Information Security Analyst
Summary
On-site Information Security Analyst at First United Bank supporting the bank's security program through technical audits, security log analysis, vulnerability management, and reporting, working with Excel, PowerShell, and SIEM platforms under the CISO.
First United Bank is accepting applications for a Full Time Information Security Analyst to join our team.
The Information Security Analyst supports the Bank's information security program through technical audits, security log analysis, vulnerability management, reporting, and data analysis. This position identifies security risks, compliance issues, and operational trends by reviewing security-related data from systems, applications, and vendors. The role works closely with Information Technology and business departments to support monitoring, reporting, and security improvement efforts. This position reports to the Chief Information Security Officer, and this position is located at the Lubbock PBI office.
DUTIES:
Technical Audits:
- Reviews data to assess compliance with internal business processes, IT General Controls (ITGCs), security controls, application systems, technical systems, regulatory requirements, and established policies and procedures.
- Collects, organizes, and reviews data for quarterly application access and user/deprovisioning audits.
- Utilizes Microsoft Excel and other business productivity tools to review audit data, including formulas, lookups, and pivot tables.
- Investigates audit discrepancies and communicates findings to the Information Technology Department and other Bank departments.
- Prepares and presents final audit findings reports to the Chief Information Security Officer.
Data Analysis:
- Collects and reviews security logs from servers, applications, cloud environments, and SIEM platforms for analysis and reporting.
- Creates trend analysis from collected logs and raw data to identify suspicious and anomalous activity.
- Creates and maintains analytical reports and distributes them to the Chief Information Security Officer and IT Management.
- Performs weekly internal and external vulnerability scans and asset discovery scans.
- Creates and distributes weekly vulnerability, hardware, and software asset reports to the Chief Information Security Officer and IT Management.
- Utilizes PowerShell scripts and advanced Excel functions for data analysis and reporting.
- Participate in projects for information security implementations, audit remediations, and vulnerability management.
Performance Measurements:
- Daily, weekly, monthly, and quarterly audits and log reviews and reporting are completed on schedule.
- Weekly vulnerability and hardware/software scans and reports are completed on schedule.
- Audit and log review discrepancies are readily identified, reported, and resolved.
- Assigned tasks and responsibilities are completed in accordance with established standards, policies, and procedures.
- Maintains positive working relationships with Information Technology personnel, bank employees, bank management, bank executives, and vendors.
- Participates in job-specific training, various bank training programs, and complies with all bank policies and procedures.