Information Security Analyst

COMMUNITY FIRST CREDIT UNION OF FLORIDAJacksonville, FL
Hybrid

About The Position

The Information Security Analyst role will contribute to the Information Security program of the credit union by supporting Incident Response, Vulnerability Management, reporting, governance activities, and continuous improvement of security controls. Works closely with the Information Technology department. This role requires the ability to research solutions as needed. This role ensures compliance with security standards, maintains operational security metrics, and supports risk management initiatives. Should be proactive and able to work in both team settings and on individual projects.

Requirements

  • 2–5 years of experience in information security, IT risk, or compliance-related roles.
  • Bachelor’s degree in Information Security, Information Technology, or related field (or equivalent experience).
  • Possess knowledge and understanding of a breadth of information technologies and information security topics.
  • Understand networking protocols, firewall functionality, host and network intrusion detection systems, and vulnerability assessments.
  • Experience with Microsoft 365 and Azure security and compliance tools.
  • Experience with identity and access management concepts (Entra ID/Azure AD).
  • Experience with governance, risk, and compliance (GRC) tools
  • Knowledge of CIS benchmarks and security control frameworks.
  • Knowledge of NIST CSF 2.0 and other security best practices.
  • Perform primarily sedentary work with limited physical exertion and occasional lifting of up to 10 lbs.
  • Must be capable of climbing / descending stairs in emergency situation.
  • Must be able to operate routine oce equipment including telephone, copier, facsimile, and calculator.
  • Must be able to routinely perform work on computer for an average of 6-8 hours per day, when necessary.
  • Must be able to work extended hours whenever required or requested by management.
  • Must be capable of regular, reliable and timely attendance.
  • Must be able to perform job functions independently or with limited supervision and work effectively either on own or as part of a team.
  • Must be able to read and carry out various written instructions and follow oral instructions.
  • Must be able to speak clearly and deliver information in a logical and understandable sequence.
  • Must be capable of complex mathematical calculations and spell accurately.
  • Must be capable of dealing calmly and professionally with numerous different personalities from diverse cultures at various levels within and outside of the organization and demonstrate highest levels of customer service and discretion when dealing with the public.
  • Must be able to perform responsibilities with composure under the stress of deadlines / requirements for extreme accuracy and quality and/or fast pace.
  • Must be able to effectively handle multiple, simultaneous, and changing priorities.
  • Must be capable of exercising highest level of discretion on both internal and external confidential matters.

Nice To Haves

  • Relevant certifications such as Security+, SSCP, or similar are preferred.
  • Would consider 5+ years of IT experience with a focus on security in lieu of degree.
  • A certification of Industry equivalence would also be considered.

Responsibilities

  • Maintain information security metrics across multiple platforms, including the information security dashboard, audit committee reporting requirements, and other governance reporting needs.
  • Gather, validate, and report metrics related to Microsoft 365 and Azure security and compliance posture.
  • Conduct periodic User Access Reviews to validate appropriate access and enforce least privilege principles.
  • Lead vulnerability remediation meetings with internal stakeholders to review findings, track corrective actions, resolve blockers, and support timely remediation of identified weaknesses.
  • Own and manage the Information Security Procedure Library, ensuring procedures are reviewed, updated, and aligned with policies.
  • Monitor and report on Vulnerability Management, CIS benchmark alignment, and overall security tool compliance.
  • Respond to alerts escalated from MSSP and assist in the development of incident response runbooks.
  • Collaborate with IT, compliance, and business teams to improve security posture.
  • Must comply with all company policies and procedures, applicable laws and regulations, including but not limited to, the Bank Secrecy Act, the Patriot Act, and the Office of Foreign Assets Control.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service