Cyber Security Analyst
Cyber security analyst job in New York, NY
Job Title: Sr. Cybersecurity Risk Analyst
Duration: 24+Months
Responsibilities:
Build new risk processes and implement risk frameworks to enable better monitoring and evaluation of risks across the City;
Manage complex, cross-functional projects, pushing through ambiguity and challenges which may arise;
Work with stakeholders across various divisions, soliciting input and working through feedback;
Evaluate risk of third parties used by New York City agencies;
Document and track remediation of risks in the Risk Register;
Review and analyze various cybersecurity risk cases, justification, and exceptions documents submitted by agencies;
Assist in the development of cybersecurity risk assessment procedures and testing methodologies based on established frameworks and guidelines;
Initiating corrective actions to remediate vulnerabilities or weaknesses where necessary;
Engage in communications with NYC Agencies;
Handle special projects and initiatives as assigned.
Required Sklls:
A minimum of 4 years of experience in risk management or cybersecurity risk assessment or 4 years of experience evaluating and managing third parties in a cybersecurity team.
DESIRABLE SKILLS/EXPERIENCE:
BS/BA degree in Cybersecurity, Risk Management, Information Systems, Computer Science, or a related field.
One or more of the following certifications are a plus:
Certified Information Systems Auditor (CISA)
Certified Information Systems Security Professional (CISSP)
Certified in Risk and Information Systems Control (CRISC)
Certified Information Security Manager (CISM)
CompTIA Security+
CompTIA Network+
CompTIA A+
CompTIA CySA+
Cisco Certified Network Associate - CCNA
CEH: Certified Ethical Hacker
GIAC Information Security Fundamentals (GISF)
GIAC Security Essentials (GSEC)
(ISC)2 Systems Security Certified Practitioner (SSCP)
Ability to work effectively in a team environment.
Being highly organized, motivated and a self-directed professional.
Knowledge of hardware, software, data, and network principles and systems related to Private and/or Public Sectors services.
Understanding of commonly used computer operating systems, databases, network structures.
Familiarity with cybersecurity framework(s) (NIST, SANS, PCI, ISO 27001/27002, or CIS)
Investigative and analytical skills.
Excellent oral and written communication skills;
Knowledge of the current and evolving cyber threat landscape;
Knowledge of laws, regulations, policies, and ethics related to cybersecurity and information privacy;
Cyber Security Analyst
Cyber security analyst job in New York, NY
Job Title: Cyber Security Risk Analyst.
Job Type: Contract.
IS NOT OPEN TO AGENCIES.
The Cyber Security Risk Analyst supports enterprise governance, risk, and compliance (GRC) initiatives by strengthening cyber risk management practices, enhancing third-party risk oversight, and contributing to cybersecurity governance across a complex organizational environment. This role works closely with cybersecurity leadership, internal stakeholders, and partner teams to mature risk assessment processes and ensure consistent, well-documented risk management activities.
Key Responsibilities
Design, develop, and enhance cybersecurity risk management processes and supporting frameworks
Support enterprise cyber risk governance, including risk identification, evaluation, and remediation tracking
Perform cybersecurity risk assessments in collaboration with business and IT stakeholders
Evaluate and manage third-party and vendor cybersecurity risk throughout the vendor lifecycle
Contribute to the development and maintenance of a third-party risk register
Review and analyze cybersecurity risk cases, exceptions, and justifications
Document risks, mitigations, and remediation actions within a centralized risk register
Assist in developing risk assessment procedures, methodologies, and testing approaches aligned with industry frameworks
Collaborate with cross-functional teams and subject matter experts to gather risk intelligence
Support remediation efforts by helping initiate corrective actions where vulnerabilities or weaknesses are identified
Participate in special cybersecurity initiatives and projects as assigned
Required Qualifications
Minimum of 4 years of experience in one or more of the following areas:
Cybersecurity risk management
Cybersecurity risk assessment
Third-party or vendor risk management within a cybersecurity function
Strong understanding of GRC concepts and the cyber risk lifecycle
Experience working in large, complex, multi-stakeholder environments
Strong analytical, investigative, and documentation skills
Excellent written and verbal communication skills
Preferred Qualifications
Bachelor's degree in Cybersecurity, Risk Management, Information Systems, Computer Science, or a related field
Familiarity with one or more cybersecurity frameworks or standards, including:
NIST
ISO/IEC 27001 / 27002
CIS
SANS
PCI
Relevant certifications are a plus, including but not limited to:
CISSP, CISM, CRISC, CISA
CompTIA Security+, CySA+, Network+
GIAC certifications
Knowledge of cybersecurity laws, regulations, and data privacy principles
Ability to work independently in a self-directed and organized manner
About Buchanan Technologies
Since Buchanan's inception over 30 years ago, we have operated on 5 core values - People Matter, Customers Matter, Principles Matter, Community Matters, and Every Interaction Matters. These values are represented across each facet of the company, from employee relations to client service delivery to corporate social responsibility initiatives and beyond.
Why Work at Buchanan?
At Buchanan Technologies, we offer a great employment experience with a fun but professional work environment, competitive salary, and various employee career advancement programs that add value to your skills and daily life. If you are excited about being part of an energetic team where your contributions are appreciated and hard work is recognized, Buchanan is the place for you.
Things We Are Passionate About
We are passionate about providing top-tier technology services to our customers and clients and fostering a culture of continuous learning for our employees. We are a people- centric company, focused on growth and diversity for our workforce. Come join us and let's build something amazing together.
Follow Us:
LinkedIn: *******************************************************
Website: ****************
Buchanan Technologies provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, protected veteran status, or genetics. In addition to federal law requirements, Buchanan Technologies complies with applicable state and local laws governing nondiscrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
Cyber Security Engineer
Cyber security analyst job in New York, NY
JOB FUNCTION
The Cybersecurity Engineer will be responsible for implementing and maintaining the firm's cybersecurity technology solutions, monitoring for security incidents and vulnerabilities, coordinating end user activities, and participating in the investigation and response of any breaches or attacks. The ideal candidate will be a self-starter who can work both independently and collaboratively with diverse technical and business teams. He or she will report to the Chief Information Security Officer. Additional responsibilities include:
Managing the vulnerability management program, including internal and external scanning, monitoring threat feeds, news sources, and vendor bulletins for risks and tracking remediation
Maintaining and monitoring control baselines, hardening standards, asset/coverage metrics, and configuration compliance
Monitoring and documenting key performance indicators (KPIs) and governance, risk, and compliance (GRC) evidence
Suggesting and evaluating new technologies
Educating employees on security best practices to reduce the risk of human error
Collaborating with the Cloud, Systems, Network, Database, Desktop, and Development engineering teams on risk identification, analysis, and remediation
Assisting with vendor due diligence
Assisting with physical security infrastructure projects, maintenance, and updates
QUALIFICATIONS
The ideal candidate should have the following experience:
3+ years of experience in a Security Engineer role
Proficiency with managing EDR solutions, SIEM, network security, cloud security, mobile security, vulnerability management, identity and access management, encryption, and a solid understanding of operating systems like Windows and Linux
Strong ability to analyze security data, identify threats, and create effective solutions
Ability to document and communicate technical information clearly to both technical and non-technical audiences
Scripting/automation experience a plus
The ideal candidate possesses the following traits:
Creativity: the ability to deploy different approaches and be resourceful.
Intellectual curiosity: passion for learning and investigating a broad range of subject matter; satisfaction derived from the consumption and understanding of information and increasing knowledge base.
Accountability: ownership of individual responsibilities and work product.
Strong people skills: ability to build relationships internally and externally and to be versatile in engaging with different constituents.
