Cyber security analyst jobs in Yonkers, NY - 334 jobs
All
Cyber Security Analyst
Information Security Analyst
Security Engineer
Senior Security Analyst
Network Security Analyst
Senior Security Engineer
Information Security Engineer
Defense Analyst
Cyber Security Engineer
Senior Security Analyst
Capgemini 4.5
Cyber security analyst job in New York, NY
Choosing Capgemini means choosing a company where you will be empowered to shape your career in the way you'd like, where you'll be supported and inspired bya collaborative community of colleagues around the world, and where you'll be able to reimagine what's possible. Join us and help the world's leading organizationsunlock the value of technology and build a more sustainable, more inclusive world.
The Senior SecurityAnalyst supports the governance of service provider activities in the enterprise security program, monitoring and escalating problems and providing information on security issues. Undertakes security assurance and audit activities to ensure compliance and to identify risks and opportunities. Provides information to senior managers and executives to ensure that they are aware of any security-related risks or opportunities. Provides subject matter expertise, consultancy and training in security-related matters. Must be able to function in a fast-paced, multi-vendor outsourced environment, facilitating conference calls among other subject matter experts and the client.
Responsibilities
Handles monthly reporting duties for the Information Risk Management team.
Facilitates audit planning and audit remediation activities of the service providers, leading calls and documenting and reporting progress.
Has familiarity with security technologies and controls; expertise not required, but the ability to escalate to more senior subject matter experts is important.
Develops work plans to structure solutions and communications.
Involves client and vendor staff appropriately in resolving security problems.
Participates effectively within the business' security governance framework.
Tracks the corrective and preventive actions being taken to improve security to closure.
Possesses strong communication skills to communicate technical and security risk information to management.
Experience
Ability to self-manage with little interaction from other management staff.
Flexible and able to adapt to manage a fast‑changing environment.
Ability to solve complex issues and provide recommendations and advice regarding remediations.
Experience with security architecture, security software, or security policy.
Ability to organize agendas, lead conference calls, and track action items to completion.
Security and Audit certifications such as SSCP, CISSP, CISA, CISM, CGEIT, CRISC, Security+ are preferred.
Job Description - Grade Specific
The base compensation range for this role in the posted location is: $65,586-121,980.
Capgemini provides compensation range information in accordance with applicable national, state, provincial, and local pay transparency laws. The base compensation range listed for this position reflects the minimum and maximum target compensation Capgemini, in good faith, believes it may pay for the role at the time of this posting. This range may be subject to change as permitted by law.
The actual compensation offered to any candidate may fall outside of the posted range and will be determined based on multiple factors legally permitted in the applicable jurisdiction.
These may include, but are not limited to: Geographic location, Education and qualifications, Certifications and licenses, Relevant experience and skills, Seniority and performance, Market and business consideration, Internal pay equity.
It is not typical for candidates to be hired at or near the top of the posted compensation range.
In addition to base salary, this role may be eligible for additional compensation such as variable incentives, bonuses, or commissions, depending on the position and applicable laws.
Capgemini offers a comprehensive, non‑negotiable benefits package to all regular, full‑time employees. In the U.S. and Canada, available benefits are determined by local policy and eligibility and may include:
Paid time off based on employee grade (A-F), defined by policy: Vacation: 12‑25 days, depending on grade, Company paid holidays, Personal Days, Sick Leave
Medical, dental, and vision coverage (or provincial healthcare coordination in Canada)
Retirement savings plans (e.g., 401(k) in the U.S., RRSP in Canada)
Life and disability insurance
Employee assistance programs
Other benefits as provided by local policy and eligibility
Important Notice: Compensation (including bonuses, commissions, or other forms of incentive pay) is not considered earned, vested, or payable until it becomes due under the terms of applicable plans or agreements and is subject to Capgemini's discretion, consistent with applicable laws. The Company reserves the right to amend or withdraw compensation programs at any time, within the limits of applicable legislation.
Disclaimers
Capgemini is an Equal Opportunity Employer encouraging inclusion in the workplace. Capgemini also participates in the Partnership Accreditation in Indigenous Relations (PAIR) program which supports meaningful engagement with Indigenous communities across Canada by promoting fairness, accessibility, inclusion and respect. We value the rich cultural heritage and contributions of Indigenous Peoples and actively work to create a welcoming and respectful environment. All qualified applicants will receive consideration for employment without regard to race, national origin, gender identity/expression, age, religion, disability, sexual orientation, genetics, veteran status, marital status or any other characteristic protected by law.
Physical, mental, sensory or environmental demands may be referenced in an attempt to communicate the manner in which this position traditionally is performed. Whenever necessary to provide individuals with disabilities an equal employment opportunity, Capgemini will consider reasonable accommodations that might involve varying job requirements and/or changing the way this job is performed, provided that such accommodation does not pose an undue hardship. Capgemini is committed to providing reasonable accommodation during our recruitment process. If you need assistance or accommodation, please reach out to your recruiting contact.
Ref. code 385096-en_US
Posted on 05 Jan 2026
Contract type Permanent
Location Atlanta, Austin, Bellevue, Berwyn, Bridgewater, Brooklyn, Burlington, Chicago, Columbia, Dallas, Dayton - Sogeti US, Guaynabo, Houston, Irving, Mclean, Nashville, New York, San Francisco, Santa Clara, Seattle, Southfield, Tampa, Westerville
#J-18808-Ljbffr
$65.6k-122k yearly 1d ago
Looking for a job?
Let Zippia find it for you.
Senior IAM Security Engineer - Zero-Trust Auth & PKI
Gemini 4.9
Cyber security analyst job in New York, NY
A leading crypto platform is seeking a Senior IAM Security Engineer to secure identity and access management systems. The role involves developing IAM services, collaborating with engineering teams, and ensuring secure authentication patterns. Candidates should have solid software development skills in Python or Go, experience with PKI and secrets management, and a strong understanding of identity protocols. This position offers a competitive salary and a hybrid work approach, with office presence required twice a week in San Francisco or New York City.
#J-18808-Ljbffr
$112k-159k yearly est. 2d ago
Lead AI Security Engineer
Capital Group 4.4
Cyber security analyst job in New York, NY
"I can be myself at work."
You are more than a job title. We want you to feel comfortable doing great work and bringing your best, authentic self to everything you do. We value your talents, traditions, and uniqueness-and we're committed to fostering a strong sense of belonging in a respectful workplace.
We intentionally seek diverse perspectives, experiences, and backgrounds, investing in a culture designed to celebrate differences. We believe that belonging leads to better outcomes and a stronger community of associates united by our mission. At Capital, we live our core values every day: Integrity, Client Focus, Diverse Perspectives, Long-Term Thinking, and Community.
"I can influence my income."
You want to feel recognized at work. Your performance will be reviewed annually, and your compensation will be designed to motivate and reward the value that you provide. You'll receive a competitive salary, bonuses and benefits. Your company-funded retirement contribution will factor in salary and variable pay, including bonuses.
"I can lead a full life."
You bring unique goals and interests to your job and your life. Whether you're raising a family, you're passionate about where you volunteer, or you want to explore different career paths, we'll give you the resources that can set you up for success.
Enjoy generous time-away and health benefits from day one, with the opportunity for flexible work options
Receive 2-for-1 matching gifts for your charitable contributions and the opportunity to secure annual grants for the organizations you love
Access on-demand professional development resources that allow you to hone existing skills and learn new ones
"I can succeed as a Lead AI Security Engineer at Capital Group"
As aLeadAISecurity Engineer, you willbe responsible forsecuring Capital Group's enterprise AI Platforms.You willhelp enable Capital Group's AIstrategy bybuilding and/orprocuringsolutions toprotecta diverse set of enterprise AI platforms being built and deployed at Capital Group.You'llcollaborate with platformengineering, security engineering, and risk teams toensure their solutions support scalable, secureadoption of AI.
Additionally,you'llbe expected toprovidementoring,advising diverse teams across the organization, andpromoting AI Securityprinciples across Capital Group.
AISecurityProcurementManagements:You willprocureand/or build technical solutionsto reducethe riskof misconfiguration, exploitation, andother security issues formultipleenterprise AI platforms.
Embedding Security in the AIPlatform Ecosystem:Working closely withplatform teams tointegrate securityintoeverycomponentof the AI Platform.
Implementing Security Controls & "Guardrails" for GenAI:Designing, deploying, andoperatingtechnical controls to prevent misuse of AI systems.Guardrails designincludescontent filtering systems, usage policies, and safety checks that mitigate issues like prompt injection attacks, unauthorized data extraction, model bias or hallucinations, and other misuse of generative AIplatforms.
AI Runtime Security:Engineer continually tests and updatestothe guardrails, replacing weaker controls with more robust solutions as threats evolve.
AI Governance:You will work cross functionally with architecture and platform teams tomonitoralignment of solutions to AI Governance processes
Contribute to Standards and Policies:You will providethought leadership for Information Security policies and standards for AIin collaboration with technology risk
AI/Agent SME:Youwill provide AI/Agent subject matterexpertisefor AI Incidentsand Security Reviews, and helpdevelop incident response playbooks for AI-related security incidents
"I am the person Capital Group is looking for."
You have 8+yearsof experience in information security, application security, platform security, or penetration testing,DevSecOps, networksecurityand other security disciplines.
You have experience securing AI platforms, whetherinternal AIplatforms or offerings such as CoPilot Studio, Amazon Bedrock, and/or Azure AI Gateway
Proficient in Programming & ML Tool.Strong Python skillsrequired, with experience in AI/ML frameworks.Abilityto review and write ML code to implement security measures (e.g., model validation, adversarial testing) isdesired.
You have5+ years of relevant professional experience ordemonstrated anequivalent level ofexpertisein security engineering, such as cloud, API, or platform security.
