Meritrust Credit Union Logo

Meritrust Credit Union

Information Security Analyst II (GRC)

Reposted 13 Days Ago
Be an Early Applicant
In-Office
80021, Broomfield, CO, USA
78K-98K Annually
Junior
In-Office
80021, Broomfield, CO, USA
78K-98K Annually
Junior
Execute the Information Security GRC program: maintain policies, map and integrate security frameworks, run risk assessments, support audits and remediation, manage control testing and exceptions, assist incident response and BC/DR exercises, monitor phishing and InfoSec tickets, and provide reporting and training to ensure regulatory compliance and security posture.
The summary above was generated by AI

We recognize that in order to meet the needs of our communities, we must represent our communities. Our success relies on creating a culture where we have diverse perspectives and a true sense of belonging. This is a journey, and we pledge to do more than simply check the box.


When you join the Meritrust team, your benefits will include:

  • Comprehensive medical insurance plan
  • Dental and vision insurance
  • Generous paid-time-off
  • 12 paid holidays
  • Annual bonus (discretionary bonus based on achievement of organizational scorecard results)
  • 401(k) plan
  • Wellness program
  • Tuition assistance
  • Employee loan discount
  • Employee Assistance Program (EAP)
  • Life and disability coverage

What sets working for Meritrust apart?

  • Career development and pathing opportunities to move into leadership roles or other lines of business within MCU such as Commercial Lending, Finance, Marketing, Underwriting, Member Solutions, Training, Human Resources, and more.
  • Supportive and engaging work environment.
  • A wellness and sustainable work culture that puts family, our community, and your health first.
  • A work environment that encourages personal as much as professional growth, teamwork to make the dream work, and treating everyone equally.
  • Studies have shown that individuals from marginalized and or historically underrepresented groups may be less likely to apply for jobs unless they meet every one of the qualifications listed. We are most interested in finding the best candidate for the job. We would encourage you to apply for a job at Meritrust Credit Union, even if you don’t meet every one of our qualifications listed.

This is a full-time position working 40 hours a week, Monday-Friday 8:00am - 5:00pm.


POSITION SUMMARY
Responsible for executing the Governance, Risk, and Compliance (GRC) program within Information Security team for Meritrust Credit Union (MCU). This position reports to the AVP, Security Analysis.

Will work closely with the Risk and Compliance department in ensuring MCU is meeting regulatory requirements and organizational risk tolerance. This position is responsible for maintaining all operational tasks within the information security portfolio including security training, building and reviewing security policies and controls, conducting risk reviews of systems and compliance with information security best practices.

ESSENTIAL FUNCTIONS Governance

  • Stay current with Financial Regulations such as FFIEC guidelines, NCUA requirements, and other compliance regulations.
  • Familiar with Information Security Frameworks such as PCI DSS, NIST 800-53, FedRAMP, ISO 27001, CIS, MITRE ATT&CK, OWASP Top 10, etc.,
  • Build and integrate the security frameworks into the MCU Information Security Program, ensuring organizational compliance.
  • Develop, implement, and maintain policies, standards, and procedures to ensure alignment with MCU security objectives and industry best practices.
  • Design and conduct employee training on compliance, information security, and risk management topics with a focus on safeguarding MCU assets, including member data.

Risk Management

  • Perform risk assessments to identify and mitigate risks related to member data, application security, and security tool health checks.
  • Analyze and document identified risks, providing actionable mitigation recommendations.
  • Support the Information Security Incident Response Plan (ISIRP), Business Continuity and Disaster Recovery (BC/DR) plans and assist tabletop exercises to ensure operational resilience.

Compliance

  • Monitor and support compliance efforts related to regulations and frameworks such as NCUA, NIST, ISO, PCI DSS, CIS, MITRE ATT&CK, OWASP Top 10, and other relevant frameworks.
  • Assist with internal and external audits and regulatory examinations, providing required evidence and ensuring timely remediation of findings.
  • Conduct regular testing of controls in security policies to ensure effectiveness and alignment with regulatory requirements. 
  • Manage findings from audits, risk assessments, security policies control testing, documenting resolutions and tracking remediation progresses.
  • Participate in the exceptions management process, conducting documentation, risk acceptance, and periodic reviews of exceptions.
  • Monitor phishing reports and InfoSec tickets submitted by employees, ensuring proper investigation, resolution, and follow-up.

Collaboration & Reporting

  • Collaborate with IT, compliance/risk management, and operational teams to align cybersecurity objectives with MCU security goals.
  • Provide regular reporting to leadership on the cybersecurity program status, compliance gaps, and risk trends specific to the credit union sector.
  • Design, implement, and update InfoSec performance metrics and key risk indicators (KRIs) to measure the maturity and effectiveness of the security program.
  • Act as a resource for employees on GRC-related inquiries to promote a culture of compliance and security awareness.
     
Qualifications

Education/Certification:      

  • Associate’s or Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent experience.
  • Entry level security certifications such as CompTIA Security+, SSCP, or similar preferred or willingness to obtain.

