Risk & Security Analyst- Onsite

GULF COAST EDUCATORS FEDERAL CREDIT UNIONPasadena, TX
Onsite

About The Position

GCEFCU is seeking a Risk & Security Analyst to join our IT department! The Risk & Security Analyst is responsible for leading and administering the Credit Union’s cyber and information security risk management program. This position develops, implements, monitors, and continually improves security controls, policies, standards, technologies, and response capabilities designed to protect the confidentiality, integrity, and availability of Credit Union information and systems. This position is located onsite at our Pasadena location.

Requirements

  • Leading and administering the Credit Union’s cyber and information security risk management program.
  • Developing, implementing, monitoring, and continually improving security controls, policies, standards, technologies, and response capabilities.
  • Protecting the confidentiality, integrity, and availability of Credit Union information and systems.
  • Overseeing the implementation, configuration, monitoring, maintenance, and effectiveness of information security technologies.
  • Coordinating with internal IT teams and service providers.
  • Managing the vulnerability and exposure management program.
  • Leading or coordinating cybersecurity incident response.
  • Maintaining incident response procedures and relationships with internal and external response resources.
  • Participating in periodic incident response exercises.
  • Maintaining and improving the Credit Union’s information security governance and risk management program.
  • Conducting or coordinating cybersecurity risk assessments.
  • Supporting regulatory examinations and audits.
  • Assessing cybersecurity risks associated with third-party relationships.
  • Providing security oversight of identity and access management controls.
  • Developing, maintaining, communicating, and supporting enforcement of information security policies, standards, procedures, and employee security awareness initiatives.
  • Providing targeted education based on emerging threats, incidents, testing results, and organizational risk.
  • Responsible for compliance with Bank Secrecy Act and all governmental regulations and Credit Union policies and guidelines.
  • Responsible for complying with Federal Rules and Regulations as required by NCUA.

Responsibilities

  • Oversee the implementation, configuration, monitoring, maintenance, and effectiveness of information security technologies, including firewalls, endpoint security, email security, encryption, network detection and prevention, security monitoring, and other preventive and detective controls.
  • Coordinate with internal IT teams and service providers to address identified security events and control deficiencies.
  • Manage the vulnerability and exposure management program, including vulnerability scanning, penetration testing, configuration assessments, tracking of remediation activities, validation of corrective actions, risk acceptance documentation, and reporting of unresolved exposures.
  • Lead or coordinate the investigation, containment, eradication, recovery, documentation, and post-incident review of cybersecurity incidents.
  • Maintain incident response procedures, escalation paths, communication protocols, evidence-handling practices, and relationships with internal and external response resources.
  • Participate in periodic incident response exercises.
  • Notify relevant stakeholders within timely manner.
  • Maintain and continually improve the Credit Union’s information security governance and risk management program.
  • Conduct or coordinate cybersecurity risk assessments, monitor security control effectiveness, support regulatory examinations and audits, maintain evidence of compliance, track corrective actions, and provide security risk reporting to management.
  • Assess cybersecurity risks associated with applicable third-party relationships.
  • Review security documentation, risk assessments, contractual security requirements, incident notification provisions, remediation plans, and ongoing monitoring results in coordination with Vendor Management, Compliance, Legal, and business owners.
  • Provide security oversight of identity and access management controls, including privileged access, multifactor authentication, access reviews, segregation of duties, authentication standards, and timely removal or modification of access.
  • Develop, maintain, communicate, and support enforcement of information security policies, standards, procedures, and employee security awareness initiatives.
  • Provide targeted education based on emerging threats, incidents, testing results, and organizational risk.
  • Responsible for compliance with Bank Secrecy Act and all governmental regulations and Credit Union policies and guidelines.
  • Responsible for complying with Federal Rules and Regulations as required by NCUA.
  • Performs other job-related duties as assigned.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service