Associate Cyber Risk Analyst
University Federal Credit Union
Job SummaryThe Associate Cyber Risk Analyst coordinates governance, risk, and compliance activities that support UFCU’s cybersecurity program. This role organizes participation in internal audits and third-party due diligence, maintains cybersecurity program knowledge and records, coordinates the development and lifecycle of security processes and procedures, and administers the security awareness training and phishing exercise program. The Associate Cyber Risk Analyst partners with Information Security, Risk Management, Internal Audit, Compliance, Legal, Human Resources, Technology, and business teams to collect evidence, track commitments, improve documentation, and promote secure behaviors across the organization.The Associate Cyber Risk Analyst is an exempt position and reports to the Director, Information Security, and is part of the Information Security team at UFCU.About UFCUOur Credit Union was founded in 1936 and has grown to serve members throughout Texas and beyond. At UFCU, we are more than just a financial institution, and our people are more than just employees. We are dedicated to our purpose of empowering our Members to achieve financial success and build brighter futures.In pursuit of our aspiration that UFCU is loved by millions of Members and built to thrive for generations, we are guided by our values:Purposefully Member-Obsessed: We are driven by a profound sense of empathy to deeply understand our Members’ needs and preferences, what brighter futures means to them, and the obstacles in their way. We act in our Members’ best interests, forever seeking to empower their financial success.Possibilities Reimagined: We are inspired to courageously experiment, learn, and iterate in pursuit of positive impact for our Members, UFCU, and coworkers. We challenge assumptions, embrace diverse perspectives, and make use of data and insights.Performance Excellence Rooted in Unwavering Integrity: We do the right thing, always. We champion teamwork, accountability, continuous improvement, and celebrate successful outcomes of others, fostering an inclusive environment of excellence and collaboration.Essential FunctionsAudit and Due Diligence CoordinationCoordinate, organize, and manage Information Technology participation in internal audits, external audits, regulatory examinations, risk assessments, and control reviews.Maintain audit schedules, evidence inventories, request lists, stakeholder assignments, due dates, dependencies, and status reporting from initiation through closure.Collect, review, organize, and securely retain audit evidence to support accurate, complete, and timely responses.Facilitate meetings among auditors, vendors, control owners, subject matter experts, and leadership; document decisions, action items, and follow-up commitments.Track findings, management responses, remediation plans, and evidence of closure; escalate delays, risks, and resource constraints to Information Security leadership.Cybersecurity Knowledge & Information ManagementMaintain the cybersecurity program’s authoritative documentation repository, including standards, procedures, control narratives, evidence, risk records, decisions, meeting materials, metrics, and program artifacts.Organize cybersecurity information using consistent taxonomy, naming, ownership, version control, retention, review dates, and access permissions.Coordinate recurring reviews with document owners to validate accuracy, remove obsolete content, and preserve institutional knowledge.Prepare dashboards, reports, presentations, and program updates that communicate cybersecurity activities, risks, trends, and commitments to technical and business audiences.Support records retention, legal hold, privacy, and confidentiality requirements for cybersecurity program information.Cybersecurity Process & Procedure CoordinationCoordinate the development, review, approval, publication, and scheduled refresh of Information Security processes, procedures, standards, and supporting templates.Partner with process owners and subject matter experts to document roles, workflows, control points, inputs, outputs, dependencies, exceptions, and evidence requirements.Facilitate workshops and working sessions to identify gaps, resolve conflicting requirements, and align documentation with policy, risk, regulatory, and operational needs.Maintain document inventories, ownership assignments, approval records, revision history, review cadence, and exceptions.Monitor process adoption and effectiveness; recommend improvements based on audit results, incidents, metrics, stakeholder feedback, and changes in the threat or regulatory environment.Security Awareness Training & Phishing ExercisesAdminister the enterprise security awareness and training program, including annual training, role-based learning, new-hire content, targeted campaigns, and recurring communications.Plan and execute periodic phishing simulations with approved scenarios, audience groups, schedules, safeguards, and escalation paths.Maintain training assignments, completion records, exceptions, reminders, and evidence required for audits and regulatory reviews.Analyze training and phishing results, identify trends and higher-risk populations, and coordinate appropriate coaching, follow-up learning, and corrective actions.Develop program communications, metrics, and leadership reporting; evaluate content and platform effectiveness and recommend