Civic Federal Credit Union · RALEIGH, NC

Salary
Posted
Jul 21, 2026
Location
RALEIGH, NC
Last confirmed open
Jul 23, 2026

What this job asks for AI summary

A second-line cybersecurity governance role focused on independent oversight of an organization's risk management program. Day-to-day work spans security architecture reviews, threat intelligence analysis, vulnerability management oversight, and risk assessments across cloud, network, application, and third-party environments. Suited to an experienced cybersecurity professional with a background in governance, risk, or security assurance, ideally within a regulated industry.

Senior level · 7+ years · Full-time

Must have (10)
NIST Cybersecurity FrameworkFFIEC ACETCIS Controlscybersecurity risk assessmentscloud securitynetwork securityidentity managementvulnerability managementthreat intelligencepenetration testing
Nice to have (4)
MITRE ATT&CKCVSSEPSSCISSP, Crisc, Cism, Cgrc, Cisa or Giac

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
vulnerability management55%network security45%identity management45%cloud security42%NIST Cybersecurity Framework40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (6)

The 7–9 year experience range is stated as a hard requirement; the overall years minimum is set to 7 (the lower bound).

A BA/BS degree is listed under the 'nice to have' section, so it is not treated as a hard requirement.

Professional certifications (CISSP, CRISC, CISM, CGRC, CISA, GIAC) are listed under preferred qualifications; CISSP is used as the primary skill name with the others captured as alternatives.

MITRE ATT&CK, CVSS, and EPSS appear only under the preferred qualifications section.

The alternative occupation runner-up (15-1211 Computer Systems Analysts) reflects the governance, architecture review, and risk-advisory dimensions of the role, though the primary security analysis and risk management focus makes 15-1212 the clear primary.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