UFCU Logo

UFCU

Associate Cyber Risk Analyst

Posted Yesterday
Be an Early Applicant
In-Office
Austin, TX
Junior
In-Office
Austin, TX
Junior
Coordinates cybersecurity governance, risk, and compliance activities, including audits, due diligence, evidence collection, remediation tracking, documentation lifecycle management, process development, security awareness training, and phishing simulations. Maintains cybersecurity records, dashboards, metrics, and reporting while partnering with Information Security, Risk, Audit, Compliance, Legal, HR, Technology, and business stakeholders. Supports regulatory requirements and continuous improvement of cybersecurity processes and controls.
The summary above was generated by AI
Job Summary

The Associate Cyber Risk Analyst coordinates governance, risk, and compliance activities that support UFCU’s cybersecurity program. This role organizes participation in internal audits and third-party due diligence, maintains cybersecurity program knowledge and records, coordinates the development and lifecycle of security processes and procedures, and administers the security awareness training and phishing exercise program. The Associate Cyber Risk Analyst partners with Information Security, Risk Management, Internal Audit, Compliance, Legal, Human Resources, Technology, and business teams to collect evidence, track commitments, improve documentation, and promote secure behaviors across the organization.

The Associate Cyber Risk Analyst is an exempt position and reports to the Director, Information Security, and is part of the Information Security team at UFCU.

About UFCU

Our Credit Union was founded in 1936 and has grown to serve members throughout Texas and beyond. At UFCU, we are more than just a financial institution, and our people are more than just employees. We are dedicated to our purpose of empowering our Members to achieve financial success and build brighter futures.

In pursuit of our aspiration that UFCU is loved by millions of Members and built to thrive for generations, we are guided by our values:

  • Purposefully Member-Obsessed: We are driven by a profound sense of empathy to deeply understand our Members’ needs and preferences, what brighter futures means to them, and the obstacles in their way. We act in our Members’ best interests, forever seeking to empower their financial success.
  • Possibilities Reimagined: We are inspired to courageously experiment, learn, and iterate in pursuit of positive impact for our Members, UFCU, and coworkers. We challenge assumptions, embrace diverse perspectives, and make use of data and insights.
  • Performance Excellence Rooted in Unwavering Integrity: We do the right thing, always. We champion teamwork, accountability, continuous improvement, and celebrate successful outcomes of others, fostering an inclusive environment of excellence and collaboration.
Essential FunctionsAudit and Due Diligence Coordination
  • Coordinate, organize, and manage Information Technology participation in internal audits, external audits, regulatory examinations, risk assessments, and control reviews.
  • Maintain audit schedules, evidence inventories, request lists, stakeholder assignments, due dates, dependencies, and status reporting from initiation through closure.
  • Collect, review, organize, and securely retain audit evidence to support accurate, complete, and timely responses.
  • Facilitate meetings among auditors, vendors, control owners, subject matter experts, and leadership; document decisions, action items, and follow-up commitments.
  • Track findings, management responses, remediation plans, and evidence of closure; escalate delays, risks, and resource constraints to Information Security leadership.
Cybersecurity Knowledge & Information Management
  • Maintain the cybersecurity program’s authoritative documentation repository, including standards, procedures, control narratives, evidence, risk records, decisions, meeting materials, metrics, and program artifacts.
  • Organize cybersecurity information using consistent taxonomy, naming, ownership, version control, retention, review dates, and access permissions.
  • Coordinate recurring reviews with document owners to validate accuracy, remove obsolete content, and preserve institutional knowledge.
  • Prepare dashboards, reports, presentations, and program updates that communicate cybersecurity activities, risks, trends, and commitments to technical and business audiences.
  • Support records retention, legal hold, privacy, and confidentiality requirements for cybersecurity program information.
Cybersecurity Process & Procedure Coordination
  • Coordinate the development, review, approval, publication, and scheduled refresh of Information Security processes, procedures, standards, and supporting templates.
  • Partner with process owners and subject matter experts to document roles, workflows, control points, inputs, outputs, dependencies, exceptions, and evidence requirements.
  • Facilitate workshops and working sessions to identify gaps, resolve conflicting requirements, and align documentation with policy, risk, regulatory, and operational needs.
  • Maintain document inventories, ownership assignments, approval records, revision history, review cadence, and exceptions.
  • Monitor process adoption and effectiveness; recommend improvements based on audit results, incidents, metrics, stakeholder feedback, and changes in the threat or regulatory environment.
Security Awareness Training & Phishing Exercises
  • Administer the enterprise security awareness and training program, including annual training, role-based learning, new-hire content, targeted campaigns, and recurring communications.
  • Plan and execute periodic phishing simulations with approved scenarios, audience groups, schedules, safeguards, and escalation paths.
  • Maintain training assignments, completion records, exceptions, reminders, and evidence required for audits and regulatory reviews.
  • Analyze training and phishing results, identify trends and higher-risk populations, and coordinate appropriate coaching, follow-up learning, and corrective actions.
  • Develop program communications, metrics, and leadership reporting; evaluate content and platform effectiveness and recommend enhancements that strengthen security culture.
Other
  • Adheres to all company policies, procedures, and business ethics codes.
  • Completes required regulatory training as assigned.
  • Maintains strict adherence to and compliance with all laws, rules, regulations, and internal controls specific to the role, including but not limited to Bank Secrecy Act, Anti-Money Laundering, USA Patriot Act, Office of Foreign Assets Control, and Fair Lending regulations.
Knowledge/Skills/Abilities