enhancements that strengthen security culture.OtherAdheres to all company policies, procedures, and business ethics codes.Completes required regulatory training as assigned.Maintains strict adherence to and compliance with all laws, rules, regulations, and internal controls specific to the role, including but not limited to Bank Secrecy Act, Anti-Money Laundering, USA Patriot Act, Office of Foreign Assets Control, and Fair Lending regulations.Knowledge/Skills/AbilitiesThis is an intermediate-level role and requires a competent level of knowledge, skill, and ability.KnowledgeCompetent knowledge of cybersecurity governance, risk, compliance, audit, and control concepts.Knowledge of audit evidence practices, issue remediation, control testing, records management, policy governance, and document lifecycle management.Knowledge of cybersecurity and financial-services frameworks and requirements, such as the National Institute of Standards and Technology Cybersecurity Framework, National Credit Union Administration guidance, Gramm-Leach-Bliley Act, Federal Financial Institutions Examination Council guidance, and Payment Card Industry Data Security Standard.Familiarity with security awareness principles, adult learning concepts, phishing simulation practices, and security culture measurement.SkillsProject coordination skills, including planning, scheduling, dependency management, action tracking, status reporting, and meeting facilitation.Clear business and technical writing skills for developing processes, procedures, control narratives, audit responses, presentations, and program communications.Information organization and records-management skills, including taxonomy, version control, document ownership, review cycles, retention, and access management.Data analysis and reporting skills using Microsoft Excel, Power BI, or similar tools to develop meaningful metrics and dashboards.Proficiency with Microsoft 365 collaboration tools and experience administering governance, risk, compliance, audit, knowledge-management, or security-awareness platforms.AbilitiesAbility to manage multiple concurrent requests, deadlines, and stakeholders while maintaining attention to detail and accurate records.Ability to translate cybersecurity, audit, and compliance requirements into practical activities and clear communications.Ability to build cooperative relationships and influence control owners and cross-functional partners without direct authority.Ability to handle confidential or sensitive information with discretion and apply sound judgment when escalating risks or delays.Ability to identify process gaps, recommend improvements, and follow work through to measurable completion.Core CompetenciesDemonstrating Member ObsessionPuts themselves in the Member’s shoesLooks for friction pointsMakes it personalized and easyDemonstrating Performance ExcellenceSets standards for elevating excellenceEnsures elevated qualityTakes responsibilityConducts continuous improvementDemonstrating InnovationChallenges current thinkingApproaches change with a positive mindsetExperienceMinimum RequirementsBachelor’s degree in cybersecurity, information systems, business, risk management, communications, or a related field, or equivalent relevant professional experience.0-2 years of relevant experience in cybersecurity, governance, risk, compliance, IT audit, information security, records management, training coordination, or a related field.Experience developing or maintaining business or technical processes, procedures, standards, training content, or program communications.Must be bondable.Preferred RequirementsExperience in financial services, fintech, credit unions, or another regulated industry.2 or more years of relevant experience in cybersecurity, governance, risk, compliance, IT audit, information security, records management, training coordination, or a related field.Master’s degree in cybersecurity, information systems, business, risk management, communications, or a related field, or equivalent relevant professional experience.Experience supporting Information Security audits, regulatory examinations, control assessments, or issue-remediation programs.Experience administering a security awareness training or phishing simulation platform.Experience with governance, risk, and compliance platforms; document-management systems; Microsoft SharePoint; Power BI; or similar tooling.Relevant certification or progress toward certification, such as Certified in Cybersecurity, Security+, Certified in Risk and Information Systems Control, Certified Information Systems Auditor, or Certified Information Security Manager.Physical DemandsThe physical demands described are representative of those that must be met by an employee, with or without accommodation, to successfully perform the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.FrequentWhile performing the duties of this job, the employee is regularly required to sit; use hands to finger, handle or feel; reach with hands and arms; and talk or hear.Specific vision abilities required by this job include close vision, distance vision, peripheral vision, and ability to adjust focus.Employee will make extensive use of the telephone and virtual communications requiring the ability to explain complex information effectively and accurately.Work EnvironmentThe work environment characteristics described are representative of those an employee encounters while performing the essential functions of this job.This position is hybrid, requiring working onsite at UFCU Plaza in Austin, Texas approximately two days per week, with the remaining days worked remotely.This position may involve periodic stressful conditions.May occasionally require an adjusted work schedule, overtime, and evening or weekend hours.May occasionally move from one work location or branch to another.Public contact position, requiring appropriate professional appearance.Frequent computer use at a workstation of up to two hours at a time.The noise level in the work environment is usually moderate.#INDUFCUJob SummaryRequisition Number: ASSOC004425Job Category: Information TechnologySchedule: Full-Time