Cyber Security Engineer (CyberArk)
Cyber security analyst job in New York, NY
We are seeking a highly skilled and motivated CyberArk PAM Administrator to support the deployment, configuration, and ongoing management of privileged access management (PAM) and cybersecurity technologies. This role is ideal for a cybersecurity professional who enjoys working in collaborative environments, driving secure system design, and supporting enterprise-scale security initiatives.
The successful candidate will play a key role in implementing new cybersecurity solutions, supporting infrastructure upgrades, and ensuring systems are secure, reliable, and well-documented. This position offers the opportunity to work with modern security platforms while contributing to the organization's overall cyber maturity and growth.
Key Responsibilities
Implement and support new deployments of cybersecurity technologies, including CyberArk PAM and related security products.
Assist with infrastructure upgrades to support application growth and evolving cybersecurity requirements.
Configure, deploy, and maintain systems in accordance with security best practices and architectural standards.
Troubleshoot and support all aspects of CyberArk Privileged Access Management, including onboarding, vault management, and access controls.
Develop and maintain technical documentation, procedures, and runbooks for daily operations and major initiatives.
Propose and document system architectures for secure and scalable deployments.
Collaborate with internal teams, vendors, and stakeholders to ensure successful technology implementations.
Patch, maintain, and monitor security platforms to ensure system stability and compliance.
Train team members and end users on new systems and security processes as needed.
Follow up promptly with stakeholders to address issues, changes, and enhancements.
Required Skills / Education
Proven experience as a CyberArk Administrator or in a similar Privileged Access Management role.
Hands-on experience troubleshooting and supporting CyberArk PAM components.
Strong understanding of cybersecurity principles, access control, and secure system administration.
Ability to create clear, detailed technical documentation and operational procedures.
Excellent written and verbal communication skills, with the ability to work effectively across technical and non-technical teams.
Preferred Qualifications
Experience with scripting or programming languages.
Hands-on experience with PowerShell.
Familiarity with enterprise infrastructure environments and security integrations.
Strong interpersonal skills and the ability to collaborate with stakeholders at all organizational levels.
About Seneca Resources
At Seneca Resources, we are more than just a staffing and consulting firm-we are a trusted career partner. With offices across the U.S. and clients ranging from Fortune 500 companies to government organizations, we provide opportunities that help professionals grow their careers while making an impact.
When you work with Seneca, you're choosing a company that invests in your success, celebrates your achievements, and connects you to meaningful work with leading organizations nationwide. We take the time to understand your goals and match you with roles that align with your skills and career path. Our consultants and contractors enjoy competitive pay, comprehensive health, dental, and vision coverage, 401(k) retirement plans, and the support of a dedicated team who will advocate for you every step of the way.
Seneca Resources is proud to be an Equal Opportunity Employer and is committed to fostering a diverse and inclusive workplace where all qualified individuals are encouraged to apply.
Vice President, Application Cyber Security Specialist
Cyber security analyst job in Iselin, NJ
Job information:
Functional title - Application Security Specialist
Department - IT Security
Corporate level - Vice President
Report to - Director, Application Security
Expected full-time salary range between $ 140,000- $180,000 + variable compensation + 401(k) match + benefits.
What you will be doing:
Perform Application Security scans (e.g. DAST and SCA) on applications and APIs to identify security vulnerabilities and weaknesses,
Triage security findings and collaborate with development teams to prioritize and remediate identified vulnerabilities.
Drive threat modelling as a standard part of the SDLC, and develop and maintain threat models for critical applications, identifying potential security risks and proposing mitigations.
Drive the Security Champions program, and define and promote secure coding practices, patterns, and standards across development teams.
Conduct security reviews and provide guidance on security requirements for new features and projects.
Assist in the analysis, selection and rollout of new application security tools, processes, and standards.
Stay up to date with the latest security threats, vulnerabilities, and industry best practices.
What we're looking for:
Proven experience in application security with a focus on application security testing and vulnerability management.
Hands-on experience with Application Security tools.
Strong understanding of common application vulnerabilities (e.g., OWASP Top 10) and mitigation techniques.
Experience with threat modelling methodologies and tools.
Proficiency in at least one programming language (e.g., Java, Python, JavaScript).
Excellent communication and collaboration skills, with the ability to work effectively in cross functional teams.
Strong understanding of risk management.
Professional qualifications / certifications
Degree in a technology discipline (Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent).
Relevant security certifications (e.g. CISSP, CEH, CSSLP) or equivalent is preferred.
IGA/Security Analyst
Cyber security analyst job in New York, NY
Client: Metropolitan Transportation Authority
Job Title: IGA/Security Analyst
Duration: 12+Months
Contract
Number of Hours: 37.50 Hrs/Week
Interview Type: Either Webcam Interview or In Person
Ceipal ID: MTA_SECU154_MA
Requirement ID: 5154-1
**PLEASE NOTE THIS POITION WILL ALLOW CONSULTANT TO WORK A HYBRID REMOTE SCHEDULE.
UPON START DATE CONSULTANT WILL BE REQUIRED TO WORK FIRST MONTH FULLY ONSITE. ONCE WORK CAPABILITY IS ESTABLISHED, CONSULTANT WILL BE ALLOWED TO WORK A HYBRID REMOTE SCHEDULE CONSISTING OF 3 DAYS ONSITE/ 2 DAYS REMOTE. ASLO HOURS PER WEEK IS 37.5 NO OVERTIME**
Overview: The IGA Analyst will play a critical role in strengthening the organization's identity security posture across corporate, frontline, and operational technology (OT) environments. This role will focus on onboarding applications into the enterprise IGA platform, modernizing authentication through FIDO2 and passwordless technologies, and reducing technical debt through effective governance and lifecycle management controls.
The ideal candidate has hands-on experience with major IGA, PAM, and MFA platforms, possesses a strong understanding of Active Directory and Entra ID, and can collaborate with cross-functional teams to implement scalable identity controls that align with Zero Trust principles.
KEY RESPONSIBILITIES:
**Application Onboarding & Integration**
* Partner with application owners to onboard and certify applications within the IGA platform (e.g., SailPoint, Saviynt, or Oracle).
* Define and enforce access models, entitlements, and approval workflows for new and existing applications.
* Establish least-privilege and segregation-of-duties (SoD) controls within IGA.
**Identity Security Posture & Technical Debt Reduction**
* Identify and remediate identity risks such as orphaned accounts, excessive entitlements, and privileged access sprawl.
* Contribute to ongoing cleanup initiatives for AD, Entra ID, and connected systems to align with modern identity hygiene standards.
* Support implementation of risk-based access policies and automated lifecycle management processes.
**Authentication Modernization**
* Support the adoption of phishing-resistant authentication methods, including FIDO2 security keys and passwordless sign-ins.
* Collaborate with MFA and SSO platform teams to migrate legacy authentication flows to modern protocols (e.g., WebAuthn, OIDC, SAML).
* Evaluate user experience, security impact, and deployment readiness across diverse user populations (corporate, frontline, OT).
**Federation & Access Management**
* Configure and manage federated SSO integrations via Entra ID and other IdPs.
* Apply conditional access and adaptive authentication policies based on user risk, device health, and context.
* Coordinate with PAM teams to align privileged session management with federated access controls.
**Cross-Domain Collaboration**
* Partner with security architecture, IAM engineering, and compliance teams to ensure IGA controls meet enterprise and regulatory standards.
* Document and report on metrics related to access certifications, compliance posture, and identity lifecycle performance.
* Provide operational support for IGA platform maintenance, upgrades, and new integrations.
QUALIFICATIONS
* Bachelor's degree in Information Security, Computer Science, or related field (or equivalent experience).
* 3-5 years of hands-on experience in Identity Governance & Administration (IGA).