You have3+ years of experience embedded identity, network, and encryption controls into enterprise platforms
Youcaneffectively partner and collaborate with stakeholder teams.
You have effective communication skills andthe abilityto outline security riskstoleadership.
You are familiar with cloud and API security vendors and managed services providers.
Preferred Qualifications:
You have knowledge and experience with technologies including Kubernetes, Containers, CI/CD, and Cloud Service Providers
You are familiar withfunctionand purpose of key AI platform components such as AI gateways (Kong, Databricks Mosaic AI Gateway, custom API orchestration), Model Orchestration (ExamplesLangChain,LlamaIndex, etc.)
You are familiar with key AI regulatory frameworks such as NIST AI RMF, MITRE ATLAS, GDPR, EU AI Act,etc
You have information Security certifications (CISSP, SANS GIAC, CISA, etc.)
"I can apply in less than 4 minutes."
You've reviewed this job posting and you're ready to start the candidate journey with us. Apply now to move to the next step in our recruiting process. If this role isn't what you're looking for, check out our other opportunities and join our talent community.
"I can learn more about Capital Group."
At Capital Group, the success of the people who invest with us depends on the people in whom we invest. That's why we offer a culture, compensation and opportunities that empower our associates to build successful and prosperous careers. Through nine decades, our goal has been to improve people's lives through successful investing. We know that our history is a testament to the strength of the people we hire. More than 9,000 associates in 30+ offices around the world help our clients and each other grow and thrive every day. Find us on LinkedIn, Instagram, YouTube and Glassdoor.
Southern California Base Salary Range: $179,273-$286,837San Antonio Base Salary Range: $147,378-$235,805New York Base Salary Range: $190,040-$304,064
In addition to a highly competitive base salary, per plan guidelines, restrictions and vesting requirements, you also will be eligible for an individual annual performance bonus, plus Capital's annual profitability bonus plus a retirement plan where Capital contributes 15% of your eligible earnings.
You can learn more about our compensation and benefits
here
.
* Temporary positions in the United States are excluded from the above mentioned compensation and benefit plans.
We are an equal opportunity employer, which means we comply with all federal, state and local laws that prohibit discrimination when making all decisions about employment. As equal opportunity employers, our policies prohibit unlawful discrimination on the basis of race, religion, color, national origin, ancestry, sex (including gender and gender identity), pregnancy, childbirth and related medical conditions, age, physical or mental disability, medical condition, genetic information, marital status, sexual orientation, citizenship status, AIDS/HIV status, political activities or affiliations, military or veteran status, status as a victim of domestic violence, assault or stalking or any other characteristic protected by federal, state or local law.
$190k-304.1k yearly 5d ago
Security Engineer, Product Security
Scale Ai, Inc. 4.1
Cyber security analyst job in New York, NY
We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the overall security strategy. Your expertise in TypeScript, Python, Kubernetes, CI/CD, SAST, DAST, and terraform orchestration will be crucial in identifying and mitigating potential security vulnerabilities. You will also structure complex problems, diagnose root causes independently, and clearly explain the mechanics and significance of security vulnerabilities, including their exploitability and potential impact.
You will:
Conduct in-depth code reviews to identify and remediate security vulnerabilities.
Evaluate and enhance the security of our product offerings, through RFC and service review.
Implement and maintain CI/CD pipelines with a strong focus on security.
Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify vulnerabilities in production code.
Utilize terraform orchestration to ensure secure and efficient infrastructure management.
Guide engineering teams to build robust long-term solutions that consider security and privacy.
Clearly explain the mechanics and significance of security vulnerabilities, including their exploitability and potential impact.
Influence the security strategy and direction of the team, advocating for best practices and continuous improvement.
Ideally, you'd have:
Proven experience as a Security Engineer with a focus on product security.
Proficiency in NodeJS, TypeScript, Python, and/or Kubernetes.
Strong understanding of modern Javascript application design.
Production experience with Kubernetes backed services
Hands-on experience with SAST and DAST tools and methodologies.
Familiarity with terraform orchestration for infrastructure management.
You can structure complex problems and diagnose root causes independently, providing actionable insights without requiring manager input.
Excellent communication skills, with the ability to clearly present technical concepts and their implications to both technical and non-technical stakeholders.
Demonstrated ability to influence security strategies and drive improvements within a team.
Relevant security certifications (e.g., CISSP, CEH, OSCP) are a plus.
Compensation packages at Scale for eligible roles include base salary, equity, and benefits. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position, determined by work location and additional factors, including job-related skills, experience, interview performance, and relevant education or training. Scale employees in eligible roles are also granted equity based compensation, subject to Board of Director approval. Your recruiter can share more about the specific salary range for your preferred location during the hiring process, and confirm whether the hired role will be eligible for equity grant. You'll also receive benefits including, but not limited to: Comprehensive health, dental and vision coverage, retirement benefits, a learning and development stipend, and generous PTO. Additionally, this role may be eligible for additional benefits such as a commuter stipend.
Please reference the job posting's subtitle for where this position will be located. For pay transparency purposes, the base salary range for this full-time position in the locations of San Francisco, New York, Seattle is:$189,200-$236,500 USD
PLEASE NOTE:
Our policy requires a 90-day waiting period before reconsidering candidates for the same role. This allows us to ensure a fair and thorough evaluation of all applicants.
About Us:
At Scale, our mission is to develop reliable AI systems for the world's most important decisions. Our products provide the high-quality data and full-stack technologies that power the world's leading models, and help enterprises and governments build, deploy, and oversee AI applications that deliver real impact. We work closely with industry leaders like Meta, Cisco, DLA Piper, Mayo Clinic, Time Inc., the Government of Qatar, and U.S. government agencies including the Army and Air Force. We are expanding our team to accelerate the development of AI applications.
We believe that everyone should be able to bring their whole selves to work, which is why we are proud to be an inclusive and equal opportunity workplace. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability status, gender identity or Veteran status.
We are committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities. If you need assistance and/or a reasonable accommodation in the application or recruiting process due to a disability, please contact us at . Please see the United States Department of Labor's
Know Your Rights poster
for additional information.
We comply with the United States Department of Labor's
Pay Transparency provision
.
PLEASE NOTE: We collect, retain and use personal data for our professional business purposes, including notifying you of job opportunities that may be of interest and sharing with our affiliates. We limit the personal data we collect to that which we believe is appropriate and necessary to manage applicants' needs, provide our services, and comply with applicable laws. Any information we collect in connection with your application will be treated in accordance with our internal policies and programs designed to protect personal data. Please see our privacy policy for additional information.
$189.2k-236.5k yearly 2d ago
Information Security Engineer
Aarete 4.1
Cyber security analyst job in New York, NY
AArete is one-of-a-kind when it comes to consulting firm culture.
We're a global, innovative management and technology consulting firm, with offices in the U.S., India, and the U.K. Our name comes from the Greek word for excellence: "Arete." And excellence is exactly what we strive for.
Our success starts with enriching and empowering our people. From robust career development planning to competitive life and wellness benefits, AArete's "Culture of Care" takes a holistic approach to the employee experience.
AAretians (our team members) are leaders at every level. You are encouraged to unlock your full potential by directly contributing to our mission and prioritizing space for personal development and fulfillment.
The Role
AArete is looking for an Information Security Engineer. You are highly technical with an entrepreneurial spirit and commitment to excellence. You thrive in a team environment and have the ability to flip tasks and priorities midstream because you love an exciting challenge. The bar is set high at AArete. There is a lot to do around here, and you love getting the job done right.
At AArete, we are dedicated to delivering the best experience to our clients every day. We are fresh, passionate, full of energy, and love what we do-providing non-labor cost reduction solutions and impressing our clients with impeccable service.
Work You'll Do
Manage and optimize security technologies, including endpoint protection tools, email security tools, vulnerability scanners, and Siems
Provide support, administration, and maintenance necessary to ensure effective and efficient information technology system performance and security
Identify, analyze, and mitigate threats to internal information technology systems or networks
Maintain baseline system security according to organizational policies
Manage accounts, network rights, and access to systems and equipment
Design access control lists to ensure compatibility with organizational standards, business rules, and needs
Provide ongoing optimization and problem-solving
Analyze data sources to provide actionable recommendations
Assess the validity of source data and subsequent findings
Present technical information to technical and non-technical audiences
Present data in creative formats
Provide actionable recommendations to stakeholders based on data analysis and findings
Oversee installation, implementation, configuration, and support of system components
Answer requests for information
Conduct in-depth research and analysis
Provide input and assist in the development of plans and guidance
Maintain infrastructure within a cloud environment
Other duties as assigned
Requirements
2+ years of experience working in an information security role
Experience with tools such as Sentinel One, Microsoft Defender, Mimecast, Rapid7 IDR, AWS Native Security Services, Microsoft Purview, Microsoft Intune, vRx (Vicarius) or similar
Direct client interaction, including possible travel to client location
Applicants must be based in Chicago, IL, and flexible to work from our Chicago office as needed
Must be legally authorized to work in the United States without the need for employer sponsorship
Preferred Requirements
Technology-focused degree
Professional certifications such as GSEC, SSCP, Security+, SC-200, SC-400 or others
Compensation & Benefits
Flexible PTO, monthly half-day refuels, volunteer time off, 10 paid holidays
Own Your Day flexible work policy
Competitive majority employer-paid benefits: Medical, Dental, Vision, 401K Match
Generous paid parental leave options
Employer paid Life Insurance, STD, LTD
Charitable contribution matching program
New client commission opportunities and referral bonus program
Bike share discount program
The estimated base salary range for this position is $72,000 - $92,000. In addition to this base salary, individuals may be eligible for an annual discretionary bonus. This range is a part of a competitive, total compensation package together with our majority employer-paid benefits and incentive pay for eligible roles. Please note that this range is a guideline and individual total compensation may vary due to numerous factors including but not limited to experience level, certifications, and other relevant business considerations.
