Blaze Credit Union
Saint Paul, Minnesota
Job Description Job Description Description: Role: This position will be responsible for designing, implementing, and maintaining robust security solutions to protect our organization's information assets. This role requires a strong understanding of cybersecurity principles, hands-on experience with security technologies, and the ability to collaborate with cross-functional teams to mitigate risks and ensure the integrity of our systems. Job Type: Full-time, on-site at our Westminster Administrative office in St Paul, MN Major Duties and Responsibilities Design and implement security infrastructure, including firewalls, intrusion detection systems, VPNs, and endpoint protection solutions, to safeguard company networks and data. Develop and enforce security policies and procedures to ensure compliance with industry regulations and best practices. This includes creating incident response plans, access control policies, and security awareness training programs. Implement, architect and provide guidance on Identity management best practices Implement, architect and provide guidance on Data security best practices Remediate vulnerabilities and provide guidance on the method of remediation Conduct regular vulnerability assessments and penetration testing to identify and remediate security weaknesses in our systems. Stay updated on emerging threats and recommend proactive measures to strengthen our defenses. Implement security monitoring tools to detect and respond to security incidents in real-time. Coordinate incident response efforts, investigate security breaches, and implement corrective actions to prevent future occurrences. Assess the security risks associated with new technologies, systems, and processes. Work closely with IT and business teams to identify potential threats and develop strategies to mitigate risks effectively. Ensure compliance with relevant security standards and regulations, such as NIST, ISO or CIS. Maintain documentation and evidence of compliance activities for audits and regulatory inspections. Coordinate with the Information Security Operations Manager to create new or modify existing technical security documents, playbooks or runbooks. Participate in Security Operations activities such as monitoring and triage of security events, intrusion detection, analysis of anomalies, threat hunting, security operation monitoring, and tuning of security systems and tools. Monitor, track, and maintain certificates/certificate providers. Document security breaches and assess the damage. Assist with support of existing systems and/or business requests. Detect and respond to cyber security threats to ensure Blaze CU operates securely. Identify gaps and propose solutions to increase security efficiency and effectiveness. Identify, evaluate, and apply vulnerability remediations or provide recommendations. Act as technical security advisor to the institution, members and peers. Subscribe to threat notification networks, new regulations and information sharing networks to stay current on requirements and new threats to the industry. Build relationships across the organization to ensure efficient use of controls. Create a robust network of diverse information security and technical professionals. Attend continuing technical security and fraud education appropriate to the position. Attend a certain number of company sponsored security training/education classes including the following areas - BSA, AML, OFAC, privacy, safeguarding member information and physical security. Advise on best security practices as they relate to information technology resources. Participate in the design, configuration & deployment of information security infrastructures. Provide secure alternatives to achieve desired business results. Offer training on technical controls affecting the security and privacy of member information. Other Duties Comply with applicable laws and regulations, including but not limited to, the Bank Secrecy Act, the Patriot Act, and the Office of Foreign Assets Control Exhibit Blaze's Core Value's: Better Lives, Thoughtfully Compassionate, Minnesota's Best, and Give Back Regular and predictable attendance Perform other duties as assigned to support effective department operation Requirements: Experience/Education/Certifications/Licenses Minimum High School degree or equivalent. Bachelor's degree in business, computer science or related field preferred 4+ years' experience in Information Security, preferably in the financial industry Security+/CySA+/Pentest+/Microsoft or similar certifications preferred Advanced knowledge of Identity access management Advanced knowledge of Data security best practices Demonstrated Knowledge Advanced PC skills and aptitude in various software applications Advanced problem-solving skills to evaluate risk, analyze complex security incidents and develop solutions to mitigate risk Understanding of local and wide area networks (LAN/WAN), Internet, electronic communication systems, telecommunications, virtualization Advanced understanding of information security technologies (e.g. firewalls, VPNs, IDS/IPS, penetration testing, security devices) Experience with programming and scripting languages Understanding cryptographic algorithms, encryption techniques, hashing functions, digital signatures, and certificate management. Familiarity with SSL/TLS protocols and PKI infrastructure. Awareness of emerging technologies such as cloud computing, containerization, Internet of Things (IoT), and artificial intelligence (AI), and their security implications. Ability to assess risks and implement security controls for new technologies. Proficiency in conducting security assessments, vulnerability scans, penetration tests, and security audits. Ability to analyze results, prioritize vulnerabilities, and recommend remediation measures. Advanced understanding of information security technologies such as endpoint protection, SEIM, firewalls, VPNs, IDS/IPS, vulnerability scanning, and data loss prevention. Communication Skills Ability to proactively respond to members/staff to document and develop new and ongoing techniques to improve processes; written communications draw from expert information from the field whether as an individual contributor or manager. Physical Requirements Ability to sit and stand; answer calls; operate computer; interact with internal staff and public on the phone; travel to designated offices; lift up to 20 lbs. Diversity creates a healthier atmosphere, and we encourage diverse applicant depth and breadth. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law. We are committed to providing salary ranges for all open positions. Please note that the specific compensation for this role will be determined based on your experience, qualifications, location, and internal equity considerations. The salary range for this position is: $78,490.65- $117,735.97/annually. This range reflects the base salary for this position. We have other benefits associated with this position which include: low-cost medical (as low as $20 a paycheck), dental insurance, vision insurance, quarterly bonuses, generous vacation and sick time hours, paid leave options, up to 6% 401k contribution, and tuition reimbursement.