* Strong knowledge of Active Directory, Entra ID, and federated authentication protocols (SAML, OIDC, OAuth2).
* Familiarity with one or more of the following platforms:
* IGA: SailPoint, Saviynt, Oracle IDCS
* PAM: BeyondTrust, CyberArk, ManageEngine PAM360
* MFA/SSO: Microsoft Entra ID, Duo, Okta, Ping Identity
* Working knowledge of Zero Trust, FIDO2, passwordless, and phishing-resistant MFA concepts.
* Experience applying IGA controls for diverse user types (corporate, frontline, OT).
* Strong analytical, documentation, and communication skills; ability to collaborate across technical and business teams.
Additional Skills and Information:
* Experience with identity lifecycle automation and role-based access control (RBAC) modeling.
* Understanding of privilege escalation risks, identity threat detection, and compliance frameworks (NIST 800-63B, CIS, TSA, etc.).
* Scripting knowledge (PowerShell, Python, or SQL) for data analysis or automation.
* Familiarity with cloud identity models (Azure, AWS, GCP).
V Group Inc. is a NJ based IT Services and Products Company with its business strategically categorized in various Business Units including Public Sector, Enterprise Solutions, Professional Services, Ecommerce, Projects, and Products. Within Public Sector business unit, we cater IT Professional Services to Federal, State and Local. We have multiple awards/ contracts with 30+ states, including but not limited to NY, CA, FL, GA, MD, MI, NC, OH, OR, CO, CT, TN, PA, TX, VA, NM, VT, and WA.
If you are considering applying for a position with V Group, or in partnering with us on a position, please feel free to contact me for any questions you may have regarding our services and the advantages we can offer you as a consultant.
Please share my contact information with others working in Information Technology.
Website: **************************************
LinkedIn: *****************************************
Facebook: *********************************
Twitter: *********************************
Senior Security Engineer
Cyber security analyst job in New York, NY
You will provide guidance and technical support to clients deploying security integrations. You'll act as the technical partner, providing strategic guidance around complex systems to secure a digital environment. Interacting directly with the client, you'll partner closely with client personnel to guide and suggest integrations to better serve their success. Your thorough understanding of our product integrations contributes to the development of new principles and concepts - providing detailed analysis around what's working, what's not, and what could be better.
You enjoy implementation work, are proactive about resolving potential concerns, and operate well around strict best practices that enable our clients on their road to a more secure digital world. You're creative, innovative, and you love a challenge - learning how integrations might work better around new products and technologies.
Responsibilities
Communicate with the customer(s), sales teams, peers, engineering and support teams as appropriate
Understand the customer environment, requirements, and security roadmap to implement the appropriate security solution
Configure, implement, and maintain Security Operating Platform
Optimize and migrate policies and objects from the existing environment to our Next-Gen Firewall
Test and validate the migration environment
Coordinate and execute cutover to production
Provide guidance on code upgrades
Facilitate the development of new application and threat signatures
Interact with our Technical Assistance Center (TAC) to understand and diagnose support cases
Some travel may be required, dependent on customer request
You work with the customer's security & network teams to build confidence across the business units impacted by the change
Experience
High level of experience with Panorama and log collectors
NGFW
Global Protect
BS in Computer Science, MIS, business, or equivalent education/training/experience
Minimum of 5 years' experience with network/security solutions and technologies (BGP, SD-WAN concepts, VXLAN and general routing and switching)
Minimum of 3 years' experience leading security solutions in large environments)
Detailed technical experience in the installation, configuration, and operation of high-end firewall appliances, ideally Palo Alto Networks products
You're experienced in internetworking, LAN, and WAN technologies
You have a good understanding of Internet protocols and applications
Any of the following industry certifications or equivalent experience is a plus: CISSP, CCNA, PCNSE, JNCIE-SEC
You effectively handle multiple projects and work calmly in high pressure
You're an excellent writer, with strong verbal communication skills, with demonstrable ability to communicate to senior leaders and technical peers
Senior Cloud Security Engineer (Infrastructure and Security) - New York - Competitive Salary + Competitive Package + Opportunity to work with an Ambitious, Young, Growing Organisation!
Cyber security analyst job in New York, NY
This young and agile company, providing identity risk solutions is currently seeking a Senior Cloud Security Engineer with a focus on Infrastructure and Security to join their growing team.
You will assist with the continuous maturation of their Cloud Security services within the Security division.
This is an excellent opportunity for an experienced Cloud Security Engineer with experience in both Infrastructure and Security to take the next step into a challenging position with a company offering significant growth potential.
About the Company:
Founded in the last 10 years, they are one the fastest growing companies in their space.
They are a fast-growing company that have built a platform that allows finance organisations and fintechs to strengthen their security defences.
Their mission is to allow companies to manage their identity and fraud risk.
Everything they do is entrenched in achieving engineering excellence.
Their culture is not corporate, and they like to trust their employees to take on a lot of responsibility and have input into the shape of growth of the organisation.
About the Senior Cloud Security Engineer (Infrastructure and Security) Vacancy:
What you will be doing:
• Serve as a cloud security subject matter expert, advise on and implementing best practices
• Respond to security incidents and provide timely and appropriate solutions
• Conduct cloud security risk assessments and audits
• Conduct investigations into security incidents and potential threats
• Take part in on call rotations for incident response and remediation
• Assist with policy management, security audits, and due diligence for cloud security concerns
• Advise on, configuring, and managing a variety of security tools
• Keep informed about and respond to emerging security threats and vulnerabilities
• Assist with cloud security reviews of potential vendors
Ideal Requirements for the Senior Cloud Security Engineer (Infrastructure and Security) Vacancy:
• Several years of experience working in a similar role with a focus on Cloud Security in AWS
• Experience provisioning infrastructure in AWS using Terraform, CloudFormation, CDK, or similar tools
• Experience configuring VPCs, route tables, NACLs, Security Groups, iptables, Web Application Firewall, Config, GuardDuty, Inspector, KMS, IAM, etc.
• In depth knowledge of AWS security best practices around systems hardening, monitoring, and incident response
• Experience taking part in an on-call rotation
• You are passionate about securing infrastructure, reducing risk, and protecting data!
• You are a subject matter expert on cloud security in AWS
• You have a solid understanding of network architecture and protocols
• You can advise on cloud security policies and procedures
Apply to the Role:
Roles like these are snapped up very quickly, so act now if you do not want to miss out! Reply to this advert or email your CV to **********************
Lead Security Engineer
Cyber security analyst job in New York, NY
Lead Security Engineer - Hands-On Role with Leadership Opportunity
We're looking to hire a senior-level Security Engineer who's ready to step up and take the lead. Someone who's still very hands-on technically but also enjoys mentoring others, setting direction, and building scalable solutions that make a real difference.
Title: Lead Security Engineer
Salary: $160,000 to 190,000 +Bonus
Location: Queens, NY (Hybrid)
This role sits at the center of engineering, operations, and security-you'll be working directly with software and infrastructure teams to make sure security is embedded into everything we do. You won't just be managing tools; you'll help shape how security is done across the company.
If you're based in the NYC area and looking for the next serious step in your career-where your ideas are heard and your work actually drives change-this is worth a conversation.
What the Role Looks Like:
You'll lead and mentor a small but growing team of security engineers, helping them grow while staying deep in the tech yourself.
Work with internal teams to design and implement security solutions-cloud security, PAM, app and system hardening, etc.
You'll be the one connecting the dots between development, infrastructure, and security-building relationships across teams and making sure security is part of the process from the start.
Help optimize and improve the tools we already have, and figure out what's missing.
What We're Hoping You Bring:
A few years of experience leading or mentoring other security engineers-you don't need to have managed huge teams, but you've helped others level up.