AArete will accept applications until the position is filled. The job posting will be removed once the role is no longer available.
We put humans at the center of our work
We're a global management and technology consulting firm specializing in strategic profitability improvement, digital transformation, and strategy & change for clients. Our cross-industry solutions are powered by a digital-first mindset, market intelligence, and data-driven approach to deliver purposeful change, actionable insights, and guaranteed results.
But what sets us apart is our people. We are guided by our deeply embedded guiding principles: Excellence, Passion, Loyalty to Clients, Stewardship, Family, Community, Sustainability, and Inclusion.
And we've been recognized as a top firm to work for by companies like Forbes, Top Workplaces Chicago Tribune, and Consulting Magazine.
We've earned a Great Place to Work Certification and been named a World's Best Management Consulting Firm by Forbes, Vault's Top 50 Firms to Work For, Crain's Chicago Business Fast 50, Inc 5000's Fastest Growing Firms, and Consulting Magazine's Fastest Growing Firms.
Learn more about our award-winning culture
We are an Equal Employment Opportunity Employer
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
#LI-DNI
$72k-92k yearly 4d ago
Network Security Analyst
Skadden 4.9
Cyber security analyst job in White Plains, NY
We invite you to review our current business services professionals openings to learn about the opportunities available across the firm.
About Us
Skadden, Arps, Slate, Meagher & Flom LLP has forged a reputation as one of the most prestigious law firms in the world. Relying on innovation, intellect, teamwork and tenacity, our lawyers deliver the highest quality advice and novel solutions to our clients' legal issues. We are known for handling the most complex transactions, litigation/controversy issues, and regulatory matters, as well as for the strong partnerships we build with clients and each other. Our attorneys, who reflect a broad range of experiences and perspectives, work together seamlessly across 50-plus practices and 21 offices in the world's major financial centers.
The Opportunity
We are seeking two Network SecurityAnalysts to join our Firm. These positions will be based in our White Plains office (hybrid), and please note the roles have different shift times, listed below. The Network SecurityAnalysts are responsible for implementing and supporting network security solutions for the Firm and, implementing and enforcing practical solutions to secure the Firm's internal and external network infrastructure.
Available Shift Times (EST- Hybrid)
1.) Saturday - Sunday: 7:00 a.m. - 8:00 p.m. EST & Monday 7:00 a.m. - 7:00 p.m.
2.) Monday - Friday: 2:00 p.m. - 10:00 p.m.
Note: The scheduled hours listed may be flexible and will be discussed during the interview process.
Responsibilities
Performs daily review of automated security reports and escalate as necessary.
Responds to system generated security alerts and coordinate responses.
Assists with internal audits, vulnerability scans and risk assessments.
Assists with annual penetration testing, review of findings and tracking issue resolution.
Participates in evaluating new technologies or new versions of existing products.
Works with project teams to implement secure network connectivity solutions.
Writes and maintains technical documentation including procedures and troubleshooting guides.
Demonstrates effective interpersonal, written and verbal communication skills to facilitate effective work relationships with others.
Manages Firm resources responsibly.
Complies with and understands Firm operation, policies and procedures.
Performs other related duties as assigned.
Qualifications
Knowledge of relevant firm computer software programs (e.g., Outlook, Excel, PowerPoint), with the ability to learn new software and operating systems
Proficient with Access, Project and Visio
Thorough knowledge of network management and security technologies and approaches
Thorough knowledge of security techniques, latest protocols and defenses
Proficient with Microsoft Active Directory and Operating Systems
Basic ability to program scripts and batch files
Demonstrates effective interpersonal and communication skills, both verbally and in writing
Demonstrates close attention to detail
Excellent analytical, troubleshooting, organizational, and planning skills
Ability to handle multiple projects and shifting priorities
Ability to handle sensitive matters and maintain confidentiality
Ability to organize and prioritize work
Ability to work well in a demanding and fast-paced environment
Ability to work well independently as well as effectively within a team
Ability to use discretion and exercise independent and sound judgment
Flexibility to adjust hours and work the hours necessary to meet operating and business needs
Education/Experience
Bachelor's degree or equivalent
Minimum of two years' experience in multi-national enterprise IT
Culture & Life at Skadden
What makes Skadden special is our people and the culture, community and spirit of collaboration we have created. We believe in teamwork and inspiring each other to be our best in an atmosphere that promotes professionalism and excellence in all that we do. We know that inclusion and drawing on the strength of a wide spectrum of talent only make us better and is vital to the firm's success. Our goal is for everyone at the firm to enjoy a challenging career with opportunities for development and growth and to support the well-being of our attorneys and business services professionals.
Benefits
The overall well-being of our team is important to us. We offer generous benefits to help you achieve wellness in all areas of your life.
Competitive salaries and year-end discretionary bonuses.
Comprehensive health care (medical, dental, vision), savings plan/401(k) and voluntary benefits.
Generous paid time off.
Paid leave options, including parental.
In-classroom, remote, and on-demand learning and professional development opportunities.
Robust well-being classes and programs.
Opportunities to give back and make an impact in local communities.
For further details, please visit: *******************************************************
Skadden is an Equal Opportunity Employer (Disability/Vet/other protected categories). For more information, please visit Skadden.com/careers.
The starting base salary for this position is expected to be within the range listed under Salary Details. Actual salary will be determined based on skills, experience (to the extent relevant) and other-job related factors, consistent with applicable law.
Salary Details
$125,000 -$140,000
EEO Statement
Skadden is an Equal Opportunity Employer. It does not discriminate against applicants or employees based on any legally impermissible factor including, but not limited to, race, color, religion, creed, sex, national origin, ancestry, age, alienage or citizenship status, marital or familial status, domestic partnership status, caregiver status, sexual orientation, gender, gender identity or expression, change of sex or transgender status, genetic information, medical condition, pregnancy, childbirth or related medical conditions, sexual and reproductive health decisions, disability, any protected military or veteran status, or status as a victim of domestic or dating violence, sexual assault or offense, or stalking.
Applicants who require an accommodation during the application process should contact Alex Taylor at **************.
Skadden Equal Employment Opportunity Policy
Skadden Equal Employment Opportunity Policy
Applicants Have Rights Under Federal Employment Law
Applicants Have Rights Under Federal Employment Law
In accordance with the Transparency in Coverage Rule,
click here to review machine-readable files made available by UnitedHealthcare:
Transparency in Coverage
$125k-140k yearly Auto-Apply 58d ago
Cyber Command Forensic Analyst 2
K Systems Solutions 4.0
Cyber security analyst job in New York, NY
Client Name: City of New York
Contract Length (in weeks): 52
Hybrid: 3 days in office/2 days remote.
SCOPE OF SERVICES
The forensics Analyst will investigate network intrusions and other cyber incidents to determine cause, extent and consequences of the breach.
TASKS:
Investigate network intrusions and other cybersecurity incidents to determine the cause and extent of the breach. Includes ability to perform host -based and network -based forensic analysis.
Research and develop new techniques, and procedures to continually improve the digital forensics process.
Produce high quality written work product presenting complex technical issues clearly and concisely.
Managing and maintaining the analysis labs and forensics tools leveraged for investigations.
Ensuring data is collected and preserved within industry standard best practices and in alignment evidence integrity requirements.
Assisting the Cyber Emergency Response Team during critical incidents.
RequirementsMANDATORY SKILLS/EXPERIENCE
Note: Candidates who do not have the mandatory skills will not be considered
Minimum 4 years of experience in Threat Management/Forensics Investigations/Incident Response environment
Proficient in performing digital forensic investigations on a variety of platforms and operating systems with a deep understanding of digital forensics processes and tools.
DESIRABLE SKILLS/EXPERIENCE:
Experience with a wide range of forensic tools (TZWorks, X -Ways, SIFT, AXIOM, Volatility, etc.)
Experience with memory analysis tools (i.e. Volatility)
Experience with Linux and open source tools
Experience investigating intrusions on Windows and Linux/Unix operating systems
Knowledge of gathering, accessing, and assessing evidence from computer systems and electronic
devices
Knowledge of virtual environments
Knowledge of forensic imaging techniques
Knowledge of Microsoft Windows operating system and Windows artifacts
Knowledge of Linux/UNIX operating systems and artifacts
Knowledge of MAC OS operating system and forensics artifacts
Knowledge of file systems
Strong analytical skills
$82k-114k yearly est. 60d+ ago
Cyber Security Analyst
Zone It Solutions
Cyber security analyst job in New York, NY
Job Description
We is seeking a talented CyberSecurityAnalyst. As a CyberSecurityAnalyst, you will play a key role in ensuring the security and integrity of our organization's data and systems.
Requirements
Responsibilities:
Monitor, detect, and respond to cyber threats and security incidents,
Conduct vulnerability assessments and penetration testing to identify potential weaknesses in our systems,
Develop and implement security measures and best practices to protect against cyber attacks,
Stay up-to-date with the latest cybersecurity trends and technologies,
Collaborate with cross-functional teams to identify security risks and implement appropriate solutions,
Provide training and guidance to employees on cybersecurity awareness and best practices.
Requirements:
Bachelor's degree in Computer Science, Information Security, or a related field,
Proven experience in cybersecurity or a related role,
Strong knowledge of security protocols and tools,
Ability to analyze and interpret complex data and make informed decisions,
Excellent problem-solving and communication skills,
Relevant certifications (e.g. CISSP, CISM) are preferred but not required.
