Cybersecurity Analyst

Financial Plus Credit UnionFlint, MI
$85,000 - $95,000Onsite

About The Position

Financial Plus Credit Union is seeking a hands-on Cybersecurity Analyst with a strong infrastructure background to help protect our members, systems, and data. This individual contributor will own day-to-day security operations across our endpoint, network, and cloud environments – including vulnerability management, patching, and hardening of Microsoft 365 and Azure. The ideal candidate blends deep infrastructure knowledge with practical security experience and thrives in a fast-paced financial services environment governed by regulatory and audit requirements.

Requirements

  • 5+ years of experience in an infrastructure or security role, with a heavy infrastructure background (servers, networking, endpoints, identity).
  • Hands-on experience with a modern security stack such as Cato Networks (SASE/SSE) or CrowdStrike (EDR/XDR).
  • Base scripting proficiency in PowerShell, Bash, and Python for automation, data parsing, and security tooling.
  • Demonstrated experience with vulnerability management and patch management programs and tooling.
  • Working knowledge of Microsoft 365 administration and security hardening.
  • Hands-on experience securing and administering Microsoft Azure.
  • Solid understanding of security best practices, frameworks, and controls across on-premises and cloud environments.
  • Strong analytical, documentation, and communication skills with the ability to work independently as an individual contributor.

Nice To Haves

  • Experience in financial services and familiarity with related audit and regulatory bodies (e.g., NCUA, state examiners, external auditors).
  • CompTIA Security+ certification (or equivalent security certification).
  • Experience securing artificial intelligence (AI) tools, services, and data – including responsible AI usage and governance.
  • Experience assessing risk and creating qualitative and quantitative risk assessments to evaluate and prioritize security exposures.
  • Additional certifications such as Microsoft SC-200/AZ-500, CrowdStrike, or Cato administration credentials.

Responsibilities

  • Administer, tune, and monitor the organization’s security stack (e.g., Cato SASE and/or CrowdStrike EDR/XDR), responding to alerts, investigating incidents, and driving remediation.
  • Lead the vulnerability management lifecycle – scanning, triaging, prioritizing, and tracking remediation of vulnerabilities across servers, endpoints, and cloud workloads.
  • Own and improve the patch management program, ensuring operating systems, applications, and infrastructure are consistently updated and compliant.
  • Harden and secure Microsoft 365 (Exchange Online, SharePoint, Teams, Entra ID) using secure baselines, conditional access, and MFA.
  • Administer and mature Microsoft Purview capabilities, including Data Loss Prevention (DLP), sensitivity labels, retention policies, audit logging, eDiscovery support, insider risk signals, and compliance evidence collection to protect member and organizational data.
  • Manage Microsoft Intune endpoint security responsibilities, including device compliance policies, configuration profiles, security baselines, device enrollment, conditional access integration, and remediation of non-compliant endpoints.
  • Configure, monitor, and secure Microsoft Azure resources, applying cloud security best practices, identity governance, and least-privilege access.
  • Apply and enforce security best practices including network segmentation, endpoint protection, logging, monitoring, and configuration management.
  • Administer and maintain firewall policies, including rule reviews, segmentation controls, VPN/security access, logging, and coordination of network security changes.
  • Develop, review, and enforce Group Policy settings to support secure workstation and server configurations, hardening standards, and consistent endpoint controls.
  • Manage email security controls, including phishing protection, attachment and URL defense, quarantine review, policy tuning, and investigation of suspicious messages.
  • Coordinate security awareness training and phishing simulation activities, including user education, campaign support, reporting, and follow-up guidance for employees.
  • Leverage APIs and base scripting in PowerShell, Bash, and Python to automate security operations, integrate tooling, extract and correlate data, and streamline repetitive tasks across on-premises and cloud environments.
  • Support security audits, examinations, and assessments by gathering evidence, documenting controls, and helping remediate findings for regulatory and audit bodies.
  • Contribute to security policies, standards, and procedures, and promote security awareness across the organization.
  • Assist with incident response activities, including detection, containment, eradication, recovery, and post-incident reporting.
  • Collaborate with infrastructure and application teams to embed security into projects, migrations, and new technology rollouts.
  • Must be flexible and able to work unusual and variable hours/schedules, without supervision, including but not limited to holidays, evenings or weekends.
  • Enforces compliance with all federal and state laws and regulations, including the Bank Secrecy Act (BSA), Patriot Act, and Office of Foreign Asset Controls (OFAC) requirements, and should request legal interpretation as necessary to identify compliance concerns.
  • Adhere to applicable federal and state laws, regulations, and internal compliance with standard polices relevant to their roles and responsibilities.
  • Perform other duties as assigned.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service