Solid technical background (5+ years in security engineering) and experience with on-prem and cloud security solutions (AWS or Azure).
Hands-on knowledge of privileged access, identity management, system hardening, and network security.
Strong instincts for risk, practical problem-solving, and keeping systems both secure and usable.
Someone who communicates clearly, doesn't get lost in buzzwords, and works well with people across teams.
Nice to Have, But Not Dealbreakers:
Certifications like CISSP, CEH, CISM
Experience with Linux security or scripting
Familiarity with CI/CD pipelines and how security fits into DevOps
Why This Role Might Be Right for You:
You're ready for more responsibility and leadership, but don't want to give up the technical side of the work.
You want to be part of a stable company with real backing and complex challenges to work on.
Information Security Engineer
Cyber security analyst job in Iselin, NJ
We are seeking a high-judgment, detail-oriented operator to lead our Threat Modeling Program Operations. This individual will be responsible for orchestrating workflows, triaging intake, designing key metrics, and eliminating process inefficiencies. The role demands an expert in building executive-ready reports and dashboards to track throughput, cycle times, and model quality, ensuring optimal outcomes for complex, multifaceted initiatives in Information Security Engineering.
This is a contingent resource assignment, and the candidate may:
Consult on complex, large-scale initiatives in Information Security Engineering.
Review and analyze intricate, long-term security challenges, considering multiple factors including intangible or unprecedented elements.
Contribute to resolving complex issues requiring deep understanding of security policies, procedures, and compliance requirements.
Strategically collaborate with client personnel to ensure project success.
Key Responsibilities:
Lead and optimize workflow orchestration for the Threat Modeling Program.
Develop and manage reports and dashboards to monitor program effectiveness (throughput, cycle time, model quality).
Analyze and address complex security engineering issues, guiding teams to resolution.
Collaborate cross-functionally with stakeholders, delivering executive communication and reporting.
Continuously improve processes to eliminate inefficiencies and ensure scalability.
Required Qualifications:
5+ years of experience in Information Security Engineering or equivalent (consulting, training, military, education).
Proven ability to take initiative, work independently, and drive results.
Strong attention to detail and ability to handle ad hoc reporting.
Advanced skills in Microsoft Excel (VLookups & Pivot Tables) and PowerPoint.
Proficient with Agile methodologies and project management tools like Atlassian JIRA and Confluence.
Experience in analytical
AWS Security Engineer
Cyber security analyst job in Jersey City, NJ
Type : Contract
f2f Interview is must
We are seeking an experienced AWS Security Engineer to design, implement, and manage security controls across Snowflake and Databricks environments. The ideal candidate will have strong expertise in AWS security, data platform governance, and Python-based automation to ensure secure, compliant, and efficient operations within our cloud ecosystem.
Key Responsibilities:
Implement, monitor, and enhance security controls across network, application, and data layers for Snowflake and Databricks environments.
Manage user access, roles, and permissions in Snowflake or Databricks to ensure compliance with least privilege and governance policies.
Configure and manage AWS security components, including IAM roles/policies, S3 bucket policies, EC2, Lambda, and CloudWatch for monitoring and event response.
Collaborate with data engineering and platform teams to ensure secure data ingestion, storage, and access controls.
Automate security monitoring and configuration management using Python scripting and AWS SDKs.
Identify and remediate security vulnerabilities, ensuring continuous compliance with internal and external standards.
Contribute to security documentation, audits, and process improvements for data platform security posture.
Cloud Security Engineer - SRE
Cyber security analyst job in Berkeley Heights, NJ
Job Posting Title: Cloud Security Engineer - SRE
Job Profile: Technical Project Management - Advisor II
We are seeking a skilled and motivated Cloud Security Engineer - SRE to join our dynamic team. The ideal candidate will possess a strong technical background in systems administration, cloud computing, and infrastructure as code, with a particular focus on solution engineering/site reliability. This role will involve collaborating with cross-functional teams to enhance our security posture and streamline processes through automation.
Technical Skills
• Programming and Scripting: Strong proficiency in languages like Python, Go, Bash, or Ruby. SREs often need to write automation scripts and build tooling.
• Systems Administration: Deep understanding of operating systems (Linux/Unix), file systems, processes, and system configurations.
• Infrastructure as Code (IaC): Experience with IaC tools like Terraform, Ansible, or Chef to manage infrastructure.
• Cloud Computing: Knowledge of cloud platforms such as AWS, Azure, or Google Cloud Platform, including services like EC2, S3, Kubernetes, and serverless functions.
• Containers and Orchestration: Expertise in containerization (Docker) and container orchestration (Kubernetes, OpenShift).
• Networking: Understanding of networking concepts, including DNS, firewalls, load balancing, and VPNs.
• Monitoring and Observability: Experience with monitoring and observability tools like Prometheus, Grafana, Datadog, or New Relic. Ability to set up and maintain monitoring dashboards, alerts, and logs.
• Continuous Integration/Continuous Deployment (CI/CD): Familiarity with CI/CD tools like Jenkins, GitLab CI, GitHub Actions, or CircleCI.
• A strong understanding of HashiCorp Vault and Terraform will make you stand out.
2. Problem-Solving and Troubleshooting
• Incident Management: Ability to manage and respond to incidents, perform root cause analysis, and implement post-mortem reviews.
• Automation: Focus on automating repetitive tasks to improve efficiency and reduce human error.
• Performance Tuning: Skills in identifying and resolving performance bottlenecks in systems and applications.
3. Collaboration and Communication
• Teamwork: Ability to work closely with cross-functional teams, including software engineers, product managers, and DevOps teams.
• Documentation: Skill in creating clear and comprehensive documentation for systems, processes, and incident reports.
• Communication: Effective communication skills for interacting with stakeholders and explaining technical concepts to non-technical audiences.
4. Reliability and Scalability
• Service-Level Objectives (SLOs) and Service-Level Agreements (SLAs): Understanding of setting, monitoring, and maintaining SLOs and SLAs for system reliability.
• Scalability: Knowledge of best practices for designing and scaling systems to handle increased loads and demands.
• Redundancy and Resilience: Experience in designing systems with redundancy and fault tolerance to minimize downtime.
5. Security and Compliance
• Security Best Practices: Understanding of security principles, such as access control, data encryption, and secure coding practices.
• Compliance: Familiarity with compliance standards like GDPR, HIPAA, or PCI-DSS, depending on the industry.
Minimum Job Qualifications:
• Bachelor degree in business or equivalent work experience
• 10 years of previous program leadership and/or relevant consulting experience
• Knowledge of and demonstrated experience in program management framework, knowledge groups & life cycle
• 5+ years' experience in driving large scale data center consolidation efforts
• Minimum 5 years' experience with matrix management of cross-functional processes and teams
• Proficient with Project Management tools
Chief Information Security Officer
Cyber security analyst job in New York, NY
A financial firm is looking for a Chief Information Security Officer (CISO) to join their team in New York, NY.