Benefits
About Us
Zone IT Solutions is an Australia-based Recruitment Company. We specialise in Digital, ERP and larger IT Services. We offer flexible, efficient and collaborative solutions to any organisation that requires IT, experts. Our agile, agnostic and flexible solutions will help you source the IT Expertise you need. If you are looking for new opportunities, your profile at *******************************.
Also, follow our LinkedIn page for new job opportunities and more.
Zone IT Solutions is an equal-opportunity employer, and our recruitment process focuses on essential skills and abilities.
$80k-109k yearly est. Easy Apply 18d ago
Cyber Command Forensic Analyst
Govserviceshub
Cyber security analyst job in New York, NY
Job Title: Cyber Command Forensic Analyst
SCOPE OF SERVICES:
The forensics Analyst will investigate network intrusions and other cyber incidents to determine cause, extent and consequences of the breach.
TASKS:
· Research and develop new techniques, and procedures to continually improve the digital forensics process.
· Produce high quality written work product presenting complex technical issues clearly and concisely.
· Managing and maintaining the analysis labs and forensics tools leveraged for investigations.
· Ensuring data is collected and preserved within industry standard best practices and in alignment evidence integrity requirements.
· Assisting the Cyber Emergency Response Team during critical incidents.
· Investigate network intrusions and other cybersecurity incidents to determine the cause and extent of the breach. Includes ability to perform host -based and network -based forensic analysis.
MANDATORY SKILLS/EXPERIENCE:
· Minimum 4 years of experience in Threat Management/Forensics Investigations/Incident Response environment
· Proficient in performing digital forensic investigations on a variety of platforms and operating systems with a deep understanding of digital forensics processes and tools.
Requirements
DESIRABLE SKILLS/EXPERIENCE:
· Experience with a wide range of forensic tools (FTK, X -Ways, SIFT, AXIOM, EnCase, etc.)
· Experience with memory analysis tools (i.e. Volatility, MemProcFS)
· Experience with Linux and open source tools
· Experience investigating intrusions on Windows and Linux/Unix operating systems
· Experience with performing forensics collections in cloud environments (AWS, Azure, GCP)
· Knowledge of gathering, accessing, and assessing evidence from computer systems and electronic devices
· Knowledge of virtual environments
· Knowledge of forensic imaging techniques
· Knowledge of Microsoft Windows operating system and Windows artifacts
· Knowledge of Linux/UNIX operating systems and artifacts
· Knowledge of mac OS operating system and forensics artifacts
· Knowledge of file systems
· Strong analytical skills
Skills:
· Incident Management
· Threat Management
· CyberSecurity
$80k-109k yearly est. 41d ago
Global Cyber Wordings Analyst
Liberty Mutual 4.5
Cyber security analyst job in New York, NY
Join our global Cyber team as a Wordings Analyst supporting the Global Cyber Wordings Manager in the strategic development and governance of our Cyber and Tech policy suite, including Liberty Cyber Resolution and Liberty Tech Resolution. This role is a hands-on business enabler: you will help translate complex legal and regulatory requirements into clear, market-ready wordings, maintain our global clause library, support manuscript negotiations, and produce practical tools that empower underwriters and strengthen broker confidence. It's an excellent opportunity for an early-career insurance wordings or legal professional to build expertise in a fast-moving, global specialty line and make a visible impact on growth, innovation, and client experience.
Key responsibilities:
Wording library and drafting support
Maintain and expand the global wording library centered on Liberty Cyber Resolution and Liberty Tech Resolution, including endorsements, exclusions, and guidance notes.
Redline and prepare first drafts of standard clauses and endorsements; ensure consistency with definitions, coverage intent, and plain-language standards.
Track version control, change logs, approvals, and archiving;
Assist with localization for different jurisdictions, coordinating translations and filing documentation with Legal/Compliance.
Commercial enablement
Build practical tools (playbooks, FAQs, objection-handling guides, coverage summaries) to help regional teams position our products and close deals efficiently.
Prepare broker/client comparison decks and battlecards; support pitches, RFP/RFI responses, and manuscript negotiations with clause comparisons and recommended alternatives.
Triage wording queries from regions; track SLAs and referral approvals per the global governance framework.
Partner closely with Underwriting, Product, Global Cyber Engagement, Claims, Legal/Compliance, and regional leaders to deliver accurate, timely support and uphold governance standards.
Regulatory and legal stewardship
Monitor and synthesize global regulatory and market developments (e.g., Lloyd's cyber war/systemic guidance, GDPR, DORA, NIS2, sanctions) into succinct briefs and recommended wording actions.
Maintain audit-ready documentation; assist with regulatory filings or attestations where required.
Claims partnership and feedback loop
Collaborate with Claims to capture lessons from disputes and litigation trends; draft guidance notes and propose clarifications to improve coverage certainty.
Support coverage position letters and documentation packs with research, citations, and clause histories.
Innovation and product development support
Help draft prototype wordings for new propositions
Check alignment between underlying policy wordings and reinsurance treaty/facultative clauses.
Administer wording management tools, ensuring robust version control, approval workflows, and usage analytics.
Build dashboards and trackers for adoption of standard forms, deviation rates, SLA performance, disputes, and audit findings; provide monthly reporting to stakeholders.
Qualifications
Bachelor's degree in business, economics, or other quantitative field. Minimum 3 years, typically 4 years or more of relevant work experience.
2 - 5 years of experience in insurance wordings, legal/paralegal support, underwriting support, or product documentation; cyber specialty experience preferred.
Strong drafting, redlining, and proofreading skills with a plain-language mindset and exceptional attention to detail.
Working knowledge of insurance policy structures, endorsements, exclusions, and coverage interpretation; familiarity with cyber war/systemic language, sanctions, and privacy regulations is advantageous.
Research and synthesis skills to translate complex regulatory/legal topics into practical guidance and actionable updates.
Proficiency with MS Word (advanced track changes/redlining), Excel (trackers and dashboards), PowerPoint (training/pitch materials), and document/enablement tools.
Collaborative, service-oriented approach; comfortable operating in a global matrix and meeting defined SLAs.
Curiosity about cybersecurity risks and the incident response ecosystem; willingness to learn common threat scenarios to inform practical drafting.
About Us
Pay Philosophy: The typical starting salary range for this role is determined by a number of factors including skills, experience, education, certifications and location. The full salary range for this role reflects the competitive labor market value for all employees in these positions across the national market and provides an opportunity to progress as employees grow and develop within the role. Some roles at Liberty Mutual have a corresponding compensation plan which may include commission and/or bonus earnings at rates that vary based on multiple factors set forth in the compensation plan for the role.
At Liberty Mutual, our goal is to create a workplace where everyone feels valued, supported, and can thrive. We build an environment that welcomes a wide range of perspectives and experiences, with inclusion embedded in every aspect of our culture and reflected in everyday interactions. This comes to life through comprehensive benefits, workplace flexibility, professional development opportunities, and a host of opportunities provided through our Employee Resource Groups. Each employee plays a role in creating our inclusive culture, which supports every individual to do their best work. Together, we cultivate a community where everyone can make a meaningful impact for our business, our customers, and the communities we serve.
We value your hard work, integrity and commitment to make things better, and we put people first by offering you benefits that support your life and well-being. To learn more about our benefit offerings please visit: ***********************
Liberty Mutual is an equal opportunity employer. We will not tolerate discrimination on the basis of race, color, national origin, sex, sexual orientation, gender identity, religion, age, disability, veteran's status, pregnancy, genetic information or on any basis prohibited by federal, state or local law.
Fair Chance Notices
California
Los Angeles Incorporated
Los Angeles Unincorporated
Philadelphia
San Francisco
We can recommend jobs specifically for you! Click here to get started.
$86k-112k yearly est. Auto-Apply 13d ago
Experienced Analyst - Strategic, Defense, and Shareholder Advisory
Evercore Inc. 4.9
Cyber security analyst job in New York, NY
Primary Responsibilities: The Analyst will provide value add analysis and research as part of the Strategic, Defense, and Shareholder Advisory team within the Advisory business. In this role, the Analyst will create client presentations regarding hostile activity, proxy fights, shareholder activism, and corporate governance. The Analyst will work on live activism and raid defense situations, as well as create materials for use in client presentations, internal meetings, and marketing initiatives. The Analyst will work in a team environment within Evercore's Strategic, Defense, and Shareholder Advisory practice.
Responsibilities include, but are not limited to the following:
* Create materials related to shareholder activism, hostile activity, shareholder engagement and corporate governance for use in client presentations, internal meetings and marketing initiatives
* Support live engagements, including proxy fights and raid defense situations, contested M&A and special committee assignments
* Perform research and analysis to identify company's potential vulnerabilities to activist shareholders or potential acquirors
* Monitor relevant trends and regulatory developments
* Collaborate closely with senior bankers and other internal teams on strategic mandates
Specific Qualifications:
* Graduate of Class of 2024 through Class of 2025
* Relentless work ethic and high energy level
* An excellent, team-based atttiude
* Excellent communication skills (written and verbal)
* Proficient in Microsoft Office, specifically Excel
* Exceptional attention to detail
* Calm under pressure with a demonstrated track record of successfully managing multiple projects simultaneously
* Intellectual curiosity and an interest in finance
Expected Base Salary Range: $120,000-$140,000.
In addition to a competitive base salary, employees may be eligible to receive a discretionary bonus delivered in the form of cash and/or deferred equity. Evercore also offers a variety of benefits and programs, subject to eligibility. These include, but are not limited to:
* Medical, prescription, dental, and vision insurance, including healthcare savings and reimbursements accounts
* 401(k) Retirement Plan
* Life and disability insurance, including additional voluntary financial protection insurance
* Well-being resources and programs, including mental health and mindfulness programs, digital wellness platforms, well-being events, and targeted on-site health services
* Family-building and family-support benefits
* Paid parental, caregiver, marriage and bereavement leave
* Commuter benefits, health club membership discounts, and other corporate discounts
* Paid holidays, vacation days, personal days, sick days, and volunteer opportunities
About Evercore: Evercore (NYSE: EVR) is a premier global independent investment banking advisory firm. We are dedicated to helping our clients achieve superior results through trusted independent and innovative advice on matters of strategic significance to boards of directors, management teams, and shareholders - including mergers and acquisitions, shareholder advisory, restructurings, and capital structure. Evercore also assists clients in raising public, private capital, delivers equity research, equity sales and agency trading execution, in addition to providing wealth and investment management services to high-net-worth individuals. Founded in 1995, the Firm is headquartered in New York and maintains offices and affiliate offices in major financial centers in North America, Europe, the Middle East, and Asia. For more information, please visit *****************
Inclusion and Equal Opportunity Employment: Evercore is an equal employment opportunity employer and does not discriminate against individuals because of actual or perceived race, color, creed, religion, sex, pregnancy, national origin or ancestry, mental or physical disability, age, veteran status, military status, citizenship status, sexual orientation, gender identity or expression, genetic information, or immigration or citizenship status, or any other characteristic protected by applicable law (referred to as "protected status"), in accordance with applicable federal, state and local laws.
$120k-140k yearly 20d ago
Network Security Analyst
Integrated Resources 4.5
Cyber security analyst job in Newark, NJ
A Few Words About Us Integrated Resources, Inc is a premier staffing firm recognized as one of the tri-states most well-respected professional specialty firms. IRI has built its reputation on excellent service and integrity since its inception in 1996. Our mission centers on delivering only the best quality talent, the first time and every time. We provide quality resources in four specialty areas: Information Technology (IT), Clinical Research, Rehabilitation Therapy and Nursing.
Job Description:
Network SecurityAnalyst
6 months CTH
• 3+ years of designing, implementing and supporting CISCO ISE is required
Responsibilities:
Work with vendor to ensure the quality design, implementation, installation/configuration, and provide technical admin support for Cisco ISE Authentication Authorization, Posture Assessment, and AnyConnect end point Malware Prevention solutions.
• Upgrade Cisco ISE infrastructure including hardware, software, and AnyConnect
• Perform Cisco ISE Authentication and Authorization
• Enforce security Posture compliance for wired and wireless endpoints and enhance infrastructure security using the Cisco ISE
• Deploy Cisco ISE Profiling and client provisioning services
• Integrate Endpoint Malware Protection Services (AMP) with AnyConnect and Cisco ISE
• Provide Reports, Monitoring, Troubleshooting, and Security
Work with vendor on problem resolution
Create policies and reports to meet the business requirements
Participate in Planning, Design, and Tests
Perform security audits, scan and monitor servers
Investigate and report on security alerts and perform security incident reporting
Requirements:
Expert-level knowledge and experience with design, implementation and support of Cisco ISE
3-5 year of experience working with Network Security applications
Complex routing and switching solutions (Cisco is a must, Nexus strongly preferred, other manufacturers are a plus)
Advance knowledge of networking, TCP/IP, FTP, SCP, firewalls, ACLs, Authentication protocols, Authorization, VPN, PKI, RSA, and Encryption
Knowledge of Directory Services including Active Directory, LDAP, and TDS
Knowledge of F5 load balancers
Knowledge of IT security principles, HIPAA, SOX and PCI regulations
Knowledge of IDS/IPS, Malware Prevention (Sourcefire & Fireye desired, Palo Alto a plus)
Business Analysis skills and ability to translate business requirements into technical requirements
Excellent oral/written communication and organizational skills
Security certification a plus such as CISSP, CEH or CISA
Qualifications
Bachelor's Degree in Computer Science, Programming, or IT required
Additional Information
Contact- 732-549-2030 ext 242
Harshad
$92k-125k yearly est. 60d+ ago
Cyber Security Engineer
ACLU of Illinois 4.0
Cyber security analyst job in New York, NY
ABOUT THE JOB
The ACLU seeks applicants for the full-time position of Cybersecurity Engineer in the Information Security Department of the ACLU's National office in New York, NY. This is a hybrid role that has in-office requirements of two (2) days per week or eight (8) days per month.
Director of Security Architecture & Engineering, this hands-on technical role is responsible for securing the ACLU's infrastructure, endpoints, and cloud services by reducing vulnerability risk, improving control enforcement, and operationalizing core data protection strategies.
This role is ideal for a security engineer who thrives at the intersection of infrastructure, identity, and data - someone ready to roll up their sleeves to turn policy into technical enforcement. The engineer will drive progress across cloud posture, endpoint compliance, DLP, and insider risk detection, ensuring controls are not just defined but deployed, measurable, and resilient in production environments.
This position is part of a collective bargaining unit. It is represented by ACLU Staff United (ASU).
WHAT YOU'LL DO
Reporting to the Director of Security Architecture & Engineering, the Cybersecurity Engineer will be accountable for executing core infrastructure and endpoint security priorities across cloud, network, and device environments.
YOUR DAY TO DAY
Implement and manage cloud security posture tooling and alerts, ensuring visibility into configuration drift, overexposure, and high-risk services.
Lead the vulnerability management lifecycle - including scanning, prioritization, stakeholder coordination, remediation tracking, and reporting.
Deploy and enforce secure configuration baselines across managed devices (Windows, mac OS, mobile), including disk encryption, patch compliance, and privileged access.
Identify exposed services and reduce attack surface across infrastructure and endpoint environments using automation and policy-based enforcement.
Develop and maintain secure configuration management practices across IAM, network segmentation, endpoint posture, and SaaS platforms.
Engineer and support enterprise Data Loss Prevention (DLP) tooling, including policy definition, control enforcement, and incident response workflows across email, endpoint, and cloud.
Implement and tune insider threat detection signals using endpoint telemetry, behavior analytics, and identity context, in coordination with Security Operations.
Serve as a technical escalation point for endpoint, cloud, and identity security issues impacting control integrity or coverage.
FUTURE ACLU'ERS WILL
Be committed to advancing the mission of the ACLU
Center and embed the principles of equity, inclusion and belonging in their work by demonstrating commitment to diversity with an approach that respects and values multiple perspectives
Be committed to work collaboratively and respectfully toward resolving obstacles and conflicts
WHAT YOU'LL BRING
Demonstrated experience in security engineering, cloud/infrastructure security, or endpoint protection.
Strong working knowledge of DLP, data classification, and endpoint telemetry tooling (e.g., Microsoft Purview, Intune, Defender for Endpoint, Jamf, etc.).
Hands-on experience with vulnerability management platforms and remediation coordination.
Experience designing and deploying secure configurations across Windows, mac OS, and mobile environments.
Familiarity with insider risk detection tooling or behavioral analytics platforms is a strong plus.
Proficiency with scripting or infrastructure-as-code (e.g., PowerShell, Python, Terraform).
Excellent communication and cross-functional collaboration skills, particularly across IT, Legal, and Privacy stakeholders.
Commitment to securing digital systems in a mission-driven and rights-centered environment.
COMPENSATION The ACLU is committed to equity, transparency, and clarity in pay. Consistent with our compensation philosophy, there is a set salary for each role based on geographic work location. The annual salary for this position is $137,206(Level - F), reflecting the salary of a position based in New York, NY. Salaries are subject to a regional pay adjustment if authorization is granted to work outside of the location listed in this posting. For details on our pay structure, please visit: ************************************************************************ WHY THE ACLU
For over 100 years, the ACLU has worked to defend and preserve the individual rights and liberties guaranteed by the Constitution and laws of the United States. Whether it's ending mass incarceration, achieving full equality for the LGBTQ+ community, establishing new privacy protections for our digital age, or preserving the right to vote or the right to have an abortion, the ACLU takes up the toughest civil liberties cases and issues to defend all people.
We know that great people make a great organization. We value our people and know that what we offer is essential not just their work, but to their overall well-being.
At the ACLU, we offer a broad range of benefits, which include:
Time away to focus on the things that matter with a generous paid time-off policy
Focus on your well-being with comprehensive healthcare benefits (including medical, dental and vision coverage, parental leave, gender affirming care & fertility treatment)
Plan for your retirement with 401k plan and employer match
We support employee growth and development through annual professional development funds, internal professional development programs and workshops
OUR COMMITMENT TO ACCESSIBILITY, EQUITY, DIVERSITY & INCLUSION
Accessibility, equity, diversity and inclusion are core values of the ACLU and central to our work to advance liberty, equality, and justice for all. For us diversity, equity, accessibility, and inclusion are not just check-the-box activities, but a chance for us to make long-term meaningful change. We are a community committed to learning and growth, humility and grace, transparency and accountability. We believe in a collective responsibility to create a culture of belonging for all people within our organization - one that respects and embraces difference; treats everyone equitably; and empowers our colleagues to do the best work possible. We are as committed to anti-oppression, anti-ableism, and anti-racism internally as we are externally. Because whether we're in the courts or in the office, we believe ‘We the People' means all of us.
With this commitment in mind, we strongly encourage applications from all qualified individuals without regard to race, color, religion, gender, sexual orientation, gender identity or expression, age, national origin, marital status, citizenship, disability, veteran status and record of arrest or conviction, or any other characteristic protected by applicable law.
The ACLU is committed to providing reasonable accommodation to individuals with disabilities. If you are a qualified individual with a disability and need assistance applying online, please email
************************
. If you are selected for an interview, you will receive additional information regarding how to request an accommodation for the interview process.
The Department of Education has determined that employment in this position at the ACLU does not qualify for the Public Service Loan Forgiveness Program.
$137.2k yearly Auto-Apply 60d+ ago
Senior Security Analyst | Corporate Security
Ramp Business Corporation
Cyber security analyst job in New York, NY
About Ramp At Ramp, we're rethinking how modern finance teams function in the age of AI. We believe AI isn't just the next big wave. It's the new foundation for how business gets done. We're investing in that future - and in the people bold enough to build it.
Ramp is a financial operations platform designed to save companies time and money. Our all-in-one solution combines payments, corporate cards, vendor management, procurement, travel booking, and automated bookkeeping with built-in intelligence to maximize the impact of every dollar and hour spent. More than 50,000 businesses, from family-owned farms to e-commerce giants to space startups, have saved $10B and 27.5M hours with Ramp. Founded in 2019, Ramp powers the fastest-growing corporate card and bill payment platform in America, and enables over $100 billion in purchases each year.
Ramp's investors include Lightspeed Venture Partners, Thrive Capital, Sands Capital, General Catalyst, Founders Fund, Khosla Ventures, Sequoia Capital, Greylock, Redpoint, and ICONIQ, as well as over 100 angel investors who were founders or executives of leading companies. The Ramp team comprises talented leaders from leading financial services and fintech companies-Stripe, Affirm, Goldman Sachs, American Express, Mastercard, Visa, Capital One-as well as technology companies such as Meta, Uber, Netflix, Twitter, Dropbox, and Instacart.
Ramp has been named to Fast Company's Most Innovative Companies list and LinkedIn's Top U.S. Startups for more than 3 years, as well as the Forbes Cloud 100, CNBC Disruptor 50, and TIME Magazine's 100 Most Influential Companies.
About the Role
Ramp's Enterprise Security team is responsible for keeping our people, data, and internal tools safe while enabling a fast‑moving, AI‑driven business.
As a Senior SecurityAnalyst (Corporate Security), you'll own and scale core security programs across identity, endpoints, SaaS, and data. You'll be the primary driver for Insider Risk, DLP, SaaS posture, and endpoint security across both our corporate and FedRAMP‑aligned environments-designing strategy, implementing controls, and measuring outcomes.
Ramp is agent‑first: we rely heavily on AI assistants and automated workflows. You'll ensure those capabilities are securely rolled out to the business, not blocked.
Hybrid in NYC: This role is based in New York City and requires working in‑person at our HQ (near Madison Square Park) at least 2 days per week.
This is a senior, hands‑on individual contributor role (IC5), not a people‑management or SOC Tier 1 position.
What You'll Do
* Own core enterprise security programs
Lead and continuously improve Insider Risk and DLP across Ramp-from policies and detections to playbooks, case handling, and stakeholder training.
* Secure SaaS at scale
Manage and harden our SaaS stack (SSPM/CASB and native controls):
* Remediate misconfigurations
* Remove stale accounts/admins
* Enforce key rotation and safe OAuth scopes
* Gate risky apps and integrations
* Run sovereign / FedRAMP‑aligned environments
Operate sovereign Google Workspace and Okta tenants with strict access, monitoring, and logging. Partner with GRC to ensure controls align to NIST 800‑53/800‑171 and FedRAMP‑aligned requirements without slowing down the business.
* Modernize identity & access
Work with IT and Security Engineering to enforce:
* Phishing‑resistant MFA
* Device‑aware and context‑aware access
* Least privilege and just‑in‑time (JIT) patterns
* SCIM‑based lifecycle management
* Strong break‑glass access patterns and reviews
* Harden endpoints and network
Help keep our mac OS and Windows fleets secure at scale using EDR, MDM, and disk encryption; drive patch SLAs; and enforce ZTNA/SSE policies (e.g., Cloudflare WARP) for secure access to internal resources.
* Measure, review, and improve
Define and track key metrics (coverage, policy efficacy, MTTD/MTTR, configuration drift). Run regular control health reviews and drive remediation with partner teams.
* Automate and simplify
Use scripting, APIs, or workflow tools to reduce manual toil in enterprise security operations (e.g., account hygiene, access reviews, configuration checks, alert triage).
* Partner & communicate
Collaborate closely with IT, Engineering, Legal, People, and GRC. Write clear docs, runbooks, and decision records that make it easy for others to operate and build on your work.
What You Need
* Experience level
* 3+ years in enterprise/corporate security engineering or operations, with hands‑on ownership of security controls for identity, endpoints, SaaS, or data.
* You're comfortable being the primary owner of programs, not just following an existing playbook.
* Eligibility
* U.S. citizenship is required for this role due to the nature of our sovereign / FedRAMP‑aligned environments.
* Technical background
* Practical experience implementing and tuning Insider Risk, DLP, SaaS posture, or endpoint security in a cloud‑first environment.
* Hands‑on administration of a modern identity provider and collaboration suite-Okta and Google Workspace are ideal, but similar experience (e.g., Azure AD / Entra ID, Microsoft 365) is highly relevant.
* Familiarity with tools and concepts like EDR, MDM, SSPM/CASB, DSPM, and ZTNA/SSE, and experience hardening mac OS and/or Windows at scale.
* Experience aligning controls to at least one security framework or regulated environment (e.g., FedRAMP, NIST 800‑53/171, SOC 2, ISO 27001) and translating requirements into practical enterprise controls.
* How you work
* You can spot gaps, design pragmatic remediations, and drive them to completion across multiple teams.
* You're comfortable using automation (scripts, workflows, or low‑code tools) to make security more scalable and less manual.
* You communicate clearly-whether you're writing a runbook, summarizing risk tradeoffs, or explaining a control choice to non‑security partners.
* You enjoy partnering with IT and Engineering to get things shipped, not just documented.
Nice-to-Haves
* Experience operating sovereign or public‑sector / regulated tenants (e.g., FedRAMP, StateRAMP, or similar).
* Background scaling security in a high‑growth, cloud‑first startup or scale‑up environment (ideal but not required).
* Experience securing or enabling AI/agent workflows inside an enterprise.
* Intermediate scripting skills (e.g., Python, Bash, PowerShell) for automation and integrations.
* Relevant certifications (e.g., CISSP, CISM, Security+, GIAC) or equivalent real‑world depth.
Benefits (for U.S.-based full-time employees)
* 100% medical, dental & vision insurance coverage for you
* Partially covered for your dependents
* One Medical annual membership
* 401k (including employer match on contributions made while employed by Ramp)
* Flexible PTO
* Fertility HRA (up to $10,000 per year)
* Parental Leave
* Pet insurance
* Centralized home-office equipment ordering for all employees
* Health and Wellness stipend
* In-office perks: lunch, snacks, drinks, and more
* Budget for intra-office travel
* Relocation support to NYC or SF (as needed)
Referral Instructions
If you are being referred for the role, please contact that person to apply on your behalf.
Other notices
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Ramp Applicant Privacy Notice
$95k-130k yearly est. 29d ago
Information Security Analyst
Healthsolutions
Cyber security analyst job in New York, NY
Public Health Solutions (PHS) is a 501(c)3 non-profit community-based organization (CBO) that has existed for 70 years to improve health equity and address health-related social needs (HRSN) for historically underserved marginalized communities. As the largest public health nonprofit serving New York City, we improve health outcomes and help communities thrive by providing services directly to vulnerable families, supporting community-based organizations through our long-standing public-private partnerships, and bridging the gap between healthcare and community services. We focus on a wide range of public health issues including food and nutrition, health insurance, maternal and child health, sexual and reproductive health, tobacco control, and HIV/AIDS. Learn more about our work at healthsolutions.org.
PHS administers WholeYouNYC (WYNYC), a coordinated community resource network that builds trustworthy and reliable pathways between healthcare providers, health plans and CBOs providing critical resources in the community that address the social drivers of health. WYNYC brings together over 100 organizations offering various programs - such as food, housing, employment, health insurance, and sexual health services - across all five boroughs. These services and programs make it possible for New Yorkers to live their healthiest lives and ultimately reduce health disparities and advance health equity. To date, our network has already impacted thousands of lives through community partnerships and referrals, generating millions in estimated healthcare savings.
New York State (NYS) recently announced the availability of $500M statewide to support Social Care Network (SCN) lead entities responsible for coordinating social care delivery in various regions across the state. Public Health Solutions (PHS) and our WYNYC network were awarded the role of regional SCN for Brooklyn, Manhattan, and Queens.
This is a grant-funded position ending March 31, 2027.
Program Description:
The Information SecurityAnalyst is responsible for supporting and maintaining the organization's information security and compliance program in accordance with applicable federal, state, and contractual requirements, including the NYS OHIP, Common Security Framework (CSF), and HIPAA Security practices.
This position plays a critical role in safeguarding organizational assets by monitoring information systems, evaluating security controls, and coordinating incident response activities. The Analyst will collaborate closely with internal IT resources, the managed Security Operations Center (SOC), and external partners to ensure adherence to established policies, standards, and regulatory obligations.
Key Responsibilities
Regulatory Compliance and Risk Management
Support and maintain compliance with OHIP PM-17 standards, NYS security requirements , HITRUST CSF , and HIPAA regulations.
Participate in internal and external security audits, assessments, and certification readiness efforts.
Document and maintain evidence of compliance activities, corrective action plans, and remediation tracking.
Assist in the periodic review and revision of information security policies, standards, and procedures.
Security Operations
Monitor and respond to alerts generated through the organization's SIEM and security monitoring platforms, in coordination with the SOC.
Investigate, triage, and document security incidents and vulnerabilities in accordance with established escalation protocols.
Prepare and distribute regular security and compliance reports to IT leadership.
Microsoft 365 and Azure Security
Administer and maintain controls within the Microsoft 365 Security & Compliance Center , including data loss prevention (DLP), auditing, retention, and threat protection.
