This role is essential for safeguarding the Credit Unions digital assets by performing comprehensive security assessments, including network penetration tests, web and mobile application evaluations, and phishing tests. The role identifies and addresses security vulnerabilities, ensuring compliance with industry best practices and internal policies, thereby preventing system compromise and protecting sensitive information. Additionally, the role promotes a culture of security awareness and supports strategic initiatives to enhance the Credit Unions cybersecurity posture, ultimately building trust and confidence among members.
Work Arrangement - This position is a fully remote role within the state of Michigan or Illinois.
Schedule - Monday - Friday 8:30am - 5:00pm ET
An offer of employment with MSU Federal Credit Union and affiliates is contingent upon the agreed work arrangement (onsite/hybrid/remote) and work location. MSU Federal Credit Union may or may not be able to accommodate temporary or permanent changes to work arrangements or allow employment outside the city and/or state of residency in which the new hire resides at the time of offered employment.
Compensation & Benefits:
Essential Duties and Responsibilities:
Ethical Hacker I:
Perform network penetration tests, web application security assessments, mobile application security assessments, wireless network assessments, red team assessments and phishing tests for the Credit Union within scheduled time frames following industry best practice methodologies.
Identify, develop, and document security issues and recommendations using independent judgment concerning areas being reviewed.
Communicate results, suggestions, and/or findings via written reports and oral presentations to Credit Union management, the President/CEO and the Board of Directors.
Conduct security assessments of third-party applications utilized by the Credit Union within scheduled time frames.
Stay updated with the latest cybersecurity trends, tools, and techniques to continuously improve testing methodologies and security practices.
Assist with the coordination and performance of all contracted penetration testing projects and services conducted by third-party vendors.
Evaluate the Credit Union's risk areas and provide key input to the development of the annual penetration testing plan.
Promote a culture of security awareness within the organization through administration of phishing simulation and other best practice and emerging threat training sessions.
Understand the Credit Unions policies and procedures to ensure compliance and accountability for managing operational risks. Adhere to established internal controls and procedures to safeguard assets, prevent fraud, and maintain the integrity of credit union operations.
Perform other duties as assigned
Sr. Ethical Hacker:
Develop, implement, and refine advanced penetration testing techniques to identify vulnerabilities in our systems. Apply ethical hacking tools in an innovative and comprehensive manner to increase the Credit Union's cybersecurity posture.
Support the Credit Union strategic direction and initiatives while helping others understand the purpose of decisions and direction.
Proactively seek out and identify new areas of potential risk and opportunities for security improvements. This involves conducting thorough assessments of emerging threats and vulnerabilities and recommending strategic initiatives to enhance our security posture.
Serve as a recognized subject matter expert across the Credit Union and contribute security and control insights on strategic and innovative projects.
Job Requirements:
Ethical Hacker I:
High School Diploma or equivalent required.
This position requires a Bachelor's degree or equivalent experience in computer science, information technology, or related field.
Prior experience in penetration testing, vulnerability assessments, or related security testing activities is required.
GIAC GPEN, GIAC GWAPT, or pursuit of similar designation is preferred.
Sr. Ethical Hacker:
Prior experience leading a program or independently managing offensive security operations in professional penetration testing and/or vulnerability assessment.
GIAC GPEN, GIAC GWAPT, or pursuit of similar designation is required.
Competencies:
Physical Demands and Work Environment:
Disclaimer:
| Location | MI (Remote) |
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder