logo inner

Sr. Information Security Analyst - REMOTE

Quorum Federal Credit UnionPurchase, New York, United StatesRemote, Onsite
This job is no longer open

Who is Quorum?


Quorum Federal Credit Union is a national employer of choice that attracts, develops, enables, and retains the right resources to drive the organization forward. We are a human-centered organization that delivers a positive work journey and is committed to enhancing the lives of our employees and helping them to grow personally and professionally. We offer a unique value proposition to employees including Total Rewards, Work Journey, Work Paradigm, and Q-DNA to improve work-life balance and help employees live happier, more productive lives while contributing to our mission.

Job Description Summary


The Sr. Information Security Analyst plays a pivotal role in safeguarding sensitive data and fortifying our technology infrastructure, networks, and systems against an ever-evolving landscape of cyber threats. As a result, this position demands a unique blend of hands-on IT technical engineering expertise and business acumen with a focus on developing and implementing robust cybersecurity policies, procedures, and controls.  In this role, you will have the opportunity to contribute to the organization’s cybersecurity roadmap and priorities as well as foster cybersecurity awareness, education, and training for employees.

Your analytical and problem-solving skills will be essential as you proactively monitor and assess cybersecurity threats, enabling you to implement effective mitigation measures and promptly resolve any information security issues that may arise.The Sr. Information Security Analyst will also partner with our outsourced Technology Managed Services Provider, ensuring strict oversight to guarantee the fulfillment of contracted services. You will collaborate on matters pertaining to security tools, network monitoring, endpoint data protection, identity management, vulnerability/patch management, and incident response, upholding the highest standards of security throughout our organization.

Key Job Responsibilities and Accountabilities


  • Oversees the development, execution of information security policies, procedures, and controls to protect our organization's information systems, networks, and the confidentiality of data assets and sensitive information.
  • Ensures compliance with relevant regulations and industry standards including activities such as conducting internal audits, coordinating external audits, and ensuring adherence to compliance requirements.
  • Drives continuous improvement by proactively identifying and addressing Information security risks and vulnerabilities.
  • Communicates and collaborates with key stakeholders, within IT, executive management, and external partners or vendors.

  • Monitors effectiveness of security tools / processes and reports on the status of security services related to: Endpoint Intrusion Detection/Response, Endpoint Anti-Virus Malware, Vulnerability, SIEM and Patch management, Firewall Rules, Email Anti-Spam Quarantine, DLP, Identity Management, etc.
  • Responsible to configure and manage security tools, where applicable.
  • Provides vendor management oversight with our Technology Managed Services provider and other security vendor services to ensure adequate processes and controls are in place to monitor, detect and prevent cybersecurity incidents and threats. Monitors adherence to established service level agreements in conjunction with our Information Security and Vendor Management Policies.
  • Monitors and analyzes threat intelligence sources and conducts periodic technology risk assessments to identify emerging threats and vulnerabilities. Maintains the IT cybersecurity risk register and associated remediation action plans.

  • Prepares and delivers regular status health reports on security operations, vulnerabilities and risks, phishing and other security  incident response activities, and compliance audit efforts to management. This includes tracking and communicating security-related information to relevant stakeholders as well as executive briefs to senior management.
  • Develops and implements Information Security education and awareness training programs across the organization.
  • Creates training materials, conducts regular training sessions, and measures the effectiveness of the training program.
  • Manages projects along with related communications and content to support deployment and employee training and awareness programs.

  • Monitors, analyzes, and reports on employee engagement and security awareness as well as provides recommendations to management for improvements.
  • Ensures cybersecurity awareness benefits are clearly visible and champions related efforts going forward across the organization.

  • Manages the employee Phishing testing program and related analytics and reporting to assess the success of the program.

  • Performs technology security architecture evaluations to assess for vulnerabilities and weaknesses, recommending appropriate security technologies and solutions to enhance the organization's security posture.
  • Manages changes related to technology upgrades and other changes to the information security environment.
  • Performs cybersecurity risk assessments related to implementation of new technology and recommends appropriate controls to mitigate risk.

  • Performs vendor due diligence information security risk assessments and SOC audit reviews.

  • Manages response and mitigation actions related to audit findings conducted by internal audit, regulatory agencies or by other third parties.
  • Monitors and audits Identity management and user access privileges across Active Directory, Azure and all Single Sign-on SSO connectors.
  • Functions as a project manager on departmental and/or organization wide projects. Leads discovery and information gathering sessions. Conducts analysis and presents business case to management encompassing benefits, risks, cost, and solution recommendation. Manages the project plan inclusive of tasks, assignees, and project status updates. Contributes subject matter expertise in his/her assigned area, executes deliverables, and ensures the team completes project deliverables as outlined based on the project scope and requirements.
  • Creates and maintains Information Security documentation (policies and procedure; end-user guides, system administrator guides, etc.) using clear and concise language.
  • Supports adherence and adoption of IT policies, procedures, and governance standards.
  • Performs additional duties as required.