Compensation: $150-200K
Responsibilities:
Define and maintain the enterprise information security strategy, roadmap, and governance framework, aligned with business objectives and regulatory requirements
Draft, maintain, and periodically review security-related policies and procedures
Establish and chair/co-chair an Information Security / Cyber Risk Committee and contribute to Board-level reporting on cyber risk
Develop and maintain the firm's information security governance framework
Lead the firm's SOC 1 (Type 1/Type 2) and SOC 2 (Type 1/Type 2) readiness and ongoing attestation efforts
Own the control catalog, control testing coordination, evidence collection, and remediation tracking across technology, operations, and third parties
Act as primary security point of contact for external auditors, assessment firms, and key institutional partners
Ensure security program alignment with SEC Regulation S-P, Reg S-ID, Reg SCI, SEC / Client cybersecurity expectations, and NYDFS 23 NYCRR 500
Partner with Compliance and Legal to interpret new regulations, assess impact, and implement necessary control and policy changes
Maintain and periodically test the Incident Response Plan, Business Continuity and Disaster Recovery (BC/DR) from a security perspective
Provide security oversight for cloud (AWS) and on-prem infrastructure, including network security, endpoint security, identity and access management (IAM), and data protection
Work with Infrastructure/DevOps and application teams to embed secure SDLC practices, including code review, security testing, and secure deployment pipelines
Oversee vulnerability management, including patch management processes, penetration testing, and remediation programs
Define and oversee Security Operations Center (SOC) / XDR usage, log management, SIEM, threat detection, and incident handling
Design and enforce data classification, data loss prevention (DLP), encryption, and key management controls
Partner with business and product teams to ensure client data privacy and secure data flows, including with third-party vendors and partners
Own the vendor security risk management program, including security due diligence, contract security clauses, and ongoing monitoring
Evaluate and manage key security vendors
Build and lead a small but high-impact security team, scaling capabilities over time
Promote a security-first culture through training, awareness programs, and regular communication with staff at all levels
Qualifications:
Required
Bachelor's degree in Computer Science, Information Security, Engineering, or related field; or equivalent experience
7+ years of progressive experience in information security, including at least 3 years in a leadership role (Head of Security, Deputy CISO, CISO, or equivalent)
Hands-on experience leading SOC 1 and/or SOC 2 attestation projects at a financial institution, fintech, or SaaS provider
Strong background in financial services or capital markets (broker-dealer, clearing firm, trading platform, or similar)
Understanding of Information security frameworks (e.g., NIST CSF, NIST 800-53, ISO 27001)
Understanding of Regulatory landscape for U.S. financial firms (e.g., SEC, Client, possibly NYDFS 500)
Experience with Identity & access management, network security, endpoint security, and cloud security (preferably AWS)
Experience building and maintaining incident response, BC/DR, and vulnerability/patch management programs
Strong track record of cross-functional leadership, communicating complex security and risk topics to non-technical executives and boards
Preferred
Experience as CISO, Deputy CISO, or security leader at a broker-dealer, clearing firm, exchange/ATS, or large fintech
Professional certifications such as CISSP, CISM, CISA, CRISC, CCSP or similar
Experience with AWS security services
Familiarity with DevSecOps practices and secure CI/CD pipelines
Experience managing data localization and cross-border data separation initiatives
Chief Information Security Officer
Cyber security analyst job in New York, NY
Chief Information Security Officer (CISO)
📍
💰
Base Salary:
Up to $325,000 + Bonus + Equity
🏢
Our Client:
A Blockchain & Digital Asset Infrastructure Company
About Our Client
Our client is a fast-growing organization building infrastructure, software, and services that support the next generation of blockchain and digital asset ecosystems. They power secure transactions, institutional-grade solutions, and high-performance platforms used across the crypto economy.
As the business scales, they are expanding their leadership team with a Chief Information Security Officer (CISO) who will own the strategic direction, operations, and continuous improvement of all information and cybersecurity initiatives.
Role Overview
The CISO will set the long-term vision for security across the entire organization, covering infrastructure, products, employee environments, and customer-facing systems. This leader will ensure that the company's digital asset capabilities, blockchain networks, APIs, and cloud environments meet the highest standards of protection, resilience, and regulatory readiness.
This role requires an executive who can operate across technical, operational, and strategic levels-partnering with engineering, legal, compliance, product, and leadership teams.
Key Responsibilities
Design and drive a holistic security strategy covering infrastructure security, application security, product security, data governance, and operational risk.
Safeguard digital asset environments, including wallets, key management systems, consensus mechanisms, and blockchain-based services.
Build and lead an advanced threat detection, monitoring, and incident response program, ensuring rapid response and clear communication pathways.
Collaborate with engineering teams to integrate secure development practices into blockchain, smart contract, and cloud-native workflows.
Establish and maintain security controls, audits, and certifications, ensuring alignment with industry frameworks and regulatory expectations.
Oversee vendor security, supply-chain risk management, and third-party assessments.
Develop a culture of security throughout the business, including training, policy development, and ongoing risk awareness.
Provide regular reports and briefings to the executive team on emerging threats, risk posture, and security roadmap progress.
Experience & Qualifications
15+ years of experience in cybersecurity, with at least 5 years leading security organizations or programs at scale.
Strong experience in blockchain security, digital asset custody, exchange or infrastructure security, or related crypto-native environments.
Demonstrated success leading enterprise security programs that span cloud infrastructure, distributed systems, and high-availability environments.
Skilled in working with frameworks such as SOC 2, ISO 27001, NIST, and global data protection standards.
Expertise in cloud security (AWS, GCP, Azure), network security architecture, identity management, and DevSecOps.
Comfortable operating in fast-moving, engineering-driven environments.
Professional certifications (CISSP, CISM, CCISO, etc.) are a strong plus.
Network Security Analyst
Cyber security analyst job in White Plains, NY
We invite you to review our current business services professionals openings to learn about the opportunities available across the firm.
About Us
Skadden, Arps, Slate, Meagher & Flom LLP has forged a reputation as one of the most prestigious law firms in the world. Relying on innovation, intellect, teamwork and tenacity, our lawyers deliver the highest quality advice and novel solutions to our clients' legal issues. We are known for handling the most complex transactions, litigation/controversy issues, and regulatory matters, as well as for the strong partnerships we build with clients and each other. Our attorneys, who reflect a broad range of experiences and perspectives, work together seamlessly across 50-plus practices and 21 offices in the world's major financial centers.
The Opportunity
We are seeking two Network Security Analysts to join our Firm. These positions will be based in our White Plains office (hybrid), and please note the roles have different shift times, listed below. The Network Security Analysts are responsible for implementing and supporting network security solutions for the Firm and, implementing and enforcing practical solutions to secure the Firm's internal and external network infrastructure.
Available Shift Times (EST- Hybrid)
1.) Saturday - Sunday: 7:00 a.m. - 8:00 p.m. EST & Monday 7:00 a.m. - 7:00 p.m.
2.) Monday - Friday: 2:00 p.m. - 10:00 p.m.
Note: The scheduled hours listed may be flexible and will be discussed during the interview process.
Responsibilities
Performs daily review of automated security reports and escalate as necessary.
Responds to system generated security alerts and coordinate responses.
Assists with internal audits, vulnerability scans and risk assessments.
Assists with annual penetration testing, review of findings and tracking issue resolution.
Participates in evaluating new technologies or new versions of existing products.
Works with project teams to implement secure network connectivity solutions.
Writes and maintains technical documentation including procedures and troubleshooting guides.
Demonstrates effective interpersonal, written and verbal communication skills to facilitate effective work relationships with others.
Manages Firm resources responsibly.
Complies with and understands Firm operation, policies and procedures.
Performs other related duties as assigned.