Implement and review Azure Cloud security configurations , including conditional access, identity protection, and secure baselines.
Monitor privileged access and ensure adherence to least-privilege and separation-of-duties principles.
Coordination and Communication
Serve as a liaison with the SOC and external vendors for incident response, threat intelligence, and log management activities.
Collaborate with infrastructure, application, and compliance teams to align security practices with organizational objectives.
Qualifications and Experience:
Education: Associate or Bachelor's degree in IT, Computer Science, or related field or equivalent.
Experience : Minimum of one(1) to three (3) years of professional experience in information security, cybersecurity operations, or IT compliance.
Demonstrated knowledge of, NYS OHIP, and HIPAA compliance frameworks.
Proficiency with Microsoft 365 Security & Compliance Center, Azure Security Center, and Defender for Cloud.
Experience with SIEM platforms (e.g., Microsoft Sentinel, Splunk, LogRhythm) and associated reporting functions.
Familiarity with security incident response, vulnerability management, and risk assessment methodologies.
Strong written and verbal communication skills, with the ability to produce audit-ready documentation and reports
Desired Skills:
Professional certifications such as CompTIA Security+, CISSP, CCSK, Microsoft Certified: Security Operations Analyst Associate, or HITRUST CCSFP.
Prior experience supporting compliance efforts within a public health, nonprofit, or governmental organization.
Key Attributes for Success
Strong eagerness to learn and develop new technical skills.
A proactive and problem-solving mindset.
Attention to detail and ability to document IT processes clearly.
Ability to work both independently and collaboratively within an IT team.
Willingness to take on new challenges in a fast-paced IT environment.
Reports To:
Information Security Manager
Direct Reports:
This position has no direct reports
Benefits:
• Hybrid Work Schedule.
• Generous Paid Time Off and Holidays.
• An attractive and comprehensive benefits package including Medical, Dental and Vision.
• Flexible Spending Accounts and Commuter Benefits.
• Company Paid Life Insurance and Disability Coverage.
• 403(b) + employer matching and discretionary company contributions.
• College Savings Plan.
Ongoing training and continuous opportunities for professional growth and development.
At PHS, we place immense value on diversity within our teams, understanding that varied backgrounds and experiences significantly enhance our community and propel us toward our goals. If you find you don't have experience in all the areas listed above, we still encourage you to apply and share your background and experiences in your application. We are eager to discover how your unique perspective can bring positive transformations to our team and help advance our mission of creating healthier, more equitable communities.
We look forward to learning more about you!
PHS is proud to be an equal opportunity employer and encourages applications from women, people of color, persons with disabilities, LGBTQIA+ individuals, and veterans.
$83k-118k yearly est. Auto-Apply 27d ago
Principal Security Information Analyst
Gen Digital
Cyber security analyst job in New York, NY
Principal Information SecurityAnalyst (Tier 2) As a Principal Information SecurityAnalyst within Gen Digital's global Security Operations Center (SOC), you will play a key role in strengthening threat detection and response across the organization. The role focuses on improving SOC monitoring and detection processes through technical expertise, continuous development, and close collaboration with other security teams.
In this position, you will serve as a senior specialist, leading automation and detection engineering efforts, mentoring junior analysts and contributing to projects that enhance security visibility and overall SOC performance.
Operating in a follow-the-sun model, the SOC ensures 24/7 global coverage, with regional teams working during their respective business hours and sharing on-call responsibilities for weekend.
Key Responsibilities:
* Monitor, analyze, and correlate security alerts and events across multiple platforms (SIEM, WAF, EDR, email, cloud, network, and threat intelligence tools) to identify and validate suspicious or malicious activity
* Continuously develop and fine-tune detection rules, correlation searches, security policies, and dashboards to improve visibility, reduce false positives, and increase alert accuracy across security platforms
* Support and mentor Tier 1 analysts in alert triage, escalation quality, and use of tools
* Collaborate with security engineers on automation and enrichment initiatives to streamline operational workflows and improve detection efficiency
* Maintain complete and up-to-date documentation for all detection use cases, workflows and process improvements
* Participate in security projects and collaborate with internal stakeholders (e.g., Incident Response, Security Engineering, Application Security, and IT) to enhance detection coverage, visibility, and response capabilities
* Support the execution of incident response playbooks
Qualification and Work Experience:
* 3-5 years of hands-on experience in SOC operations, cybersecurity monitoring, or related areas such as detection engineering or threat analysis
* Solid understanding of networking concepts (TCP/IP, DNS, HTTP/S) and how they apply to security monitoring and threat analysis
* Strong knowledge of cybersecurity principles, common attack techniques, and threat types (e.g., phishing, malware, brute force, web application attacks)
* Proven experience working with security logs, alerts, and structured data across multiple platforms (SIEM, EDR, WAF, cloud, and network telemetry)
* Hands-on experience with SIEM platforms - Splunk preferred - including detection content development, rule tuning, and dashboard creation
* Familiarity with Web Application Firewall (WAF) technologies and the ability to analyze or tune related alerts and policies
* Understanding of cloud security concepts and experience with monitoring tools for major providers (AWS, Azure, GCP)
* Working knowledge of scripting or automation (e.g., Python, PowerShell, or API-based integrations) to support analysis and enrichment workflows
* Experience using AI-based tools to support daily SOC operations, including data analysis, investigation, documentation, and collaboration
* Strong analytical and problem-solving skills with attention to detail and curiosity for continuous learning
* Effective communication and documentation skills in English, both written and verbal
* Experience collaborating across teams (e.g., Security Engineering, Incident Response, Application Security) on detection improvements or automation projects
* Prior experience in a Security Operations Center (SOC) or similar environment is highly preferred
* Familiarity with the fintech environment or experience supporting financial services infrastructure is considered a strong advantage
#LI-AS1
Gen is proud to be an equal-opportunity employer, committed to diversity and inclusivity. We base employment decisions on merit, experience, and business needs, without considering race, color, national origin, age, religion, sex, pregnancy, genetic information, disability, medical condition, marital status, sexual orientation, gender identity or expression, military or veteran status, or other unlawful factors. Gen prohibits discrimination based on these protected characteristics and recruits talented candidates from diverse backgrounds.
We consider individuals with arrest and conviction records and do not discriminate against employees for discussing their own pay or that of other employees or applicants. Learn more about pay transparency.
To conform to U.S. export control regulations, applicant should be eligible for any required authorizations from the U.S. Government.
$83k-118k yearly est. Auto-Apply 60d+ ago
Information Security Specialist
McCartney Hr
Cyber security analyst job in New York, NY
Information Security Specialist Job Responsibilities:
Safeguards information system assets by identifying and solving potential and actual security problems.
Information Security Specialist Job Duties:
Protects system by defining access privileges, control structures, and resources.
Recognizes problems by identifying abnormalities; reporting violations.
Implements security improvements by assessing current situation; evaluating trends; anticipating requirements.
Determines security violations and inefficiencies by conducting periodic audits.
Upgrades system by implementing and maintaining security controls.
Keeps users informed by preparing performance reports; communicating system status.
Maintains quality service by following organization standards.
Maintains technical knowledge by attending educational workshops; reviewing publications.
Contributes to team effort by accomplishing related results as needed.
Information Security Specialist Skills and Qualifications:
System Administration, Network Security, Problem Solving, Information Security Policies, Informing Others, Process Improvement, On\-Call, Network Troubleshooting, Firewall Administration, Network Protocols, Routers, Hubs, and Switches. "}}],"is Mobile":false,"iframe":"true","job Type":"Full time","apply Name":"Apply Now","zsoid":"641401441","FontFamily":"Verdana, Geneva, sans\-serif","job OtherDetails":[{"field Label":"Industry","uitype":2,"value":"Technology"},{"field Label":"City","uitype":1,"value":"Brooklyn"},{"field Label":"State\/Province","uitype":1,"value":"New York"}],"header Name":"Information Security Specialist","widget Id":"**********00072311","is JobBoard":"false","user Id":"**********00133003","attach Arr":[],"custom Template":"3","is CandidateLoginEnabled":true,"job Id":"**********00267067","FontSize":"12","location":"Brooklyn","embedsource":"CareerSite","indeed CallBackUrl":"https:\/\/recruit.zoho.com\/recruit\/JBApplyAuth.do","logo Id":"2qf78d018cc5be94b40bbbcb719566377b192"}
$83k-118k yearly est. 60d+ ago
Information Security Analyst
Ra 3.1
Cyber security analyst job in Jersey City, NJ
Why us? You will be part of a team that believes that believes in employees success! They are a dynamic, fast growing company with great opportunities and an employee focused company culture. Join this fantastic team today and make a difference in your life and the lives of those around you!
They are an equal opportunity employer and value diversity at our company.
Job Description
Strong knowledge of Information Security concepts such as:
•Encryption, Cloud and Mobile Device Security
•Data Loss and Prevention tools and solutions
•Risk-Threat Analysis and Vulnerability Assessments
•Enterprise Security Monitoring, Role-Based Access Control (RBAC)
•Identity and Access Management, Computer Forensic
•IT Audit and Compliance, Regulatory Requirements (HIPAA, CMS, FISMA, et. al.)
•Knowledge of common vulnerability tools, and the ability to identify basic categories of vulnerability.
Sounds like you? then ping us with your most updated resume. We'd love to talk to you!
We are excited about the companies growth and the role you will play with them.
Qualifications
Desired Skills & Experience:
You hold a Bachelor's degree in any domain.
You are certified in CISSP, or CISA, or CEH, required.
You have more than 1 year experience working in the IT security function.
You have good experience with Operating System, Database, Network and
Application Security
.