- Procore is seeking a Senior Cybersecurity Risk Analyst to drive end-to-end risk lifecycle management across our cloud and SaaS environments. You will map risks to controls, leverage AI tooling for rapid risk statements, and partner with architects, engineering, and IT...Suggested
- Procore Technologies in Austin, TX is seeking a Senior Cybersecurity Risk Analyst to join the GRC organization. You will manage technical risk across the cloud and information assets, collaborating with security, engineering, IT and business teams. The role emphasizes...Suggested
- Procore is seeking a Senior Cybersecurity Risk Analyst for its GRC organization to manage risks across cloud, SaaS, and information assets. You will map risks, coordinate with architects and engineers, and apply AI tools to accelerate risk statements and reporting. The...Suggested
$86.5k - $166k
...IT) Management Level Senior Associate Job Description & Summary... ...protecting organisations from cyber threats through advanced technologies... ...Incident Response manager and analyst. What You Must Have -... ...in cybersecurity frameworks, risk management, and threat intelligence...SuggestedFull timeH1bVisa sponsorshipWork visaFlexible hours$87.7k - $157.8k
Position Purpose: Conduct analysis, pricing, and risk assessment to evaluate and project Medicare Advantage financial performance.... ...query skills required; AI/Copilot experience is a plus.In this Associate Actuary role, you will:Analyze and evaluate business risks and...SuggestedFull timePart timeWork at officeRemote workFlexible hours$110k - $140k
...recruitment solutions with HR expertise Associate Actuary - Valuation Continental General Insurance... ..., ensuring compliance with all model risk management standards, especially... ...Associate Employment Type Full‑time Job Function Analyst, Research, and Strategy/Planning...Weekly payFull timeTemporary workWork at officeFlexible hours- ...Texas at Austin seeks a Cybersecurity Threat and Vulnerability Analyst to join the Information Security Office. The role is on UT's main... ...response protocols, and publishing reports. You will collaborate with risk engineers to address enterprise cybersecurity challenges,...Remote jobWork at officeImmediate start
- The University of Texas at Austin is seeking a Cybersecurity Threat and Vulnerability Analyst to join the Information Security Office. You will collaborate with risk management engineers to evaluate daily threats, develop response protocols, and publish vulnerability assessments...Remote jobWork at office
- .... Perform rate adequacy studies and recommend pricing actions. Monitor portfolio performance and identify emerging trends and risks. Support forecasting, budgeting, and strategic planning initiatives. Predictive Modeling & Analytics Build, validate, and maintain...Flexible hoursShift work
$105.4k - $207.8k
Position Summary Cyber Security & Risk Strategy Senior Consultant Our Deloitte Cyber team understands the unique challenges and opportunities... ...been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At...Local areaVisa sponsorship- Position Summary Analyst, Cyber Strategy & TransformationOur Deloitte Cyber team understands the unique challenges and opportunities... ...resilience, grow with confidence, and proactively manage cyber, risk, and technology programs.Work you’ll doAs an Analyst, Strategy...Visa sponsorship
- ...bank accounts, real money movement, cards, payables, receivables. Risk is not a side quest. Every dollar we move is a decision —... ...have to be fast, sharp, and defensible. We're hiring a Senior Risk Analyst — an individual contributor who lives in the queues, the rules,...For contractors
- LPL Financial is seeking an experienced IT Risk & Controls professional to join its first line of defense. You will own day-to-day readiness, testing, and audit facilitation for IT compliance programs including SOX, SOC 1, SOC 2, CCPA/CPRA, and NYDFS attestations. Collaboration...
- A leading security solutions provider in Austin, TX is seeking an Intel Analyst responsible for supporting proactive risk management through intelligence analysis. Key tasks include monitoring threats, developing reports, and collaborating across teams to ensure effective...Remote work
$77k - $202k
...Industry/Sector Not Applicable Specialism Operations Management Level Senior Associate Job Description & Summary The Opportunity As a Source-to-pay Technology Consultant (Coupa, ZIP, GEP) Senior Associate, you will engage with clients to optimize their...Full timeH1b- Cosmenta in Austin, Texas is seeking a Cybersecurity Analyst to safeguard its digital infrastructure against evolving threats. The role involves monitoring systems for vulnerabilities, detecting anomalies, and responding promptly to security incidents. You will be responsible...