Qualifications
Knowledge of relevant firm computer software programs (e.g., Outlook, Excel, PowerPoint), with the ability to learn new software and operating systems
Proficient with Access, Project and Visio
Thorough knowledge of network management and security technologies and approaches
Thorough knowledge of security techniques, latest protocols and defenses
Proficient with Microsoft Active Directory and Operating Systems
Basic ability to program scripts and batch files
Demonstrates effective interpersonal and communication skills, both verbally and in writing
Demonstrates close attention to detail
Excellent analytical, troubleshooting, organizational, and planning skills
Ability to handle multiple projects and shifting priorities
Ability to handle sensitive matters and maintain confidentiality
Ability to organize and prioritize work
Ability to work well in a demanding and fast-paced environment
Ability to work well independently as well as effectively within a team
Ability to use discretion and exercise independent and sound judgment
Flexibility to adjust hours and work the hours necessary to meet operating and business needs
Education/Experience
Bachelor's degree or equivalent
Minimum of two years' experience in multi-national enterprise IT
Culture & Life at Skadden
What makes Skadden special is our people and the culture, community and spirit of collaboration we have created. We believe in teamwork and inspiring each other to be our best in an atmosphere that promotes professionalism and excellence in all that we do. We know that inclusion and drawing on the strength of a wide spectrum of talent only make us better and is vital to the firm's success. Our goal is for everyone at the firm to enjoy a challenging career with opportunities for development and growth and to support the well-being of our attorneys and business services professionals.
Benefits
The overall well-being of our team is important to us. We offer generous benefits to help you achieve wellness in all areas of your life.
Competitive salaries and year-end discretionary bonuses.
Comprehensive health care (medical, dental, vision), savings plan/401(k) and voluntary benefits.
Generous paid time off.
Paid leave options, including parental.
In-classroom, remote, and on-demand learning and professional development opportunities.
Robust well-being classes and programs.
Opportunities to give back and make an impact in local communities.
For further details, please visit: *******************************************************
Skadden is an Equal Opportunity Employer (Disability/Vet/other protected categories). For more information, please visit Skadden.com/careers.
The starting base salary for this position is expected to be within the range listed under Salary Details. Actual salary will be determined based on skills, experience (to the extent relevant) and other-job related factors, consistent with applicable law.
Salary Details
$125,000 -$140,000
EEO Statement
Skadden is an Equal Opportunity Employer. It does not discriminate against applicants or employees based on any legally impermissible factor including, but not limited to, race, color, religion, creed, sex, national origin, ancestry, age, alienage or citizenship status, marital or familial status, domestic partnership status, caregiver status, sexual orientation, gender, gender identity or expression, change of sex or transgender status, genetic information, medical condition, pregnancy, childbirth or related medical conditions, sexual and reproductive health decisions, disability, any protected military or veteran status, or status as a victim of domestic or dating violence, sexual assault or offense, or stalking.
Applicants who require an accommodation during the application process should contact Lara Bell at **************.
Skadden Equal Employment Opportunity Policy
Skadden Equal Employment Opportunity Policy
Applicants Have Rights Under Federal Employment Law
Applicants Have Rights Under Federal Employment Law
In accordance with the Transparency in Coverage Rule,
click here to review machine-readable files made available by UnitedHealthcare:
Transparency in Coverage
Auto-ApplyCyber Command Forensic Analyst
Cyber security analyst job in New York, NY
Job Title: Cyber Command Forensic Analyst
SCOPE OF SERVICES:
The forensics Analyst will investigate network intrusions and other cyber incidents to determine cause, extent and consequences of the breach.
TASKS:
· Research and develop new techniques, and procedures to continually improve the digital forensics process.
· Produce high quality written work product presenting complex technical issues clearly and concisely.
· Managing and maintaining the analysis labs and forensics tools leveraged for investigations.
· Ensuring data is collected and preserved within industry standard best practices and in alignment evidence integrity requirements.
· Assisting the Cyber Emergency Response Team during critical incidents.
· Investigate network intrusions and other cybersecurity incidents to determine the cause and extent of the breach. Includes ability to perform host -based and network -based forensic analysis.
MANDATORY SKILLS/EXPERIENCE:
· Minimum 4 years of experience in Threat Management/Forensics Investigations/Incident Response environment
· Proficient in performing digital forensic investigations on a variety of platforms and operating systems with a deep understanding of digital forensics processes and tools.
Requirements
DESIRABLE SKILLS/EXPERIENCE:
· Experience with a wide range of forensic tools (FTK, X -Ways, SIFT, AXIOM, EnCase, etc.)
· Experience with memory analysis tools (i.e. Volatility, MemProcFS)
· Experience with Linux and open source tools
· Experience investigating intrusions on Windows and Linux/Unix operating systems
· Experience with performing forensics collections in cloud environments (AWS, Azure, GCP)
· Knowledge of gathering, accessing, and assessing evidence from computer systems and electronic devices
· Knowledge of virtual environments
· Knowledge of forensic imaging techniques
· Knowledge of Microsoft Windows operating system and Windows artifacts
· Knowledge of Linux/UNIX operating systems and artifacts
· Knowledge of mac OS operating system and forensics artifacts
· Knowledge of file systems
· Strong analytical skills
Skills:
· Incident Management
· Threat Management
· Cyber Security
Cyber Security Analyst
Cyber security analyst job in New York, NY
Job Description
We is seeking a talented Cyber Security Analyst. As a Cyber Security Analyst, you will play a key role in ensuring the security and integrity of our organization's data and systems.
Requirements
Responsibilities:
Monitor, detect, and respond to cyber threats and security incidents,
Conduct vulnerability assessments and penetration testing to identify potential weaknesses in our systems,
Develop and implement security measures and best practices to protect against cyber attacks,
Stay up-to-date with the latest cyber security trends and technologies,
Collaborate with cross-functional teams to identify security risks and implement appropriate solutions,
Provide training and guidance to employees on cyber security awareness and best practices.
Requirements:
Bachelor's degree in Computer Science, Information Security, or a related field,
Proven experience in cyber security or a related role,
Strong knowledge of security protocols and tools,
Ability to analyze and interpret complex data and make informed decisions,
Excellent problem-solving and communication skills,
Relevant certifications (e.g. CISSP, CISM) are preferred but not required.
Benefits
About Us
Zone IT Solutions is an Australia-based Recruitment Company. We specialise in Digital, ERP and larger IT Services. We offer flexible, efficient and collaborative solutions to any organisation that requires IT, experts. Our agile, agnostic and flexible solutions will help you source the IT Expertise you need. If you are looking for new opportunities, your profile at *******************************.
Also, follow our LinkedIn page for new job opportunities and more.
Zone IT Solutions is an equal-opportunity employer, and our recruitment process focuses on essential skills and abilities.
Easy ApplyGlobal Cyber Wordings Analyst
Cyber security analyst job in New York, NY
Join our global Cyber team as a Wordings Analyst supporting the Global Cyber Wordings Manager in the strategic development and governance of our Cyber and Tech policy suite, including Liberty Cyber Resolution and Liberty Tech Resolution. This role is a hands-on business enabler: you will help translate complex legal and regulatory requirements into clear, market-ready wordings, maintain our global clause library, support manuscript negotiations, and produce practical tools that empower underwriters and strengthen broker confidence. It's an excellent opportunity for an early-career insurance wordings or legal professional to build expertise in a fast-moving, global specialty line and make a visible impact on growth, innovation, and client experience.
Key responsibilities:
Wording library and drafting support
Maintain and expand the global wording library centered on Liberty Cyber Resolution and Liberty Tech Resolution, including endorsements, exclusions, and guidance notes.
Redline and prepare first drafts of standard clauses and endorsements; ensure consistency with definitions, coverage intent, and plain-language standards.
Track version control, change logs, approvals, and archiving;
Assist with localization for different jurisdictions, coordinating translations and filing documentation with Legal/Compliance.
Commercial enablement
Build practical tools (playbooks, FAQs, objection-handling guides, coverage summaries) to help regional teams position our products and close deals efficiently.
Prepare broker/client comparison decks and battlecards; support pitches, RFP/RFI responses, and manuscript negotiations with clause comparisons and recommended alternatives.
Triage wording queries from regions; track SLAs and referral approvals per the global governance framework.
