IS Analyst
Southland Holdings, Inc. · California
📍 Los Alamitos, CA💰 $79,000-$95,000via icimsPosted 2026-08-11
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Southland Holdings, Inc..
Role
About the Role
Information security is about more than protecting systems—it’s about protecting the trust members place in Southland Credit Union. As an IS Analyst, you’ll help identify where that trust could be at risk, evaluate how effectively security controls are working, and turn complex security and regulatory requirements into practical recommendations.
This role sits at the intersection of cybersecurity, risk, compliance, and the business. You’ll serve as a subject matter expert, helping leadership and business teams understand security risks, determine appropriate responses, and strengthen the practices that protect Southland’s information and services.
For someone who enjoys digging into complex issues, asking the right questions, and turning technical or regulatory information into clear guidance, this is an opportunity to have a meaningful voice in how a regulated financial institution manages information security.
Major Duties and Responsibilities
Where Your Security Expertise Makes a Difference A key part of your work will be understanding where risk exists and what should be done about it. You’ll lead enterprise information security risk assessments by evaluating threats, vulnerabilities, business impact, likelihood, and residual risk. You’ll also assess security controls and critical business processes to determine how effectively they address risk and where improvements may be needed.
Your analysis will help translate risk into decisions. You’ll advise management on cybersecurity threats, security exceptions, risk treatment strategies, and opportunities to strengthen the organization’s security posture. You’ll also guide business teams on security requirements, policy expectations, and appropriate control strategies, helping them understand not only what is required, but how those requirements can be applied in practice.
Turning Requirements Into Practical Security Working in a regulated financial institution means security decisions must account for both business needs and regulatory expectations. You’ll interpret requirements and recognized frameworks, including NCUA, GLBA, NIST, and ISO 27001, and help translate them into practical security and compliance guidance.
You’ll develop and maintain information security policies, standards, procedures, and governance documentation that support a strong security program. You’ll also support internal and external audits by evaluating evidence, developing responses, explaining security controls, and helping prioritize remediation efforts.
When security events or vulnerability assessment results identify potential exposure, you’ll analyze the business impact and risk involved and help determine appropriate remediation priorities. You’ll bring that same analytical approach to strategic security initiatives and enterprise improvement projects, identifying ways to strengthen governance, improve processes, increase security maturity, and use automation to support security and compliance goals.
Success in this role means more than identifying risk. It means helping the organization understand that risk and providing thoughtful, practical recommendations that support informed decisions.
Knowledge and Skills
What Helps You Succeed Experience • 4–6 years of experience in information security, cybersecurity, risk management, compliance, or IT audit.• Demonstrated experience conducting information security risk assessments, evaluating security controls, interpreting regulatory requirements, and developing governance documentation.• Experience advising management or business stakeholders on cybersecurity risks and recommendations.• Experience with security control assessments, regulatory compliance activities, or internal/external audits is preferred.• Working knowledge of security tools and technologies.
Education • Bachelor’s degree in Information Security, Cybersecurity, Information Systems, Computer Science, or a related field, or an equivalent combination of education and relevant experience.
You’ll Be at Your Best in This Role If You... • Enjoy analyzing complex information and using structured problem-solving to determine practical next steps.• Can assess risk, consider business impact, and use sound independent judgment when making recommendations.• Understand information security governance, risk management, compliance, and cybersecurity practices.• Can take complex regulatory requirements or security frameworks and translate them into clear, practical guidance for non-technical stakeholders.• Communicate clearly in both written and verbal settings and are comfortable working with people at different levels of an organization.• Can work independently while also collaborating effectively with business teams and other stakeholders.• Stay organized, pay close attention to detail, and manage competing priorities without losing sight of what matters most.• Approach sensitive information and security decisions with discretion, accountability, and a strong commitment to ethical decision-making.• Are comfortable using standard office technology and systems.
Preferred Qualifications • Professional certification such as CISSP, CISA, CISM, or equivalent.• Experience working in a regulatory environment.• Experience with Governance, Risk, and Compliance (GRC) platforms.• Experience supporting financial services, credit unions, or similarly regulated organizations.
Why Southland? Protecting information and managing security risk is an important part of People Helping People. The work behind the scenes helps ensure that members and associates can rely on the systems, information, and services they use every day.As an IS Analyst, your expertise will reach across the organization. You’ll work with leadership and business teams, support audit and compliance efforts, contribute to strategic security initiatives, and help turn identified risks into inform
More California jobs
California jobs · Browse all locations