> Markdown version of [/jobs/ext/169734-information-security-analyst-onsite](https://www.wearedevelopers.com/jobs/ext/169734-information-security-analyst-onsite). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst (Onsite) - **Company:** Frontwave Credit Union - **Location:** Oceanside, CA, United States - **Experience:** Experienced - **Salary:** $71,885.0 - $107,827.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Computer Networks, Information Security Management, Phishing, Software Vulnerability Management, Information Technology, CIS Benchmarks - **Published:** May 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=67dbb4d4979831c5 ## About the Role Do you have experience in Vulnerability management?, Do you have a Bachelor's degree?, * Strong knowledge of CIS Critical Controls. * Information security certification(s) required, such as CISSP, CISM, or CISA. * Knowledge of financial institution regulatory guidance such as FFIEC or NCUA Part 748 Appendix A preferred. * Experience with vulnerability management and penetration testing. * Proficiency in auditing device configurations and ensuring compliance with security benchmarks. * Excellent analytical and problem-solving skills. * Strong communication and presentation skills., Bachelor's degree or equivalent experience in Computer Science, Information Technology, or a related field. Minimum of 3-5 years of experience in information security or computer networking. ## Description The Information Security Analyst is responsible for enhancing Frontwave's security posture by implementing and auditing CIS Critical Controls. This role involves developing a security program that complies with NCUA Part 748 Appendix A, remediating findings from penetration tests and audits, and presenting monthly security reports. The analyst will manage vulnerabilities, audit device configurations, monitor security incidents, and collaborate with IT System Administrators to ensure security best practices. Additionally, the analyst will conduct regular security assessments, educate staff on cyber topics, and review 3rd party SOC reports to ensure vendor security programs meet Frontwave requirements., Includes the following non-inclusive list. Other duties may be assigned. All duties are to be performed in compliance with applicable laws, regulations as well as Credit Union policies and procedures: * Implement and audit the CIS Critical Controls to enhance the organization's security posture. * Develop and maintain a comprehensive security program that complies with NCUA Part 748 Appendix A. * Remediate findings from internal and external penetration tests and General Controls audits. * Prepare and present monthly security reports to the Enterprise Information Security Committee. * Manage vulnerabilities by identifying, assessing, and mitigating security risks. * Audit device configurations to ensure compliance with CIS benchmarks. * Monitor and respond to security incidents and alerts. * Monitor for external phishing websites and domain threats and lead the take-down process. * Conduct regular security assessments and audits to identify potential vulnerabilities and recommend corrective actions. * Collaborate with IT System Administrators and other departments to ensure the implementation of security best practices. * Stay up to date with the latest security trends, threats, and technologies. * Design and implement security procedures * Collaborate with Artic Wolf Managed Security Services Provider (MSSP) to monitor and implement security best practices. * Monitor and respond to security events from multiple sensors including end point protection, SEIM, web filters, email and DLP protection. * Implement data security measures to protect sensitive information from unauthorized access. * Educate staff on cyber topics such as social engineering and phishing. * Review 3rd party SOC reports to ensure vendor security programs meet Frontwave requirements for safeguarding sensitive information. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)