Partner closely with Underwriting, Product, Global Cyber Engagement, Claims, Legal/Compliance, and regional leaders to deliver accurate, timely support and uphold governance standards.
Regulatory and legal stewardship
Monitor and synthesize global regulatory and market developments (e.g., Lloyd's cyber war/systemic guidance, GDPR, DORA, NIS2, sanctions) into succinct briefs and recommended wording actions.
Maintain audit-ready documentation; assist with regulatory filings or attestations where required.
Claims partnership and feedback loop
Collaborate with Claims to capture lessons from disputes and litigation trends; draft guidance notes and propose clarifications to improve coverage certainty.
Support coverage position letters and documentation packs with research, citations, and clause histories.
Innovation and product development support
Help draft prototype wordings for new propositions
Check alignment between underlying policy wordings and reinsurance treaty/facultative clauses.
Administer wording management tools, ensuring robust version control, approval workflows, and usage analytics.
Build dashboards and trackers for adoption of standard forms, deviation rates, SLA performance, disputes, and audit findings; provide monthly reporting to stakeholders.
Qualifications
Bachelor's degree in business, economics, or other quantitative field. Minimum 3 years, typically 4 years or more of relevant work experience.
2 - 5 years of experience in insurance wordings, legal/paralegal support, underwriting support, or product documentation; cyber specialty experience preferred.
Strong drafting, redlining, and proofreading skills with a plain-language mindset and exceptional attention to detail.
Working knowledge of insurance policy structures, endorsements, exclusions, and coverage interpretation; familiarity with cyber war/systemic language, sanctions, and privacy regulations is advantageous.
Research and synthesis skills to translate complex regulatory/legal topics into practical guidance and actionable updates.
Proficiency with MS Word (advanced track changes/redlining), Excel (trackers and dashboards), PowerPoint (training/pitch materials), and document/enablement tools.
Collaborative, service-oriented approach; comfortable operating in a global matrix and meeting defined SLAs.
Curiosity about cybersecurity risks and the incident response ecosystem; willingness to learn common threat scenarios to inform practical drafting.
About Us
Pay Philosophy: The typical starting salary range for this role is determined by a number of factors including skills, experience, education, certifications and location. The full salary range for this role reflects the competitive labor market value for all employees in these positions across the national market and provides an opportunity to progress as employees grow and develop within the role. Some roles at Liberty Mutual have a corresponding compensation plan which may include commission and/or bonus earnings at rates that vary based on multiple factors set forth in the compensation plan for the role.
At Liberty Mutual, our goal is to create a workplace where everyone feels valued, supported, and can thrive. We build an environment that welcomes a wide range of perspectives and experiences, with inclusion embedded in every aspect of our culture and reflected in everyday interactions. This comes to life through comprehensive benefits, workplace flexibility, professional development opportunities, and a host of opportunities provided through our Employee Resource Groups. Each employee plays a role in creating our inclusive culture, which supports every individual to do their best work. Together, we cultivate a community where everyone can make a meaningful impact for our business, our customers, and the communities we serve.
We value your hard work, integrity and commitment to make things better, and we put people first by offering you benefits that support your life and well-being. To learn more about our benefit offerings please visit: ***********************
Liberty Mutual is an equal opportunity employer. We will not tolerate discrimination on the basis of race, color, national origin, sex, sexual orientation, gender identity, religion, age, disability, veteran's status, pregnancy, genetic information or on any basis prohibited by federal, state or local law.
Fair Chance Notices
California
Los Angeles Incorporated
Los Angeles Unincorporated
Philadelphia
San Francisco
We can recommend jobs specifically for you! Click here to get started.
Auto-ApplyCloud Security Specialist Information Security Engineering
Cyber security analyst job in New York, NY
The Cloud Security Specialist is a senior technical and leadership position responsible for implementing, managing, and continuously improving cloud security across multi cloud environments including AWS, Azure, Google Cloud, and Oracle Cloud Infrastructure (OCI).This role combines hands on technical execution with team leadership. The successful candidate will lead a team of cloud security engineers, develop secure architectures, and manage enterprise grade cloud security solutions such as Cloud Security Posture Management (CSPM), Cloud Workload Protection (CWP), Container Security, API Security, and AI Security Posture Management (AISPM).The individual will partner with cloud service, DevOps, and application teams to design secure deployments, enforce policies, and integrate automation for vulnerability remediation, threat detection, and compliance. They will also implement secure private connectivity between cloud and on premise networks using technologies such as AWS PrivateLink and Azure ExpressRoute. Required Education/Experience
* Master's Degree and with 3 years of relevant experience IT or Information security or
* Bachelor's Degree and with 5 years of relevant experience IT or Information security or
* Associate's Degree and with 6 years of relevant experience IT or Information security or
* High School Diploma/GED and with 8 years of relevant experience IT or Information security.
Preferred Education/Experience
* Master's Degree in Cybersecurity, Computer Engineering, Computer Science, Information Systems Security, Information Technology. and 3 years in Information security, Cloud Security or Cloud Architect in a senior technical role. With certifications such as CCSP, AWS Certified Security, Azure Security Engineer Associate, or GCP Cloud Security Engineer. Experience in cloud security or cloud architecture. Experience with CSPM, CWP, AISPM, and API security implementations. Handson work with identity management, hybrid connectivity (PrivateLink, ExpressRoute).
* Bachelor's Degree in Cybersecurity, Computer Engineering, Computer Science, Information Systems Security, Information Technology. and 5 years in Information security, Cloud Security or Cloud Architect in a senior technical role. With certifications such as CCSP, AWS Certified Security, Azure Security Engineer Associate, or GCP Cloud Security Engineer. Experience in cloud security or cloud architecture. Experience with CSPM, CWP, AISPM, and API security implementations. Handson work with identity management, hybrid connectivity (PrivateLink, ExpressRoute).
Relevant Work Experience
* Handson experience with at least two major cloud providers (AWS, Azure, GCP, or OCI), required.
* Implementation and management experience with CSPM, CWP, AISPM, and API security platforms, required.
* Knowledge of IAM, rolebased access control, and policy enforcement, required.
* Experience integrating cloud telemetry and logs with SIEM tools, required.
* Understanding of hybrid connectivity and private link technologies (PrivateLink, ExpressRoute), required.
* Experience with scripting (Python, PowerShell, Bash) and automation, required.
* Experience with WAF and cloud API gateway configurations, required.
* Strong understanding of cloud network fundamentals and background in cloud network security, and secure architecture design, required.
* Experience collaborating with cloud service teams for planning and remediation, required.
* Experience implementing application security best practices and training engineering teams, required.
* Familiarity with CDN operations, certificates, and brand monitoring preferred, required.
* Experience with SIEM integration, telemetry collection, and event analysis, preferred.
* Demonstrated experience leading technical teams or project groups, preferred.
* Experience with Container Security, preferred.
* Experience securing API endpoints and implementing advanced cloud application protections, preferred.
* Knowledge of AI/ML data protection and secure model deployment practices, preferred.
* Experience integrating security automation into DevSecOps workflows using Terraform or Ansible, preferred.
* Experience developing and delivering cloud security training and awareness programs, preferred.
Skills and Abilities
* Effective leadership skills
* Demonstrated problem solving skills
* Demonstrated problem solving skills
* Strong written and verbal communication skills
* Ability to drive multiple projects to successful completion
* Proactively approaches responsibilities
Licenses and Certifications
* Driver's License Required
* Other: CISSP, CCNP Security, GSEC, GCIH, CEH, or equivalent certifications. Preferred
* Other: CCSP, AWS Certified Security, Azure Security Engineer Associate, GCP Professional Cloud Security Engineer, or OCI Security Professional. Preferred
Physical Demands
* Ability to push, pull, and lift up to 25 pounds
* Sit or stand to use a keyboard, mouse, and computer for the duration of the workday
Additional Physical Demands
* The selected candidate will be assigned a System Emergency Assignment (i.e., an emergency response role) and will be expected to work non-business hours during emergencies, which may include nights, weekends, and holidays.