Additional Information
All your information will be kept confidential according to EEO guidelines. Ping me at
**********************
$91k-130k yearly est. Easy Apply 6h ago
Information Security Analyst
Public Health Solutions 4.7
Cyber security analyst job in New York, NY
Public Health Solutions (PHS) is a 501(c)3 non-profit community-based organization (CBO) that has existed for 70 years to improve health equity and address health-related social needs (HRSN) for historically underserved marginalized communities. As the largest public health nonprofit serving New York City, we improve health outcomes and help communities thrive by providing services directly to vulnerable families, supporting community-based organizations through our long-standing public-private partnerships, and bridging the gap between healthcare and community services. We focus on a wide range of public health issues including food and nutrition, health insurance, maternal and child health, sexual and reproductive health, tobacco control, and HIV/AIDS. Learn more about our work at healthsolutions.org.
PHS administers WholeYouNYC (WYNYC), a coordinated community resource network that builds trustworthy and reliable pathways between healthcare providers, health plans and CBOs providing critical resources in the community that address the social drivers of health. WYNYC brings together over 100 organizations offering various programs - such as food, housing, employment, health insurance, and sexual health services - across all five boroughs. These services and programs make it possible for New Yorkers to live their healthiest lives and ultimately reduce health disparities and advance health equity. To date, our network has already impacted thousands of lives through community partnerships and referrals, generating millions in estimated healthcare savings.
New York State (NYS) recently announced the availability of $500M statewide to support Social Care Network (SCN) lead entities responsible for coordinating social care delivery in various regions across the state. Public Health Solutions (PHS) and our WYNYC network were awarded the role of regional SCN for Brooklyn, Manhattan, and Queens.
This is a grant-funded position ending March 31, 2027.
Program Description:
The Information SecurityAnalyst is responsible for supporting and maintaining the organization's information security and compliance program in accordance with applicable federal, state, and contractual requirements, including the NYS OHIP, Common Security Framework (CSF), and HIPAA Security practices.
This position plays a critical role in safeguarding organizational assets by monitoring information systems, evaluating security controls, and coordinating incident response activities. The Analyst will collaborate closely with internal IT resources, the managed Security Operations Center (SOC), and external partners to ensure adherence to established policies, standards, and regulatory obligations.
Key Responsibilities
Regulatory Compliance and Risk Management
Support and maintain compliance with OHIP PM-17 standards, NYS security requirements , HITRUST CSF , and HIPAA regulations.
Participate in internal and external security audits, assessments, and certification readiness efforts.
Document and maintain evidence of compliance activities, corrective action plans, and remediation tracking.
Assist in the periodic review and revision of information security policies, standards, and procedures.
Security Operations
Monitor and respond to alerts generated through the organization's SIEM and security monitoring platforms, in coordination with the SOC.
Investigate, triage, and document security incidents and vulnerabilities in accordance with established escalation protocols.
Prepare and distribute regular security and compliance reports to IT leadership.
Microsoft 365 and Azure Security
Administer and maintain controls within the Microsoft 365 Security & Compliance Center , including data loss prevention (DLP), auditing, retention, and threat protection.
Implement and review Azure Cloud security configurations , including conditional access, identity protection, and secure baselines.
Monitor privileged access and ensure adherence to least-privilege and separation-of-duties principles.
Coordination and Communication
Serve as a liaison with the SOC and external vendors for incident response, threat intelligence, and log management activities.
Collaborate with infrastructure, application, and compliance teams to align security practices with organizational objectives.
Qualifications and Experience:
Education: Associate or Bachelor's degree in IT, Computer Science, or related field or equivalent.
Experience : Minimum of one(1) to three (3) years of professional experience in information security, cybersecurity operations, or IT compliance.
Demonstrated knowledge of, NYS OHIP, and HIPAA compliance frameworks.
Proficiency with Microsoft 365 Security & Compliance Center, Azure Security Center, and Defender for Cloud.
Experience with SIEM platforms (e.g., Microsoft Sentinel, Splunk, LogRhythm) and associated reporting functions.
Familiarity with security incident response, vulnerability management, and risk assessment methodologies.
Strong written and verbal communication skills, with the ability to produce audit-ready documentation and reports
Desired Skills:
Professional certifications such as CompTIA Security+, CISSP, CCSK, Microsoft Certified: Security Operations Analyst Associate, or HITRUST CCSFP.
Prior experience supporting compliance efforts within a public health, nonprofit, or governmental organization.
Key Attributes for Success
Strong eagerness to learn and develop new technical skills.
A proactive and problem-solving mindset.
Attention to detail and ability to document IT processes clearly.
Ability to work both independently and collaboratively within an IT team.
Willingness to take on new challenges in a fast-paced IT environment.
Reports To:
Information Security Manager
Direct Reports:
This position has no direct reports
Benefits:
• Hybrid Work Schedule.
• Generous Paid Time Off and Holidays.
• An attractive and comprehensive benefits package including Medical, Dental and Vision.
• Flexible Spending Accounts and Commuter Benefits.
• Company Paid Life Insurance and Disability Coverage.
• 403(b) + employer matching and discretionary company contributions.
• College Savings Plan.
Ongoing training and continuous opportunities for professional growth and development.
At PHS, we place immense value on diversity within our teams, understanding that varied backgrounds and experiences significantly enhance our community and propel us toward our goals. If you find you don't have experience in all the areas listed above, we still encourage you to apply and share your background and experiences in your application. We are eager to discover how your unique perspective can bring positive transformations to our team and help advance our mission of creating healthier, more equitable communities.
We look forward to learning more about you!
PHS is proud to be an equal opportunity employer and encourages applications from women, people of color, persons with disabilities, LGBTQIA+ individuals, and veterans.
$68k-96k yearly est. Auto-Apply 27d ago
Information Security Analyst
Creston
Cyber security analyst job in Rockleigh, NJ
The Information SecurityAnalyst plays a key role in advancing the company's Governance, Risk & Compliance (GRC) program by protecting enterprise information assets and ensuring compliance with regulatory, contractual, and ethical standards. This position offers hands-on experience across multiple security domains including policy governance, risk management, AI governance, and data security, making it an excellent opportunity for early career professionals or recent graduates passionate about cybersecurity and emerging technology risks. In this role, you will collaborate with teams across Information Security, IT, and Legal to drive initiatives that safeguard sensitive data, maintain compliance obligations, and promote responsible use of artificial intelligence and other advanced technologies.
Responsibilities
Governance & Policy Management
Assist in developing, maintaining, and aligning information security policies with frameworks such as NIST CSF, ISO 27001, SOC 2, CIS, and the NIST AI RMF.
Contribute to documentation and control mapping for new or updated regulations related to AI, privacy, and data protection (e.g., GDPR, CCPA, NIST 800-53 Rev 5).
Support internal policy review cycles, ensuring consistent version control and executive approval.
Risk Management
Participate in enterprise risk assessments, including third-party, application, and AI model risk reviews.
Help identify, document, and track remediation of security and privacy risks within the GRC platform (e.g., Drata, ServiceNow GRC, OneTrust, Vanta, etc.).
Support the development of risk metrics and dashboards for leadership reporting.
Learn to evaluate AI-related risks such as model bias, data leakage, data lineage, model transparency, and unintended data exposure.
Data Governance & Data Security
Assist with data classification, retention, and handling standards, ensuring sensitive data is appropriately protected.
Support data inventory and mapping efforts to improve visibility where critical data resides.
Help review access controls, encryption standards, and secure data transfer processes in coordination with IT teams.
Collaborate with the IT team to ensure alignment between data quality, privacy, and security controls.
Compliance & Audit Support
Gather and organize evidence for internal and external audits (ISO 27001, PCI, HIPAA, etc.).
Maintain control documentation and track audit remediation activities.
Support continuous monitoring of compliance requirements and updates to regulatory obligations, including emerging AI governance and data-related laws.
AI Governance Support
Contribute to inventories of AI tools and use cases across the enterprise.
Assist in risk assessments for AI systems, ensuring they align with responsible AI principles such as fairness, accountability, and transparency.
Collaborate with IT and legal teams to ensure that AI use complies with company policies.
Security Awareness & Communication
Help design and distribute training materials related to cybersecurity, data protection, and responsible AI practices.
Support internal campaigns promoting secure data handling and ethical technology usage.
Prepare metrics, dashboards, and presentations for leadership briefings.
Continuous Improvement
Participate in projects that automate or streamline GRC processes, such as policy lifecycle management or risk scoring.
Stay informed about new threats, regulatory trends, and AI governance frameworks.
Engage in ongoing professional development and certification opportunities.
Qualifications
Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Data Science, or a related field is preferred
0-2 years of experience in cybersecurity, risk management, compliance, or data governance (internship or coursework acceptable).
Understanding of cybersecurity principles, risk management, and data privacy fundamentals.
Basic familiarity with AI systems, data governance concepts, or information security practices.
Strong analytical, communication, and documentation skills.
Ability to manage multiple priorities in a fast-paced environment.
Proficient in Microsoft Excel, PowerPoint, and data analysis or GRC tools.
Exposure to frameworks such as NIST CSF, ISO 27001, SOC 2, NIST AI RMF, or COBIT.
Must be able to work in the U.S. without sponsorship
Per applicable state requirements, the annual pay range for this position ($60,500 - $84,000) which consists of base salary (subject to performance), reflects the hiring range for candidates. Also note, an individual's offer may vary from this range as it may be impacted by additional factors, including but not limited to the candidate's hiring location, qualifications, experience, and market factors.
How much does a cyber security analyst earn in Yonkers, NY?
The average cyber security analyst in Yonkers, NY earns between $69,000 and $125,000 annually. This compares to the national average cyber security analyst range of $66,000 to $117,000.
Average cyber security analyst salary in Yonkers, NY