This is an intermediate-level role and requires a competent level of knowledge, skill, and ability.

Knowledge
  • Competent knowledge of cybersecurity governance, risk, compliance, audit, and control concepts.
  • Knowledge of audit evidence practices, issue remediation, control testing, records management, policy governance, and document lifecycle management.
  • Knowledge of cybersecurity and financial-services frameworks and requirements, such as the National Institute of Standards and Technology Cybersecurity Framework, National Credit Union Administration guidance, Gramm-Leach-Bliley Act, Federal Financial Institutions Examination Council guidance, and Payment Card Industry Data Security Standard.
  • Familiarity with security awareness principles, adult learning concepts, phishing simulation practices, and security culture measurement.
Skills
  • Project coordination skills, including planning, scheduling, dependency management, action tracking, status reporting, and meeting facilitation.
  • Clear business and technical writing skills for developing processes, procedures, control narratives, audit responses, presentations, and program communications.
  • Information organization and records-management skills, including taxonomy, version control, document ownership, review cycles, retention, and access management.
  • Data analysis and reporting skills using Microsoft Excel, Power BI, or similar tools to develop meaningful metrics and dashboards.
  • Proficiency with Microsoft 365 collaboration tools and experience administering governance, risk, compliance, audit, knowledge-management, or security-awareness platforms.
Abilities
  • Ability to manage multiple concurrent requests, deadlines, and stakeholders while maintaining attention to detail and accurate records.
  • Ability to translate cybersecurity, audit, and compliance requirements into practical activities and clear communications.
  • Ability to build cooperative relationships and influence control owners and cross-functional partners without direct authority.
  • Ability to handle confidential or sensitive information with discretion and apply sound judgment when escalating risks or delays.
  • Ability to identify process gaps, recommend improvements, and follow work through to measurable completion.
Core CompetenciesDemonstrating Member Obsession
  • Puts themselves in the Member’s shoes
  • Looks for friction points
  • Makes it personalized and easy
Demonstrating Performance Excellence
  • Sets standards for elevating excellence
  • Ensures elevated quality
  • Takes responsibility
  • Conducts continuous improvement
Demonstrating Innovation
  • Challenges current thinking
  • Approaches change with a positive mindset
ExperienceMinimum Requirements
  • Bachelor’s degree in cybersecurity, information systems, business, risk management, communications, or a related field, or equivalent relevant professional experience.
  • 0-2 years of relevant experience in cybersecurity, governance, risk, compliance, IT audit, information security, records management, training coordination, or a related field.
  • Experience developing or maintaining business or technical processes, procedures, standards, training content, or program communications.
  • Must be bondable.
Preferred Requirements
  • Experience in financial services, fintech, credit unions, or another regulated industry.
  • 2 or more years of relevant experience in cybersecurity, governance, risk, compliance, IT audit, information security, records management, training coordination, or a related field.
  • Master’s degree in cybersecurity, information systems, business, risk management, communications, or a related field, or equivalent relevant professional experience.
  • Experience supporting Information Security audits, regulatory examinations, control assessments, or issue-remediation programs.
  • Experience administering a security awareness training or phishing simulation platform.
  • Experience with governance, risk, and compliance platforms; document-management systems; Microsoft SharePoint; Power BI; or similar tooling.
  • Relevant certification or progress toward certification, such as Certified in Cybersecurity, Security+, Certified in Risk and Information Systems Control, Certified Information Systems Auditor, or Certified Information Security Manager.
Physical Demands