* The selected candidate will be assigned a System Emergency Assignment (i.e., an emergency response role) and will be expected to work non-business hours during emergencies, which may include nights, weekends, and holidays.
Core Responsibilities
* Lead and mentor a team of cloud security engineers, fostering technical excellence and professional growth.
* Architect and maintain secure multi-cloud environments across AWS, Azure, GCP, and OCI in partnership with Enterprise Architecture.
* Deploy and manage CSPM platforms to drive continuous visibility, compliance, and risk posture improvement.
* Implement CWP solutions to protect cloud workloads, prevent threats, and manage vulnerabilities effectively.
* Define and enforce IAM policies and least-privilege principles to strengthen identity security across all platforms.
* Design and secure private and hybrid connectivity using technologies such as AWS PrivateLink, Azure ExpressRoute, and Google Cloud Interconnect.
* Integrate cloud telemetry and security events with SIEM systems to enhance incident detection and response capabilities.
* Automate provisioning, configuration, and remediation workflows using IaC tools like Terraform and Ansible, supported by Python or PowerShell scripting.
* Implement and manage WAF policies and API gateways to safeguard cloud applications and services.
* Partner with DevOps and engineering teams to embed security within CI/CD pipelines and promote secure development practices.
* Collaborate with risk and architecture teams to assess emerging technologies and align them with enterprise security strategy.
* Stay informed on evolving threats, regulatory frameworks, and AI security trends to continuously improve cloud security posture.
Information Security Analyst II (E5122)
Cyber security analyst job in Piscataway, NJ
Information Security Analyst II (E5122) - 250363: KNW-B40 Description Job Summary The overall purpose of this position is to protect the security and integrity of IEEE data through the implementation and maintenance of information security practices, measures, and technologies consistent with industry best practices.
This position will act as a subject matter expert who will diligently assist with the maintenance and improvement of information and systems to ensure appropriate safeguards are in place.
The incumbent must possess a thorough understanding and knowledge of security controls, strategies and methodologies as well as knowledge of some of the following technologies: firewalls, identity and access management, advanced authentication, single sing on, security audits, security diagnostics and encryption.
The role reports to the Manager, Information Security and manages 0 direct reports.
Key ResponsibilitiesProactively identify and remediates vulnerabilities using industry best practices and maintains a strong awareness and understanding of the current threat landscape.
Performs internal and external security audits to ensure compliance with agreed security practices, policy and procedures to adhere with legal and regulatory requirements.
Identifies security policy violations and leads in the corrective actions to maintain data and infrastructure security.
Provides guidance and technical expertise to other technical employees and project teams and enforces established security policies.
Assists project teams with the application and implementation of IEEE security policies, standards, processes and agreed architectures.
Makes recommendations for enhancing security services, participates and, at times, leads the evaluation of commercial information security products and services to determine which of these should be adopted by or tested by the organization.
Assists with the installation, maintenance and support of information security tools and services including, but not limited to, identity and access management systems including single sign on (SSO).
Participates in development and update of security policies, procedures, standards, guidelines, and architectures.
Assists with the execution vulnerability and penetration tests of IEEE network and systems including the remediation of findings.
Assists with the investigation of security incidents, recommends and implements solutions to remediate or mitigate them.
Assists in the formulation and enforcement of security policies and procedures.
Qualifications Education Bachelor's degree or equivalent experience Bachelor's Degree in computer related field such as Computer Science, Mathematics or Engineering.
In lieu of a degree equivalent experience will be considered.
ReqWork Experience 2-4 years At least 4 years direct experience involving security, network architectures and Internet communications protocols (TCP/IP), monitoring and intrusion prevention strategies (e.
g.
Firewalls, Security Event Correlation, Malware Detection, IDS/IPS), Identity & Access Management technologies and concepts (Enterprise Directory Services, Virtual Directory, Enterprise Single Sign-On / Web Access Controls and Authorization models) in a large, distributed, high performance, business critical networked environment.
ReqLicenses and Certifications Relevant professional qualifications / certifications (CISSP, CEH, CISM, CISA, CSSLP, SANS, CHECK, CREST) a plus.
PrefSkills and Requirements Knowledge or familiarity of security technologies and concepts, including but not limited to, encryption, Public Key Infrastructure (PKI), two factor authentication, network security (firewall, intrusion detection / protection, and network anomaly detection), host based security (Anti-malware, firewall, intrusion detection / protection, patch management and file integrity), web application security (web application firewall, secure application development, authentication, session management, access control, single sign-on and error handling), database security (authentication, access control, auditing and integrity), secure remote access (VPN, terminal and console), security data analysis (security event monitoring, correlation, analysis and response) Knowledge or familiarity on conducting and mitigating security/risk assessments Knowledge of Authentication & Authorization technologies (LDAP, RADIUS, Two-factor authentication, SAML, OpenToken, OAuth, etc.
) Knowledge and experience installing and administering Enterprise Directory Services technologies, such as; Oracle Unified Directory, Oracle Virtual Directory, OpenLDAP, and Microsoft Active Directory.
Knowledge or familiarity installing and administering Enterprise Single Sign-On (ESSO) and Access Management (AM) technologies, such as; Computer Associates SiteMinder, Oracle Access Manager, IBM Tivoli, PingFederate, PingAccess and OpenSSO / OpenAM.
Knowledge and experience Windows Active Directory.
Knowledge of Self Service Account Management technologies, concepts and best practices, such as; Identity validation, user provisioning, self-service password recovery and automation workflows (i.
e.
Self Service Access requests).
Good understanding of a programming language (e.
g.
Java, C, Perl), HTML/XML and Unix “shells” scripting (e.
g.
CSH, KSH, SH).
Excellent communication skills (written and verbal) and able to articulate key messages to a range of audiences.
o Can effectively discuss security challenges with developers and testerso Experience of at least one code security review tool Ability to work alone and build relationships across the organization.
Anticipates problems and identifies long-term implications of decisions and actions.
Familiarity with server operating systems, such as; Windows, Linux & SolarisFamiliarity with web application security concepts, such as; secure application development, secure session management, cryptography, input validation, logging and error handling a plus.
Familiarity with load balancer technologies and ESSO integration capabilities is a plus.
Familiarity of Authentication, Authorization concepts, such as; Identity Federation, Multi-Factor Authentication (MFA), Public Key Infrastructure (PKI), RADIUS / TACACS a plus.
Other Requirements:As defined in IEEE Policies, individuals currently serving on an IEEE board or committee are not eligible to apply.
PLEASE NOTE: This position is not budgeted for employer-sponsored immigration support, this includes all persons in F (both CPT and OPT), J, H, L, or O status.
For information on work demands and conditions required for this position, please consult the reference document, ADA Requirements.
This position is classified under Category I - Office Positions.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
===============================================Disclaimer: This is proprietary to IEEE.
It outlines the general nature and key features performed by various positions that share the same job classification.
It is not designed to contain or be interpreted as a comprehensive inventory of all duties and qualifications required of all employees assigned to the job.
Nothing in this job description restricts management's right to assign or re-assign duties to this job at any time due to reasonable accommodations or other business reasons.
Min: $91,000.
00 Max: $114,000.
00 Job: Technology Primary Location: United States-New Jersey-Piscataway Schedule: Full-time Job Type: Regular Job Posting: Dec 22, 2025, 4:20:40 PM
Auto-Apply