> Markdown version of [/jobs/ext/2388601-security-analyst-ii](https://www.wearedevelopers.com/jobs/ext/2388601-security-analyst-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst II - **Company:** Harborstone Credit Union - **Location:** Lakewood, WA, United States - **Experience:** Expert - **Salary:** $102,332.0 - $153,499.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Software System Penetration Testing, CompTIA Security+, Cyber Security, Databases, Data Stores, Disaster Recovery, Monitoring of Systems, IT Management, Network Administration, PCI Data Security Standards, Windows PowerShell, Security Software, Security Information and Event Management, Software Vulnerability Management, Scripting, Network Access Control, Information Technology, Patch Management, Laptops, Network Server, Server Operating Systems & Platforms, Vulnerability Analysis - **Published:** August 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a85cf8a326bded2d ## About the Role * Experienced security professional with strong hands-on knowledge of incident response, vulnerability management, security monitoring, and cybersecurity tools. * Strong communicator and problem solver who can translate complex security risks into clear, actionable recommendations for leadership and business partners. * Self-motivated, adaptable teammate who demonstrates sound judgment, protects confidential information, supports compliance expectations, and continuously improves Harborstone's security posture., * Bachelor's degree in computer science, Information Security, or related field * Experience: * 5-7 years or more experience in information security, with a focus on incident response, vulnerability management, and security monitoring software, required. Maintain strict confidentiality and utmost discretion handling sensitive information and security incidents, ensuring all data and findings are protected and shared only with authorized personnel * Experience in the financial services industry, particularly within credit unions * 10 years or more experience in information security, with a focus on incident response, vulnerability management, and security monitoring software, preferred Technical Skills: * Advanced knowledge of Windows Desktop/Server Operating Systems, Active Directory, Patch Management, Security Information and Event Management, Endpoint Detect and Response, Network Access Control, Vulnerability Scanning, and Network Administration * Knowledge of regulatory requirements and industry standards related to information security * Ability to provide guidance to junior security analysts and other team members * PowerShell or other scripting language/automation skills Soft Skills: * Ability to work non-standard hours as necessary to address incidents * Proven analytical and problem-solving skills, ability to learn new systems, and proficiency with security tools and technologies * Highly adaptable and flexible; able to adjust quickly and effectively prioritize and execute tasks * Strong customer service orientation with excellent written and oral communication skills to communicate complex issues clearly and concisely in business-friendly and user-friendly language * Highly self-motivated and willing to learn and adapt to rapidly changing technology and share knowledge with other team members * Certifications/Additional Qualifications (if applicable): * Hold one or more of the following certifications: Security+, GIAC Information Security Fundamentals, Microsoft Certified Systems Administrator: Security, or CISSP, required * Must be bondable * Hold one or more of the following certifications: CCSP, CISA, or CISM, preferred Physical Considerations * Ability to communicate effectively in verbal, written, and electronic formats with internal and external stakeholders. * Ability to read, comprehend, and respond to written and verbal instructions and information. * May be required to sit or stand for extended periods, depending on job duties. * May involve repetitive motions, including keyboarding and handling office equipment. * May require stooping, bending, squatting, or reaching occasionally. * May be required to lift and carry items weighing up to 20 pounds. * Ability to navigate office environments, including walking between workstations, meeting rooms, and member service areas. * Travel may be required as needed to support business operations and organizational needs. ## Description * Monitor, investigate, and respond to security alerts, incidents, vulnerabilities, and emerging threats to protect Harborstone's systems, data, and information assets. * Maintain and improve cybersecurity controls, policies, procedures, reporting, and documentation in alignment with regulatory requirements and industry standards. * Partner with IT Leadership on security architecture, vendor risk reviews, disaster recovery planning, awareness training, and recommendations that strengthen the organization's overall security posture., * Lead day-to-day cybersecurity operations by monitoring security tools, investigating alerts and incidents, coordinating response efforts, and protecting Harborstone's systems, data, and information assets. * Manage vulnerability, risk, and control activities by supporting assessments, penetration testing, remediation recommendations, vendor security reviews, and disaster recovery planning. * Maintain and strengthen the security program through policy and procedure documentation, regulatory compliance support, leadership reporting, security awareness coordination, and continuous improvement of security controls., The Security Analyst II performs core functions of day-to-day operations for in-place security solutions and the monitoring, identification, investigation, and resolution of security incidents detected by those systems to protect the organization's information assets. Secondary tasks include involvement in the implementation of new security solutions, participation in the creation and or maintenance of policies, standards, baselines, guidelines, and procedures as well as conducting vulnerability audits and assessments. The position works closely with IT Leadership to design, implement, and management of the aforementioned. The position is also expected to be fully aware of Harborstone's security goals as established by stated policies, procedures, and guidelines and to actively work towards upholding those goals. The position reports indirectly to the SVP/Chief Information Officer to ensure appropriate segregation of security responsibilities., * Ensure the confidentiality, integrity, and availability of the data residing on or transmitted to/from/through the organizations workstations, laptops, servers, and other systems and in databases and other data repositories * Monitoring and analysis of security alerts and incidents, conduct investigations, collaborate with leadership and coordinate response efforts to mitigate threats * Use security tools and technologies to monitor for suspicious activity and potential threats * Oversee and respond to regular vulnerability assessments, penetration testing, identification of potential security risks, and collaborate with IT Leadership to recommend remediation * Produce, maintain, document, and enforce; security policies, procedures, incident response reports, root cause analysis, and standards to protect information assets * In support of the Vendor Management Program, review and document SOC reports, disaster recovery, and similar documentation of current and potential business partners. Provide feedback and recommendations to IT Leadership * Participate in planning and design of business continuity and disaster recovery plan * Other job-related duties as assigned Oversight and Development * Keep current with and ensure proactive and timely compliance with relevant regulations and standards, such as PCI-DSS, NCUA, DFI, FFIEC, and other regulatory guidelines * Prepare and present detailed reports on security incidents, findings, and recommendations to IT Leadership * Prepare reports for Cybersecurity Committee regarding current and potential threats * Assist IT Leadership in development of Annual Cybersecurity Report to the Board of Directors * Coordinate with IT Leadership and Training and Development to promote a comprehensive and cohesive approach to security and security awareness training programs * Collaborate with IT Leadership on security architecture and systems to protect critical infrastructure and sensitive data * Stay up to date on the latest cybersecurity threats, trends, and technologies, ensuring the organization's defenses are continuously improved * Ensure continuous maturity of appropriate security controls, policies, and procedures in compliance with industry standards (NIST, CIS 18, etc.) Other Responsibilities * Keep current with FS-ISAC, ISC2, and other sources * Upholds legal, regulatory and compliance requirements unique to the role, in addition to Bank Secrecy Act, Anti-Money Laundering, OFAC, and Information Security policies and procedures. * Completes annually required compliance related courses and required Product and Process Knowledge competency testing, in addition to job related courses. * You may be expected to perform other duties as assigned ## Related Videos - [Agentic employees in world's most downloaded FinTech app](https://www.wearedevelopers.com/videos/100123-agentic-employees-in-world-s-most-downloaded-fintech-app) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Synthetic Insiders: The New AI Risk to Your Org](https://www.wearedevelopers.com/videos/100057-synthetic-insiders-the-new-ai-risk-to-your-org) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)