Job Requirements, Competencies, and Skills


  • Bachelor’s degree in computer science, information technology or other related degree is strongly preferred, however a combination of education and related work experience may be considered.
  • The position has the following minimum requirements:
  • Seven plus years of Information Technology experience.
  • Four plus years of demonstrated “hands-on” information security engineering experience.
  • Two plus years of demonstrated “hands-on” experience running Azure Cloud security products and tools (e.g., MS Defender, XDR, Sentinel, Purview, Entra, Azure Logs, etc.).
  • Certified Information Systems Security Professional (CISSP) and or Certified Information Security Manager (CISM).

  • In-depth knowledge of security technologies and tools, such as networking, firewalls, intrusion detection and prevention systems, endpoint protection, Patching, vulnerability, DLP and identity Management tools and processes.

  • Technical knowledge and experience with Azure Cloud PaaS and SaaS technologies and M365 environments.

  • Knowledge of relevant regulations and standards, such as FFIEC, SOX, PCI, NIST or NCUA / OCC preferred.

  • Technical knowledge of Windows server and desktop operating systems and related technologies. Experience supporting virtualized environments, particularly Virtual Desktop Infrastructure using Citrix and Azure VMs.
  • Good understanding of network protocols (for example: TCP/IP, DNS, DHCP etc.)
  • Experience using ITIL Service Management based ticketing systems.
  • Excellent written communication and interpersonal skills, with demonstrated ability to formally package and present business case risk and or solutions to management stakeholders.
  • Results Driven, Adaptive Thinking, Digital Proficiency.
  • Excellent problem-solving, analytical, and time management skills.

  • Ability to provide IT service support and respond to incident alert notifications during off hours, on a rotational basis, is required.

  • Ability to physically lift, carry and install equipment weighing up to 25 lbs.

Environmental / Physical / Mental Requirements


  • Stable internet connection with speeds high enough for video conferencing and screen sharing. 
  • Smartphone with current iOS/Android OS  
  • Prolonged periods sitting at a workstation and working on a computer. 
  • Ability to communicate with coworkers and customers via email, chat, teleconference, and/or phone. 

Compliance/legal requirements


  • Quorum is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will be considered for employment without regard to race, color, religion, gender, sexual orientation, national origin, age, marital status, protected veteran status, or disability status.
  • Quorum will make reasonable accommodations in compliance with the Americans with Disabilities Act of 1990. Reasonable accommodations are available upon request for qualified individuals with disabilities throughout the application and employment process. 

**PLEASE NOTE**


We are not able to consider candidates for this role who reside in Montana, Nebraska, Rhode Island, or Puerto Rico


Salary Range: $100,000 to $115,000 annually.  Individual salary will vary based on skills and experience.  Discretionary incentive compensation may be available based on company and individual performance.


Benefits: Medical, Vision, Dental, Retirement Benefits, and Paid Time Off (PTO)


#LI-Remote

This job is no longer open

Life at Quorum Federal Credit Union

Quorum is a credit uniona member-owned, not-for-profit financial institution. We offer services similar to what you would expect from a bank, but unlike a bank, we do not answer to stockholders. Instead, we return profits to our members in the form of leading industry rates, services, and financial products. Founded in 1934 as the exclusive credit union for Kraft Foods employees, today we serve over 50 companies nationwide (Ogilvy, Avon, Mondelz International, Philip Morris, etc.) and have over 70,000 members living in all 50 states. We serve these members with both in-person and remote banking channels, including branch, call center, online and mobile banking, so banking is possible anywhere, any time. At Quorum, we focus on what we can do really well. We strive to offer a select portfolio of products that demonstrates our drive for excellence. Because quality products demand quality service, we make sure our members benefit from the expertise of a deeply knowledgeable and helpful team.
Thrive Here & What We Value1. Humancentered organization with a positive work journey2. Commitment to employee growth and wellbeing3. Total Rewards program for enhanced work-life balance4. Work Journey initiative5. Innovative Work Paradigm6. QDNA (Quality Development Needs Assessment) approach
Your tracker settings

We use cookies and similar methods to recognize visitors and remember their preferences. We also use them to measure ad campaign effectiveness, target ads and analyze site traffic. To learn more about these methods, including how to disable them, view our Cookie Policy or Privacy Policy.

By tapping `Accept`, you consent to the use of these methods by us and third parties. You can always change your tracker preferences by visiting our Cookie Policy.

logo innerThatStartupJob
Discover the best startup and their job positions, all in one place.
Copyright © 2024