Enter a job title or keyword

Senior Cybersecurity Governance Analyst

Civic Credit Union


Job Location:

Raleigh, WV - USA

Monthly Salary: Not provided by the employer
Posted: 27 July 2026 (30+ days ago)
Application Deadline: 24 October 2026
Vacancies: 1 Vacancy

Job Summary

Full-time
Description

OUR CULTURE

Our organization believes we can all do well by doing good. We value the contributions of diverse minds and prioritize the success and well-being of our employees. We also believe every person in our organization plays a role in supporting a healthy environment and helping to achieve our goal of prosperity for all. To this end we recruit bright energetic and talented people to be members of our return we offer a dynamic workplace that presents opportunities for professional advancement and individual growth. We strive to always display integrity self-awareness courage and respect for one another while continuing to seek opportunities to learn. We really believe that when our employees succeed our community wins.


ABOUT THE POSITION

The Senior Cybersecurity Governance Analyst provides second-line oversight of the organizations cybersecurity risk management program by leading security architecture governance threat-informed risk analysis vulnerability management oversight and independent security assurance activities. This role ensures cybersecurity risks are identified evaluated communicated and managed in alignment with the organizations risk appetite regulatory requirements and strategic objectives. The Senior Cybersecurity Governance Analyst serves as a key advisor to technology business and risk stakeholders by providing independent challenge governance oversight and risk-informed recommendations to strengthen the organizations overall cybersecurity posture.


NORMAL DAY-TO-DAY WORK

  1. Conduct independent risk-based reviews of system network application cloud and third-party architectures to identify cybersecurity risks and evaluate alignment with security policies standards and secure-by-design principles.
  2. Provide governance oversight of network segmentation identity management cloud security and infrastructure security initiatives identifying risks and recommending appropriate mitigating controls.
  3. Participate in project governance and system development lifecycle processes to ensure cybersecurity risks are identified assessed and addressed throughout technology initiatives.
  4. Perform cybersecurity risk assessments for technology initiatives applications infrastructure changes and third-party services evaluating threats vulnerabilities control effectiveness and residual risk exposure.
  5. Facilitate risk acceptance exception management and remediation tracking processes ensuring cybersecurity risks are appropriately documented communicated and managed in alignment with organizational risk tolerance.
  6. Support enterprise and operational risk management activities through risk analysis reporting and communication.
  7. Monitor and assess relevant threat intelligence sources and industry threat activity to identify emerging cyber threats and evaluate potential impacts on organizational risk exposure.
  8. Translate threat intelligence into risk informed recommendations for control enhancements mitigation strategies and cybersecurity planning.
  9. Provide independent oversight of the vulnerability management program including review of prioritization methodologies and validation of remediation plans for critical and high-risk vulnerabilities.
  10. Monitor remediation performance against established service level objectives and provide reporting on vulnerability trends exposure metrics program effectiveness and significant risk conditions.
  11. Coordinate and oversee penetration testing red team assessments and independent security reviews; evaluate results and ensure identified risks are appropriately addressed and remediated.
  12. Develop and maintain cybersecurity metrics dashboards risk reporting policies standards and control frameworks while contributing to cybersecurity strategy maturity improvement initiatives and governance committee activities as a subject matter expert on cybersecurity risk and governance matters.
  13. Display integrity self-awareness courage and respect for staff while ensuring learning agility and flexibility communicating and delegating effectively. Work effectively collaboratively and creatively in a team-oriented environment both internally and externally.


JOB QUALIFICATIONS

Here are a few skills you MUST have to be qualified for this position.

  1. Minimum of 7-9 years of experience in cybersecurity governance risk management security architecture security assurance vulnerability management or related disciplines.
  2. Strong understanding of cybersecurity frameworks including NIST Cybersecurity Framework (CSF) NIST SP 800-53 FFIEC ACET CIS Controls and industry best practices.
  3. Experience conducting cybersecurity risk assessments and evaluating control effectiveness.
  4. Knowledge of secure architecture principles across cloud network application and identity platforms.
  5. Understanding of threat intelligence vulnerability management and cybersecurity risk analysis methodologies.
  6. Experience supporting audits regulatory examinations and compliance initiatives.
  7. Strong analytical communication presentation and report writing skills.
  8. Ability to function in a Consumer business office environment and utilize standard office equipment including but not limited to: PC copier telephone etc.
  9. Ability to lift a minimum of 25 lbs. (file boxes computer).
  10. Travel required on occasion.


Here are a few qualities wed LIKE for you to have to make you more suited for this position.

  1. BA/BS degree in Cybersecurity Information Technology Information Systems Risk Management or a related field.
  2. Experience in financial services credit unions or highly regulated industries.
  3. Familiarity with threat intelligence frameworks MITRE ATT&CK CVSS and EPSS.
  4. Experience supporting board or executive-level cybersecurity reporting.
  5. Professional certifications such a CISSP CRISC CISM CGRC CISA and/or GIAC (GCTI GSEC or equivalent).





Required Experience:

Senior IC


About Company

Company Logo

The North Carolina credit union for local government employees, elected and appointed officials, volunteers and their families.

View Profile View Profile