The physical demands described are representative of those that must be met by an employee, with or without accommodation, to successfully perform the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.

Frequent
  • While performing the duties of this job, the employee is regularly required to sit; use hands to finger, handle or feel; reach with hands and arms; and talk or hear.
  • Specific vision abilities required by this job include close vision, distance vision, peripheral vision, and ability to adjust focus.
  • Employee will make extensive use of the telephone and virtual communications requiring the ability to explain complex information effectively and accurately.
Work Environment

The work environment characteristics described are representative of those an employee encounters while performing the essential functions of this job.

  • This position is hybrid, requiring working onsite at UFCU Plaza in Austin, Texas approximately two days per week, with the remaining days worked remotely.
  • This position may involve periodic stressful conditions.
  • May occasionally require an adjusted work schedule, overtime, and evening or weekend hours.
  • May occasionally move from one work location or branch to another.
  • Public contact position, requiring appropriate professional appearance.
  • Frequent computer use at a workstation of up to two hours at a time.
  • The noise level in the work environment is usually moderate.


#INDUFCU

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Similar Jobs at UFCU

2 Hours Ago
In-Office
Junior
Junior
Financial Services
Collects past-due consumer, commercial, and real estate loans through empathetic communication across phone, email, text, chat, and letters. Researches accounts, validates loan and financial information, locates responsible parties, negotiates payment arrangements, processes resolutions, documents collection activity, and ensures compliance with debt-collection laws and credit union policies. Uses collections and financial systems, supports loan servicing, and contributes to process and system improvements.
Top Skills: Billing SystemsChatCollections Management SystemsEmailExcelMember Relationship Management SystemsMicrosoft Office SuiteOutlookPayment PlatformsTelephone SystemsText MessagingWord
6 Days Ago
In-Office
Senior level
Senior level
Financial Services
Leads a team delivering enterprise APIs, integrations, and microservices using MuleSoft, C#/.NET, Kubernetes, and Azure. Owns platform architecture, governance, security, reliability, observability, CI/CD, incident response, and operational readiness. Manages roadmap execution, architecture reviews, engineering standards, stakeholder communication, hiring, coaching, and contractor resources. The role requires hybrid work in Austin, Texas, with occasional after-hours incident response.
Top Skills: AksAzureC#/.NetCi/CdDatadogGrafanaKubernetesMtlsMulesoft Anypoint PlatformOauth2OidcOpenapiRest
Junior
Financial Services
Provides empathetic, bilingual member service for past-due consumer, commercial, and real estate loans. Contacts members through phone and digital channels, validates identities and loan responsibility, researches contact information, negotiates payment solutions, documents collection activities, and completes delinquency-resolution tasks. Uses collections, billing, payment, and member-management systems while complying with debt-collection laws, financial regulations, and company procedures. This is a fully remote, part-time role available to residents of select states.
Top Skills: Billing SystemsChatCollections Management SystemsEmailExcelMember Relationship Management SystemsMS OfficeOutlookPayment PlatformsTelephone SystemsText MessagingUfcu ConnectWord

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account