JobTarget Logo

IT Security Analyst in Marlborough, Massachusetts at St. Mary's Credit Union

NewSalary: $90000 - $105000Job Function: Information Technology
St. Mary's Credit Union
Marlborough, Massachusetts, 01752, United States
Posted on
New job! Apply early to increase your chances of getting hired.

Explore Related Opportunities

Job Description

St. Mary's Credit Union is currently hiring a IT Security Analyst role. This is a hybrid position based at our main office in Marlborough, MA

If you are looking to join a great place to work that is growing, progressive, offers development opportunities, has an awesome team, and outstanding benefits, we want to hear from you!

Job Summary

The IT Security Analyst is a hands-on member of the Credit Union's Information Technology team responsible for operating core security and compliance processes. Working with and receiving day-to-day guidance from the Senior IT Security Analyst, this role manages security scanning and remediation tracking, supports the investigation and response to security events and incidents, and administers security access changes and related workflows. The analyst also supports compliance activities, audit and risk assessment remediation, security documentation, control testing, and reporting. The successful candidate will bring practical IT security experience, strong process discipline, and the ability to coordinate work across IT, business units, and third-party providers in a regulated financial-services environment.


Essential Job Functions

Performs functions within the scope of authority and expertise to provide a high level of service and responsiveness to the members and employees served by the Credit Union.

Security Monitoring, Scanning and Vulnerability Management
  • Operate and monitor approved vulnerability scanning tools across servers, workstations, network devices, applications, and other in-scope technology assets.
  • Review and validate scan results; assess severity and business relevance; create, assign, track, and follow up on remediation activities through closure.
  • Coordinate with IT administrators, system owners, vendors, and independent testers to address vulnerabilities, configuration weaknesses, and security findings.
  • Maintain accurate vulnerability records, exceptions, evidence, aging information, and management reporting.
  • Monitor alerts and logs from security systems such as firewalls, endpoint protection, SIEM, identity platforms, email security, IDS/IPS, web filtering, and Microsoft security tools.
  • Support secure configuration and system-hardening activities for endpoints, servers, cloud services, network equipment, and business applications.
Security Event and Incident Management
  • Triage, investigate, document, escalate, and track security alerts, events, and suspected incidents in accordance with established procedures.
  • Collect and preserve relevant evidence; coordinate containment, remediation, recovery, and follow-up activities with the Senior IT Security Analyst, CIO, IT staff, business owners, and external providers.
  • Maintain incident tickets, timelines, decisions, communications, and supporting documentation sufficient for management, audit, regulatory, and lessons-learned purposes.
  • Participate in incident response exercises, tabletop activities, and post-incident reviews; help translate lessons learned into practical control and process improvements.
  • Support third-party security incident intake and tracking, including requests for information, impact analysis, and documentation of follow-up actions.
Identity, Access Changes and Security Workflows
  • Process and coordinate authorized user access requests, changes, removals, and periodic access reviews in accordance with least-privilege and segregation-of-duties principles.
  • Administer or coordinate security access workflows for employee onboarding, role changes, transfers, terminations, elevated access, shared accounts, service accounts, and vendor access.
  • Validate required approvals and supporting information before changes are completed; retain clear evidence of request, approval, implementation, and verification.
  • Identify incomplete, conflicting, excessive, or aging access and workflow items, and escalate exceptions or control concerns promptly.
  • Work with IT and business owners to improve the consistency, automation, documentation, and reporting of access-management workflows.
Security Compliance, Risk and Audit Support
  • Assist with operation and documentation of controls aligned with the Credit Union's Information Security Program, selected security framework, policies, and regulatory expectations.
  • Gather, organize, and retain evidence for audits, risk assessments, control testing, regulatory reviews, penetration testing, and independent security assessments.
  • Track findings, management responses, action plans, due dates, supporting evidence, and closure status; follow up with responsible parties and escalate delays.
  • Help maintain security policies, standards, procedures, playbooks, control narratives, inventories, metrics, and compliance records.
  • Complete assigned activities within the Information Security Plan and support applicable cybersecurity assessments and risk-management tools.
  • Assist with third-party security and compliance reviews, including due-diligence evidence, risk issues, remediation tracking, and ongoing monitoring for assigned vendors.
  • Prepare clear security and compliance metrics, status summaries, and supporting analysis for IT leadership and governance reporting.
Security Program and Team Support
  • Work collaboratively with the Senior IT Security Analyst, who serves as the senior analyst and provides technical and operational guidance for analyst activities.
  • Maintain assigned procedures, recurring tasks, work queues, tickets, and dashboards so that security work is visible, prioritized, and completed on schedule.
  • Participate in evaluating, implementing, configuring, and improving approved security products, tools, and services.
  • Support employee security-awareness activities, phishing exercises, and targeted communications in coordination with internal stakeholders.
  • Share knowledge, document repeatable processes, and cross-train to support continuity of security operations.