REQUIRED KNOWLEDGE

  • Basic understanding of information security concepts, principles, and best practices.
  • Familiarity with security frameworks and standards such as PCI DSS, NIST, CIS, and OWASP.
  • Basic knowledge of Microsoft Windows desktop and server environments.
  • Introductory knowledge of Linux operating systems.
  • Fundamental understanding of networking concepts and protocols.
  • Awareness of common cybersecurity threats, vulnerabilities, and attack methods.

EXPERIENCE REQUIRED

  • 0 to 2 years of experience in IT, cybersecurity, or a related technical role.
  • Experience supporting IT systems, help desk, infrastructure, or security operations preferred.
  • Exposure to regulated environments (financial services preferred) is a plus.

HARD / TECHNICAL SKILLS & ABILITIES

  • Learning Orientation:  Willingness to learn and grow within the information security field.
  • Technical Skills:  Basic experience with security tools such as endpoint protection, vulnerability scanners, or log monitoring platforms preferred.
  • Documentation Skills: Ability to follow established procedures and document work accurately.
  • Analytical Skills: Strong analytical and troubleshooting skills.
  • Communication Skills: Good written and verbal communication skills.
  • Service Orientation: Strong customer service mindset and ability to work collaboratively with others.
  • Organizational Skills: Ability to manage multiple tasks and prioritize work effectively.

 

WORKING CONDITIONS

  • Standard office conditions
  • Low to moderate noise
  • Limited lifting up to 30 lbs.

This description has been reviewed to ensure that only essential functions and basic duties have been included.  Peripheral tasks, only incidentally related to each position, have been excluded.  Essential functions, requirements, skills, and abilities included have been determined to be the minimal standards required to successfully perform the positions.  In no instance, however, should the duties, responsibilities, and requirements delineated be interpreted as all inclusive.  Additional functions and requirements may be assigned by supervisors as deemed appropriate.  

 

In accordance with the Americans with Disabilities Act, it is possible that requirements may be modified to reasonably accommodate disabled individuals.  However, no accommodations will be made which may pose serious health or safety risks to the employee or others or which impose undue hardships on the organization.


The Credit Union believes that each employee makes a significant contribution to our success.  That contribution should not be limited by the assigned responsibilities.  Therefore, this job description is designed to outline primary duties, qualifications, and job scope, but not limit the incumbent.  It is our expectation that each employee will offer his/her services wherever and whenever necessary to ensure the success of our endeavors. 

Job descriptions are not intended as and do not create employment contracts.  The organization maintains its status as an at will employer.  Employees can be terminated for any reason not prohibited by law.

Final Compensation for this position will be determined by various factors such as relevant work experience, specific skills and competencies, education, certifications, and internal pay equity.

We anticipate this position to close within 30 days of posting. Please submit your application at your earliest convenience to be considered.

You may not check every box, or your experience may look a little different from what we've outlined, but if you think you can bring value to Meritrust Credit Union, we encourage you to apply! 

Thank you for your interest in Meritrust Credit Union.

Similar Jobs

An Hour Ago
In-Office
Aurora, CO, USA
85K-105K Annually
Senior level
85K-105K Annually
Senior level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Operates, maintains, and oversees chiller, generator, boiler, HVAC, and utility distribution systems supporting government and mission-critical facilities. Leads facility maintenance personnel and contractors, performs preventive and corrective maintenance, troubleshoots system faults, conducts emergency power testing, maintains operational records, ensures safety and regulatory compliance, coordinates outages and contingency plans, and supports utility equipment replacement and lifecycle planning.
Top Skills: Automatic Transfer SwitchesBoilersBuilding Automation Systems (Bas)Chilled Water Distribution SystemsChiller PlantsCompressorsCooling TowersDdc ControlsGenerator PlantsHeat ExchangersHvacLoad Bank TestingPower Distribution SystemsPumps
An Hour Ago
In-Office
Colorado Springs, CO, USA
92K-152K Annually
Senior level
92K-152K Annually
Senior level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Supports WGS ground satellite configuration and control modernization across the product lifecycle. Responsibilities include hardware baseline analysis, rack installation and deployment, requirements derivation and traceability, mission-thread management, cabling, parts ordering, infrastructure interfaces, system integration, sustainment, technical documentation, and risk management. The role is fully onsite in Colorado Springs and requires eligibility for a U.S. Top Secret/SCI clearance and U.S. person status.
Top Skills: Automated Test EquipmentHardware/Software IntegrationNetwork InfrastructureRequirements ManagementSatcomSystems Engineering
An Hour Ago
In-Office
Colorado Springs, CO, USA
141K-191K Annually
Expert/Leader
141K-191K Annually
Expert/Leader
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Manages ground systems engineering teams supporting critical defense missions. Oversees engineering activities, technical approaches, project and process plans, resources, suppliers, schedules, budgets, process improvements, and customer relationships. Directly supervises employees, develops staff, coordinates daily operations, and ensures delivery of engineering products and processes. The role is fully onsite in Colorado Springs and requires an active U.S. Secret clearance, U.S. Person status, and 10% travel.
Top Skills: Earned Value ManagementGround Systems EngineeringProject SchedulingRequirements ManagementSatcomSystems Engineering

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account