Job Description Job Description Description: Role: This position will be responsible for designing, implementing, and maintaining robust security solutions to protect our organization's information assets. This role requires a strong understanding of cybersecurity principles, hands-on experience with security technologies, and the ability to collaborate with cross-functional teams to mitigate risks and ensure the integrity of our systems. Job Type: Full-time, on-site at our Westminster Administrative office in St Paul, MN Major Duties and Responsibilities Design and implement security infrastructure, including firewalls, intrusion detection systems, VPNs, and endpoint protection solutions, to safeguard company networks and data. Develop and enforce security policies and procedures to ensure compliance with industry regulations and best practices. This includes creating incident response plans, access control policies, and security awareness training programs. Implement, architect and provide guidance on Identity management best practices Implement, architect and provide guidance on Data security best practices Remediate vulnerabilities and provide guidance on the method of remediation Conduct regular vulnerability assessments and penetration testing to identify and remediate security weaknesses in our systems. Stay updated on emerging threats and recommend proactive measures to strengthen our defenses. Implement security monitoring tools to detect and respond to security incidents in real-time. Coordinate incident response efforts, investigate security breaches, and implement corrective actions to prevent future occurrences. Assess the security risks associated with new technologies, systems, and processes. Work closely with IT and business teams to identify potential threats and develop strategies to mitigate risks effectively. Ensure compliance with relevant security standards and regulations, such as NIST, ISO or CIS. Maintain documentation and evidence of compliance activities for audits and regulatory inspections. Coordinate with the Information Security Operations Manager to create new or modify existing technical security documents, playbooks or runbooks. Participate in Security Operations activities such as monitoring and triage of security events, intrusion detection, analysis of anomalies, threat hunting, security operation monitoring, and tuning of security systems and tools. Monitor, track, and maintain certificates/certificate providers. Document security breaches and assess the damage. Assist with support of existing systems and/or business requests. Detect and respond to cyber security threats to ensure Blaze CU operates securely. Identify gaps and propose solutions to increase security efficiency and effectiveness. Identify, evaluate, and apply vulnerability remediations or provide recommendations. Act as technical security advisor to the institution, members and peers. Subscribe to threat notification networks, new regulations and information sharing networks to stay current on requirements and new threats to the industry. Build relationships across the organization to ensure efficient use of controls. Create a robust network of diverse information security and technical professionals. Attend continuing technical security and fraud education appropriate to the position. Attend a certain number of company sponsored security training/education classes including the following areas - BSA, AML, OFAC, privacy, safeguarding member information and physical security. Advise on best security practices as they relate to information technology resources. Participate in the design, configuration & deployment of information security infrastructures. Provide secure alternatives to achieve desired business results. Offer training on technical controls affecting the security and privacy of member information. Other Duties Comply with applicable laws and regulations, including but not limited to, the Bank Secrecy Act, the Patriot Act, and the Office of Foreign Assets Control Exhibit Blaze's Core Value's: Better Lives, Thoughtfully Compassionate, Minnesota's Best, and Give Back Regular and predictable attendance Perform other duties as assigned to support effective department operation Requirements: Experience/Education/Certifications/Licenses Minimum High School degree or equivalent. Bachelor's degree in business, computer science or related field preferred 4+ years' experience in Information Security, preferably in the financial industry Security+/CySA+/Pentest+/Microsoft or similar certifications preferred Advanced knowledge of Identity access management Advanced knowledge of Data security best practices Demonstrated Knowledge Advanced PC skills and aptitude in various software applications Advanced problem-solving skills to evaluate risk, analyze complex security incidents and develop solutions to mitigate risk Understanding of local and wide area networks (LAN/WAN), Internet, electronic communication systems, telecommunications, virtualization Advanced understanding of information security technologies (e.g. firewalls, VPNs, IDS/IPS, penetration testing, security devices) Experience with programming and scripting languages Understanding cryptographic algorithms, encryption techniques, hashing functions, digital signatures, and certificate management. Familiarity with SSL/TLS protocols and PKI infrastructure. Awareness of emerging technologies such as cloud computing, containerization, Internet of Things (IoT), and artificial intelligence (AI), and their security implications. Ability to assess risks and implement security controls for new technologies. Proficiency in conducting security