Cybersecurity Analyst
Michigan Schools and Government Credit Union Troy, Michigan, United States · $79K/yr
Banking · 201-500 employees
About the role
The Cybersecurity Analyst safeguards the technology environment through daily security operations, including patching, vulnerability management, and alert monitoring. They also conduct incident investigations and assist with internal and external security audits to ensure compliance.
What they look for
Requirements
Candidates should have at least 3 years of experience in cybersecurity or system administration and a bachelor's degree in a related field is preferred. Professional certifications such as CISSP, SSCP, or CISA are also highly desired.
Benefits
Full description
Founded by a small group of educators, Michigan Schools & Government Credit Union (MSGCU) has been providing quality financial services to the community for more 70 years and welcomes everyone in Michigan to bank with us. We are financial champions committed to helping our members achieve financial success by rallying behind them and their goals. As the sixth largest Credit Union in Michigan, MSGCU has 24 branch offices in south east Michigan, over 450 team members, 150,000 members, $4 billion in assets, and a 97% member satisfaction rating for two decades. We are a caring organization that strives to ensure an equitable and inclusive culture where everyone is valued and respected. Our dedication to team member engagement has contributed to the honor of being named a Top Workplace by The Detroit Free Press thirteen years in a row.
If you have a passion for helping people and providing exceptional and dependable service, we want you on our team!
Information about our comprehensive total rewards package can be found here.
Overview of Responsibilities: Safeguards MSGCU’s technology environment through daily security operations, including patching, vulnerability management, alert monitoring, and incident investigation to ensure a secure and compliant infrastructure.
- Security Reviews: Performs regular reviews of system and application security controls to ensure settings, configurations, and protective technologies remain aligned with organizational standards. Validates the health and effectiveness of endpoint security tools, anti-malware protections, encryption settings, and other required safeguards. Reviews and assesses firewall rules and related configurations to ensure they reflect current security expectations and support policy compliance. Provides recommendations for strengthening security controls and partners with subject matter experts to implement security related changes.
- Continuous Monitoring and Incident Response: Monitors security alerts, system logs, and threat notifications to identify unusual activity or indicators of compromise with assistance of managed services. Conducts initial and mid-level incident response activities, including containment steps, user communication, and documentation of actions taken. Supports full investigations when necessary by gathering evidence, analyzing behavior patterns, and collaborating with subject matter experts to determine root cause and long-term corrective action. Maintains records of incidents and response steps to support trend analysis and future prevention.
- Patch and Vulnerability Management: Installs and validates security patches across servers, virtualized environments, workstations, and applications to ensure updates are applied consistently and within established maintenance windows. Reviews vulnerability reports and determines appropriate prioritization based on risk and system exposure. Assigns remediation tasks to subject matter experts when required and monitors progress to ensure gaps are addressed in a timely manner. Maintains documentation of patching cycles, remediation decisions, and outstanding risks to support future analysis and ongoing improvement.
- Audit and Compliance: Assists with internal and external security audits by preparing required documentation, reports, and supporting evidence. Conducts assessments to identify security gaps and helps develop mitigation plans to address areas of non-compliance. Responds to audit inquiries by providing accurate, timely information on existing controls, system protections, and implemented security measures. Coordinates with subject matter experts to ensure audit commitments and remediation timelines are met.
Core Competencies:
- Member Focus: Uses active listening skills to gain insight and understanding into the needs of stakeholders and members in order to troubleshoot, and develop secure member-focused technology solutions.
- Tech Savvy: Understands emerging technology capabilities and assesses how they could be adapted to benefit MSGCU. Readily learns and adopts new technologies.
- Manages Complexity: Understands complex systems and data flows and asks the right questions to analyze situations, uncover root causes, and solve problems.
- Action Oriented: Willingly takes on new opportunities and tough challenges with a sense of urgency and enthusiasm. Exhibits confidence under pressure and bounces back from setbacks.
- Plans and Aligns: Plans work appropriately prior to taking action and effectively prioritizes work to meet commitments. Develops appropriate contingency plans.
- Communicates Effectively: Communicates effectively with technical and non-technical audiences, effectively explaining feasible courses of action and providing actionable feedback to keep projects moving forward.
- Instills Trust: Gains the confidence of others by modeling honesty, integrity, authenticity and behaviors that align with organizational values. Exemplifies courage by stepping up to address difficult issues.
- Self-Development: Actively seeks new ways to grow and be challenged using formal and informal development channels and applies lessons learned from hardships and mistakes.
Education and Experience Requirements:
- Bachelor’s degree in Computer Information Systems, Business Administration or related field preferred.
- 3 years of experience in cybersecurity or system administration required. Experience in patching, vulnerability management, or SIEM-based security monitoring preferred.
- Certified Information Systems Security Professional (CISSP), Systems Security Certified Practitioner (SSCP), Certified Information Systems Auditor (CISA) or similar certifications preferred.
Working Conditions:
- Office and branch location environment with little discomfort from noise, extreme temperature, dust, or other factors.
- Occasionally required to travel throughout MSGCU's service area as business needs require.
- Exposed to potentially hazardous conditions, such as robbery. Receives detailed instructions and security procedures on an annual basis to minimize risk.
- This work involves sitting most of the time with brief periods of walking or standing and may occasionally require lifting and/or moving up to 30 pounds.
- Normal working hours will be MSGCU’s standard branch and administrative office hours of operation, however, occasional after-hours maintenance and flexibility to be on call before/after normal work hours, including weekends and holidays, is required.
Compensation and Benefits:
Competitive salaries are just the starting point for MSGCU team members. Generous health benefits, vacation time, retirement plan contributions and discounts on loans and phone service also come with the job.
- Base salary starts at $79,000 / year
- Medical, dental and vision on your first day! You can choose the most generous Health Savings Account (HSA)-eligible medical plan with no monthly premium for you (and your family)
- If you are at least 21 years old, you will receive a 3% contribution from MSGCU, and a 100% match for the next 7% you contribute to your 401(k)
- You will enjoy 12 paid holidays and up to 120 hours of PTO your first year of service (pro-rated based on start date)
Similar roles
-
GNMA IAISO Cybersecurity Program Manager
Crest Security Assurance $150K–$160K/yr
-
Cyber Security Engineer I
Durango Casino & Resort Las Vegas, Nevada, United States
-
IT Security Engineer / Penetration Tester 60% - 100% (m/w/d)
KastGroup GmbH Wallisellen, Zurich, Switzerland
-
Cybersecurity Compliance Analyst
RCG Suitland, Maryland, United States · $115K–$125K/yr
-
Security Engineer I
S.P. Richards Company Atlanta, Georgia, United States
-
Senior Cyber Security Engineer - Network Security (CISSP)
H&M Group Stockholm, Stockholm, Sweden