> Markdown version of [/jobs/ext/3388309-cybersecurity-analyst](https://www.wearedevelopers.com/jobs/ext/3388309-cybersecurity-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst - **Company:** Financial Plus Credit Union - **Location:** Flint, MI, United States - **Experience:** Expert - **Salary:** $85,000.0 - $95,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Artificial Intelligence, Audit Trail, Microsoft Azure, Bash Shell, Cloud Computing Security, Configuration Management, CompTIA Security+, Cyber Security, System Configuration, Information Leak Prevention, Identity and Access Management, Virtual Private Networks (VPN), Python (Programming Language), Network Security, Microsoft Security Essentials, Network Segmentation, Windows PowerShell, Cloud Services, Anti-Phishing, Microsoft SharePoint, Security Information and Event Management, Software Vulnerability Management, Data Logging, Scripting, Cloud Platform System, Firewalls (Computer Science), Microsoft InTune, Information Technology, Patch Management, CIS Benchmarks, Firewall Services Module, Network Server - **Published:** September 2, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8c6c45ed1983a02f ## About the Role * 5+ years of experience in an infrastructure or security role, with a heavy infrastructure background (servers, networking, endpoints, identity). * Hands-on experience with a modern security stack such as Cato Networks (SASE/SSE) or CrowdStrike (EDR/XDR). * Base scripting proficiency in PowerShell, Bash, and Python for automation, data parsing, and security tooling. * Demonstrated experience with vulnerability management and patch management programs and tooling. * Working knowledge of Microsoft 365 administration and security hardening. * Hands-on experience securing and administering Microsoft Azure. * Solid understanding of security best practices, frameworks, and controls across on-premises and cloud environments. * Strong analytical, documentation, and communication skills with the ability to work independently as an individual contributor., * Experience in financial services and familiarity with related audit and regulatory bodies (e.g., NCUA, state examiners, external auditors). * CompTIA Security+ certification (or equivalent security certification). * Experience securing artificial intelligence (AI) tools, services, and data - including responsible AI usage and governance. * Experience assessing risk and creating qualitative and quantitative risk assessments to evaluate and prioritize security exposures. * Additional certifications such as Microsoft SC-200/AZ-500, CrowdStrike, or Cato administration credentials. Skills and Abilities * Infrastructure and cloud security across on-premises, Microsoft 365, and Azure environments. * Vulnerability and patch management, including scanning, prioritization, and remediation tracking. * Endpoint and network defense, including EDR/XDR, SASE/SSE, firewall, and segmentation controls. * Microsoft security tooling, including Purview (DLP, sensitivity labels), Intune, and Entra ID. * SIEM administration, log monitoring, and correlation to support detection and incident response. * Base scripting and automation with PowerShell, Bash, and Python. * Detail-oriented and self-directed, with a strong audit and compliance mindset. * Clear documentation and communication skills across technical and non-technical audiences. * Represents FPCU with professionalism and purpose, communicating with members through respectful and solution-focused verbal and written communications that support a member-focused experience. * Engages in effective interpersonal communication, diplomacy, and collaboration skills to develop productive relationships, encourage cooperation, and support positive member and employee experiences. Maintains compliance with all applicable policies, demonstrating integrity, respect, and accountability while handling sensitive information and complying with FPCU policies, regulatory expectations, and confidentiality requirements. * Ability to apply logistical reasoning, analytical skills, and professional judgment to define and solve problems with effective and compliant solutions. * Adaptable, resilient, and comfortable navigating change in a fast-moving environment * Embraces innovation and continuously seeks better ways to serve members and support teams ## Description Financial Plus Credit Union is seeking a hands-on Cybersecurity Analyst with a strong infrastructure background to help protect our members, systems, and data. This individual contributor will own day-to-day security operations across our endpoint, network, and cloud environments - including vulnerability management, patching, and hardening of Microsoft 365 and Azure. The ideal candidate blends deep infrastructure knowledge with practical security experience and thrives in a fast-paced financial services environment governed by regulatory and audit requirements. Essential Functions & Primary Responsibilities The candidate will own day-to-day security operations and help embed security across the credit union's infrastructure, endpoint, network, and cloud environments. This includes, but is not limited to: * Administer, tune, and monitor the organization's security stack (e.g., Cato SASE and/or CrowdStrike EDR/XDR), responding to alerts, investigating incidents, and driving remediation. * Lead the vulnerability management lifecycle - scanning, triaging, prioritizing, and tracking remediation of vulnerabilities across servers, endpoints, and cloud workloads. * Own and improve the patch management program, ensuring operating systems, applications, and infrastructure are consistently updated and compliant. * Harden and secure Microsoft 365 (Exchange Online, SharePoint, Teams, Entra ID) using secure baselines, conditional access, and MFA. * Administer and mature Microsoft Purview capabilities, including Data Loss Prevention (DLP), sensitivity labels, retention policies, audit logging, eDiscovery support, insider risk signals, and compliance evidence collection to protect member and organizational data. * Manage Microsoft Intune endpoint security responsibilities, including device compliance policies, configuration profiles, security baselines, device enrollment, conditional access integration, and remediation of non-compliant endpoints. * Configure, monitor, and secure Microsoft Azure resources, applying cloud security best practices, identity governance, and least-privilege access. * Apply and enforce security best practices including network segmentation, endpoint protection, logging, monitoring, and configuration management. * Administer and maintain firewall policies, including rule reviews, segmentation controls, VPN/security access, logging, and coordination of network security changes. * Develop, review, and enforce Group Policy settings to support secure workstation and server configurations, hardening standards, and consistent endpoint controls. * Manage email security controls, including phishing protection, attachment and URL defense, quarantine review, policy tuning, and investigation of suspicious messages. * Coordinate security awareness training and phishing simulation activities, including user education, campaign support, reporting, and follow-up guidance for employees. * Leverage APIs and base scripting in PowerShell, Bash, and Python to automate security operations, integrate tooling, extract and correlate data, and streamline repetitive tasks across on-premises and cloud environments. * Support security audits, examinations, and assessments by gathering evidence, documenting controls, and helping remediate findings for regulatory and audit bodies. * Contribute to security policies, standards, and procedures, and promote security awareness across the organization. * Assist with incident response activities, including detection, containment, eradication, recovery, and post-incident reporting. * Collaborate with infrastructure and application teams to embed security into projects, migrations, and new technology rollouts. * Must be flexible and able to work unusual and variable hours/schedules, without supervision, including but not limited to holidays, evenings or weekends. * Enforces compliance with all federal and state laws and regulations, including the Bank Secrecy Act (BSA), Patriot Act, and Office of Foreign Asset Controls (OFAC) requirements, and should request legal interpretation as necessary to identify compliance concerns. * Adhere to applicable federal and state laws, regulations, and internal compliance with standard polices relevant to their roles and responsibilities. * Perform other duties as assigned. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)