assessments, vulnerability scans, penetration tests, and security audits. Ability to analyze results, prioritize vulnerabilities, and recommend remediation measures. Advanced understanding of information security technologies such as endpoint protection, SEIM, firewalls, VPNs, IDS/IPS, vulnerability scanning, and data loss prevention. Communication Skills Ability to proactively respond to members/staff to document and develop new and ongoing techniques to improve processes; written communications draw from expert information from the field whether as an individual contributor or manager. Physical Requirements Ability to sit and stand; answer calls; operate computer; interact with internal staff and public on the phone; travel to designated offices; lift up to 20 lbs. Diversity creates a healthier atmosphere, and we encourage diverse applicant depth and breadth. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law. We are committed to providing salary ranges for all open positions. Please note that the specific compensation for this role will be determined based on your experience, qualifications, location, and internal equity considerations. The salary range for this position is: $78,490.65- $117,735.97/annually. This range reflects the base salary for this position. We have other benefits associated with this position which include: low-cost medical (as low as $20 a paycheck), dental insurance, vision insurance, quarterly bonuses, generous vacation and sick time hours, paid leave options, up to 6% 401k contribution, and tuition reimbursement.
Blaze Credit Union
Saint Paul, Minnesota
Job Description Job Description Description: Role: This role supports the Information Security Director and the Governance, Risk and Compliance (GRC) function in maintaining a strong control environment, advancing risk and compliance activities, and building foundational security skills. The intern gains hands-on exposure to vendor risk management, policy governance, audit and exam support, and business continuity while helping the team operate efficiently. Job Type: Part time, on-site at our administrative office in St. Paul, MN. Interns will work 15-20 hours per week during the academic year. Weekly hours are determined by departmental needs, with flexibility provided to accommodate academic schedules. Major Duties and Responsibilities Assist with vendor risk management activities, including intake, due diligence, collection of SOC 2 reports, and tracking of vendor tier classifications Support the review and organization of security policies, standards, and procedures, including formatting, version control, and redline preparation Help gather and organize audit and examiner artifacts for internal audits, NCUA exams, and third-party assessments Maintain risk registers, control libraries, and compliance trackers to keep records current and accurate Support business continuity management (BCM) activities, including department intake, business impact analysis data entry, and plan documentation Assist with control testing and evidence collection to validate that security controls are operating as intended Research regulatory requirements and industry frameworks (e.g., NIST CSF, GLBA, FFIEC) and summarize findings for the team Track open risk and remediation items and follow up with owners on status Support routine GRC operations such as tracking security awareness metrics and maintaining shared documentation Other Duties Participate in business continuity, incident management, and recovery planning and exercise efforts Comply with applicable laws and regulations, including but not limited to the Bank Secrecy Act, the Patriot Act, and the Office of Foreign Assets Control Exhibit Blaze's Core Values: Better Lives, Thoughtfully Compassionate, Minnesota's Best, and Give Back Perform other duties as assigned to support effective department operation Requirements: Job Requirements Experience/Education/Certifications/Licenses Minimum High School degree or equivalent Currently pursuing an Associate's or Bachelor's degree in Information Security, Information Technology, Business, Risk Management, or a related field; recent graduates also considered Coursework, projects, or prior experience related to information security, risk, compliance, or IT is preferred Interest in pursuing security or compliance certifications (e.g., CompTIA Security+, ISACA CRISC, or similar) is a plus Demonstrated Knowledge Familiarity with basic information security, risk, and compliance concepts General awareness of data privacy and financial regulations such as GLBA, GDPR, CCPA and CPRA is a plus Proficiency with Microsoft Office (Word, Excel, PowerPoint, Outlook); exposure to collaboration and GRC tools is a plus Strong attention to detail; high level of honesty and integrity Ability to handle multiple tasks simultaneously, take initiative and be proactive Willingness to learn, ask questions, and follow documented processes Communication Skills Ability to communicate clearly and professionally with staff across the organization; willingness to document processes and develop written materials that draw from information in the field, whether working independently or as part of a team Physical Requirements Ability to sit and stand; answer calls; operate a computer; interact with internal staff and the public on the phone; travel to designated offices; lift up to 20 lbs. Diversity creates a healthier atmosphere, and we encourage diverse applicant depth and breadth. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law. We are committed to providing salary information for all open positions. Compensation for this position is $21.00/hour.
