to align cybersecurity objectives with MCU security goals
- Provide regular reporting to leadership on the cybersecurity program status, compliance gaps, and risk trends specific to the credit union sector
- Design, implement, and update InfoSec performance metrics and key risk indicators (KRIs) to measure the maturity and effectiveness of the security program
- Act as a resource for employees on GRC-related inquiries to promote a culture of compliance and security awareness