IT Security Analyst
Black Hills Federal Credit UnionAbout the role
Job DetailsJob Location: Remote Work - MST - Rapid City, SD 57702Job Category: Information TechnologyWho We Are
We have the fundamental belief that we, as an organization, can and will improve lives. Rooted in the centuries-old credit union philosophy of people helping people, we maintain a simple premise. Those we interact with will receive equal and just treatment, devoid of intolerance, false judgment, racism, or discrimination of any kind. We must not accept less if we are to fulfill our mission, "We Improve Lives." This mission empowers us to serve the greater good and to make a difference in our world. Our cooperative structure creates a cycle of mutual assistance towards the common goal of the financial well-being of members.
At Black Hills Federal Credit Union (BHFCU), we’re committed to improving the lives of our members every day, and we look for people who share that passion. Don’t have a ton of financial industry experience? No problem. Our onboarding includes an orientation program with ongoing training to help staff further their career at BHFCU by building on their existing strengths.
Remote Eligible States:
South Dakota
Montana
Wyoming
Florida
Georgia
Iowa
Utah
Kansas
Nebraska
Texas
Minnesota
General Purpose: The IT Security Analyst II supports the Credit Union’s information security governance, risk, and compliance programs through policy administration, audit coordination, risk tracking, vendor oversight, security reporting, and operational support activities. This role helps ensure alignment with regulatory requirements, cybersecurity frameworks, and organizational security objectives while supporting the overall maturity of the Information Security Program.
Essential Duties/Responsibilities:
Support the Credit Union’s Information Security Governance, Risk, and Compliance (GRC) program in alignment with FFIEC, NCUA, GLBA, NIST CSF, and CIS Controls.
Assist with the development, review, maintenance, and administration of Information Security policies, standards, and procedures.
Coordinate Information Security risk assessments, remediation tracking, exception management, and control validation activities.
Support internal and external audits, regulatory examinations, and compliance reviews through evidence collection and documentation management.
Prepare recurring security metrics, dashboards, reports, and board reporting materials.
Support governance activities related to incident response, business continuity, disaster recovery, and change management.
Assist with monitoring regulatory changes and assist with compliance impact assessments and remediation coordination.
Support security awareness training initiatives, phishing campaigns, and training completion tracking.
Maintain Information Security documentation, audit artifacts, governance records, and operational repositories.
As directed by the IT Security manager, track audit findings, remediation activities, risk items, and security-related tasks to completion.
Support administration of GRC platforms, workflow systems, and security request tracking processes.
Coordinate with the IT Security Manager appropriate access review activities, documentation management, and security governance workflows.
Maintain vendor management records, asset inventories, and security operational tracking documentation.
Assist with incident response tabletop exercises, reporting coordination, and documentation updates.
Support recurring operational reporting, committee materials, and executive reporting preparation.
Other Duties/Responsibilities:
Participate in continuous improvement efforts for the Information Security Program.
Collaborate with Information Technology, Compliance, Risk Management, Internal Audit, and business units on security initiatives.
Support strategic Information Security projects and governance initiatives.
Stay informed on evolving cybersecurity threats, regulatory requirements, and financial industry security practices.
Attend professional development and security training as required.
Job Knowledge:
Working knowledge of Information Security governance, risk management, and compliance frameworks including FFIEC, NCUA, GLBA, NIST CSF, CIS Controls, and PCI-DSS.
Understanding of Information Security policies, audit coordination, regulatory examinations, risk assessments, and remediation tracking processes.
Familiarity with third-party/vendor risk management, security awareness training, business continuity, and incident response coordination.
Familiarity with governance, reporting, and workflow management tools such as Microsoft Office, ServiceNow, Tandem, or similar business applications.
Job Qualifications (Skills):
BHFCU is committed to working with its employees to reasonably accommodate them with the physical aspects of the position. The following list outlines the physical considerations that are normally encountered in this job.
Vision
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s