Other Duties

  • Ability to travel throughout the retail branch network; a valid driver's license is required.
  • Attend staff, departmental, and other required meetings and training.
  • Travel to conferences, professional-development events, vendor locations, or other business locations when required.
  • Provide service to membership communities by volunteering time to local civic and charitable organizations.
  • Act as vendor owner for assigned third-party relationships, including applicable vendor-management processes and reviews.
  • Perform other duties as assigned.


Qualifications, Experience and Education

  • Bachelor's degree in information security, Cybersecurity, Computer Science, Information Systems, or a related field, or an equivalent combination of relevant education and practical experience.
  • Three or more years of hands-on experience in IT security, cybersecurity operations, security compliance, IT audit, or a closely related role.
  • Demonstrated experience operating vulnerability or configuration scanning tools and managing findings through remediation and closure.
  • Demonstrated experience triaging security alerts or incidents and maintaining complete incident documentation.
  • Experience administering or coordinating identity and access changes, approvals, periodic reviews, and workflow records.
  • Working knowledge of security and compliance concepts applicable to regulated organizations, including risk assessments, control evidence, policy and procedure management, audit remediation, least privilege, and segregation of duties.
  • Experience in banking, credit unions, financial services, or another regulated industry is strongly preferred.
  • Security certification such as Security+, SSCP, GSEC, CySA+, or a comparable certification is preferred.
  • Strong written communication, analytical thinking, organization, follow-through, and attention to detail.
  • Ability to handle confidential security, employee, vendor, and member information with sound judgment.
Technical Knowledge and Skills
  • Vulnerability management, endpoint security, firewalls, SIEM and log review, IDS/IPS, email security, web filtering, identity and access management, and multifactor authentication.
  • Microsoft technologies including Active Directory, Entra ID, Group Policy, Microsoft 365, Windows security, and related security administration concepts.
  • Security ticketing, case management, workflow, evidence collection, reporting, and documentation practices.
  • General understanding of networks, cloud services, endpoints, servers, authentication, common protocols, and secure configuration practices.
  • Familiarity with widely used security and control frameworks, such as NIST Cybersecurity Framework and CIS Controls.
  • Proficiency with Outlook, Word, Excel, PowerPoint, Teams, and web-based business applications.


Core Competencies

Accountability; adaptability; analytical judgment; collaboration; communication; customer service; improvement and innovation; job knowledge; organizational awareness; process discipline; and self-development.

Work Environment and Physical Demands

Usual office working conditions with occasional exposure to noise. While performing the duties of this position, the individual is required to use hands to handle objects, tools, or controls; reach with hands and arms; talk and hear; and frequently stand, walk, and sit. The individual may occasionally stoop, kneel, crouch, or lift up to fifteen pounds. Specific vision abilities include close, distance, color, peripheral, and depth vision, and the ability to adjust focus. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the position.

Note: Applicants must be currently authorized to work in the United States. This position does not include employer immigration sponsorship.

Job Location

Marlborough, Massachusetts, 01752, United States

Frequently asked questions about this position

Similar Jobs In Marlborough, Massachusetts

Transportation Analyst

Cambridge Systematics, Inc.
Medford, Massachusetts

Application Analyst (Digital Workplace)

Massachusetts Bay Transportation Authority
Boston, Massachusetts

Junior Cybersecurity Analyst - Boston

Achilleion
Boston, Massachusetts

Senior Cloud Engineer

UMass Memorial Health
Worcester, Massachusetts

Bank Secrecy Act Analyst

Middlesex Savings Bank
Westborough, Massachusetts

Apply Now