Job Description Job Description Description: Role: This role supports the Information Security Director and the Governance, Risk and Compliance (GRC) function in maintaining a strong control environment, advancing risk and compliance activities, and building foundational security skills. The intern gains hands-on exposure to vendor risk management, policy governance, audit and exam support, and business continuity while helping the team operate efficiently. Job Type: Part time, on-site at our administrative office in St. Paul, MN. Interns will work 15-20 hours per week during the academic year. Weekly hours are determined by departmental needs, with flexibility provided to accommodate academic schedules. Major Duties and Responsibilities Assist with vendor risk management activities, including intake, due diligence, collection of SOC 2 reports, and tracking of vendor tier classifications Support the review and organization of security policies, standards, and procedures, including formatting, version control, and redline preparation Help gather and organize audit and examiner artifacts for internal audits, NCUA exams, and third-party assessments Maintain risk registers, control libraries, and compliance trackers to keep records current and accurate Support business continuity management (BCM) activities, including department intake, business impact analysis data entry, and plan documentation Assist with control testing and evidence collection to validate that security controls are operating as intended Research regulatory requirements and industry frameworks (e.g., NIST CSF, GLBA, FFIEC) and summarize findings for the team Track open risk and remediation items and follow up with owners on status Support routine GRC operations such as tracking security awareness metrics and maintaining shared documentation Other Duties Participate in business continuity, incident management, and recovery planning and exercise efforts Comply with applicable laws and regulations, including but not limited to the Bank Secrecy Act, the Patriot Act, and the Office of Foreign Assets Control Exhibit Blaze's Core Values: Better Lives, Thoughtfully Compassionate, Minnesota's Best, and Give Back Perform other duties as assigned to support effective department operation Requirements: Job Requirements Experience/Education/Certifications/Licenses Minimum High School degree or equivalent Currently pursuing an Associate's or Bachelor's degree in Information Security, Information Technology, Business, Risk Management, or a related field; recent graduates also considered Coursework, projects, or prior experience related to information security, risk, compliance, or IT is preferred Interest in pursuing security or compliance certifications (e.g., CompTIA Security+, ISACA CRISC, or similar) is a plus Demonstrated Knowledge Familiarity with basic information security, risk, and compliance concepts General awareness of data privacy and financial regulations such as GLBA, GDPR, CCPA and CPRA is a plus Proficiency with Microsoft Office (Word, Excel, PowerPoint, Outlook); exposure to collaboration and GRC tools is a plus Strong attention to detail; high level of honesty and integrity Ability to handle multiple tasks simultaneously, take initiative and be proactive Willingness to learn, ask questions, and follow documented processes Communication Skills Ability to communicate clearly and professionally with staff across the organization; willingness to document processes and develop written materials that draw from information in the field, whether working independently or as part of a team Physical Requirements Ability to sit and stand; answer calls; operate a computer; interact with internal staff and the public on the phone; travel to designated offices; lift up to 20 lbs. Diversity creates a healthier atmosphere, and we encourage diverse applicant depth and breadth. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law. We are committed to providing salary information for all open positions. Compensation for this position is $21.00/hour.