- ...Hybrid 3 days onsite You will detect analyze and stop emerging cyber threats. Monitor triaging and responding to security incidents.... ...Security Program Participate in knowledge sharing with other analysts/engineers and develop solutions efficiently. What You’ll Bring...
- Sygnia is a top-tier cyber technology and services company that partners with organizations around the world to proactively strengthen... ...The Role Sygnia is looking for a Security Operations Center (SOC) Analyst to join our growing U.S. Managed Detection and Response team in...
- Cyber Incident Response Analyst Location: Austin OR San Antonio, TX - Hybrid Candidates must reside within Austin OR San Antonio, TX. Responsibilities: Perform advanced incident response across Windows and Linux environments, including triage, containment, eradication,...
- Cyber Incident & Threat Analyst The Cyber Incident & Threat Analyst will be on the front lines of some of the highest stakes cybersecurity work in the state, hunting adversaries across Windows and Linux environments, reconstructing attacks from raw telemetry, and stepping...Local area
- Peak Performers in Austin, TX is seeking an onsite Sr. Security Operations Analyst to monitor and respond to security events across on-premises, cloud, and endpoints. You will analyze threats, triage incidents, and develop detections and playbooks to improve security visibility...
$80k - $110k
Job Description : Cyber Security Analyst (Technical Solutions Delivery) - Austin Realtor Role Overview... ...to identify and prioritize security risks, coordinate remediation, support... ...Certification Requirements: Bachelor's or Associate degree in computer science, cybersecurity...Local areaFlexible hours- ...cybersecurity professional in Austin, TX with hybrid work arrangement. The role focuses on detecting, triaging, and stopping emerging cyber threats, monitoring alerts, and coordinating incident responses across teams. The ideal candidate brings 3+ years of cybersecurity...
$183k - $247.6k
...analyzing logs, or automating complex tasks using command line tools experience- 5+ years of work in identifying security issues and risks, and developing mitigation plans experience- 5+ years of (non-internship) scripting, programming, and security code review in common...InternshipLocal areaImmediate startFlexible hours$109.8k - $186k
...Investigations Visa’s Global Risk Investigations team is dedicated... ...Senior Risk Management Analyst to join our Global Risk Investigations... .... Identify emerging trends associated with security vulnerabilities... ...experience in information security or cyber forensics. Professional...Work experience placementWork at officeLocal area$124.3k - $210.3k
...world. Progress starts with you. Job Description The Senior Risk Operations Analyst is a high visibility and demanding role, responsible for monitoring... ...tools or similar intelligence reporting systems Analysis of cyber threat intelligence and fraud intelligence Undergraduate...Work experience placementWork at officeLocal areaShift workWeekend work- NXP Semiconductors is seeking a Cyber Threat Intelligence & Exposure Management Analyst to identify, analyze, and communicate cyber threats and organizational exposures... ...to deliver actionable insights that reduce business risk. You will collaborate with Security Operations,...
- Arrive Logistics is seeking an analytical and proactive Risk Specialist to join its Risk department in Austin, TX. You will support audits, refine processes, and ensure adherence to risk standards across the organization. Responsibilities include carrier auditing, HVHR...
- Collabera is seeking a Business Analyst in Austin, TX to assist with gathering data for a new application. The role involves organizing contract and risk documentation and summarizing new data for review. Candidates should have strong communication and problem-solving skills...Contract work
$159.3k - $202.4k
...security service teams across Amazon to drive risk reduction and deliver scalable security... ...) or Cloud+ or CySA+ (CompTIA Cybersecurity Analyst) or GCED (GIAC Certified Enterprise Defender) or GICSP (Global Industrial Cyber Security Professional) or PenTest+- Experience...Flexible hoursDay shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Associate Cyber Risk Analyst. Be the first to apply!
- junior associate attorney Austin, TX
- seasonal associate Austin, TX
- media associate Austin, TX
- part time associate Austin, TX
- claims associate Austin, TX
- target associate Austin, TX
- remote associate Austin, TX
- associate game producer Austin, TX
- transaction processing associate Austin, TX
- equipment associate Austin, TX


