Cyber Security Analyst
Information security analyst job in New York, NY
Job Title: Sr. Cybersecurity Risk Analyst
Duration: 24+Months
Responsibilities:
Build new risk processes and implement risk frameworks to enable better monitoring and evaluation of risks across the City;
Manage complex, cross-functional projects, pushing through ambiguity and challenges which may arise;
Work with stakeholders across various divisions, soliciting input and working through feedback;
Evaluate risk of third parties used by New York City agencies;
Document and track remediation of risks in the Risk Register;
Review and analyze various cybersecurity risk cases, justification, and exceptions documents submitted by agencies;
Assist in the development of cybersecurity risk assessment procedures and testing methodologies based on established frameworks and guidelines;
Initiating corrective actions to remediate vulnerabilities or weaknesses where necessary;
Engage in communications with NYC Agencies;
Handle special projects and initiatives as assigned.
Required Sklls:
A minimum of 4 years of experience in risk management or cybersecurity risk assessment or 4 years of experience evaluating and managing third parties in a cybersecurity team.
DESIRABLE SKILLS/EXPERIENCE:
BS/BA degree in Cybersecurity, Risk Management, Information Systems, Computer Science, or a related field.
One or more of the following certifications are a plus:
Certified Information Systems Auditor (CISA)
Certified Information Systems Security Professional (CISSP)
Certified in Risk and Information Systems Control (CRISC)
Certified Information Security Manager (CISM)
CompTIA Security+
CompTIA Network+
CompTIA A+
CompTIA CySA+
Cisco Certified Network Associate - CCNA
CEH: Certified Ethical Hacker
GIAC Information Security Fundamentals (GISF)
GIAC Security Essentials (GSEC)
(ISC)2 Systems Security Certified Practitioner (SSCP)
Ability to work effectively in a team environment.
Being highly organized, motivated and a self-directed professional.
Knowledge of hardware, software, data, and network principles and systems related to Private and/or Public Sectors services.
Understanding of commonly used computer operating systems, databases, network structures.
Familiarity with cybersecurity framework(s) (NIST, SANS, PCI, ISO 27001/27002, or CIS)
Investigative and analytical skills.
Excellent oral and written communication skills;
Knowledge of the current and evolving cyber threat landscape;
Knowledge of laws, regulations, policies, and ethics related to cybersecurity and information privacy;
Cyber Command Forensic Analyst
Information security analyst job in New York, NY
Contact Details:
1.Poonam Khandelwal
Email: poonam.khandelwal@peer-consulting.com
Cell: (732) 797-9766
Job Title: Cyber Command Forensic Analyst
Duration: 48 months
Years of Experience: 8+ years
Required Hours/Week: 35hrs/week
Job Description:
The forensics Analyst will investigate network intrusions and other cyber incidents to determine cause, extent and consequences of the breach.
Research and develop new techniques, and procedures to continually improve the digital forensics process.
Produce high quality written work product presenting complex technical issues clearly and concisely.
Managing and maintaining the analysis labs and forensics tools leveraged for investigations.
Ensuring data is collected and preserved within industry standard best practices and in alignment evidence integrity requirements.
Assisting the Cyber Emergency Response Team during critical incidents.
Investigate network intrusions and other cybersecurity incidents to determine the cause and extent of the breach. Includes ability to perform host-based and network-based forensic analysis.
Mandatory Skills/ Experience:
Candidates who do not have the mandatory skills will not be considered.
Minimum 4 years of experience in Threat Management/Forensics Investigations/Incident Response environment
Proficient in performing digital forensic investigations on a variety of platforms and operating systems with a deep understanding of digital forensics processes and tools.
Desirable Skills/ Experience:
Experience with a wide range of forensic tools (FTK, X-Ways, SIFT, AXIOM, EnCase, etc.)
Experience with memory analysis tools (i.e. Volatility, MemProcFS)
Experience with Linux and open source tools
Experience investigating intrusions on Windows and Linux/Unix operating systems
Experience with performing forensics collections in cloud environments (AWS, Azure, GCP)
Knowledge of gathering, accessing, and assessing evidence from computer systems and electronic devices
Knowledge of virtual environments
Knowledge of forensic imaging techniques
Knowledge of Microsoft Windows operating system and Windows artifacts
Knowledge of Linux/UNIX operating systems and artifacts
Knowledge of mac OS operating system and forensics artifacts
Knowledge of file systems
Strong analytical skills
Cyber Security Specialist
Information security analyst job in New York, NY
Akkodis is seeking a Cybersecurity Operations Specialist role is a Direct hire with a client located in NYC 10022 (Hybrid). Ideally looking for applicants to have a solid background in Security operations, SOC, Financial services, FINRA, SEC would come as a big plus.
Salary Range: $130k-$140k/Annum + Benefits, The salary may be negotiable based on experience, education, geographic location, and other factors.
We are seeking a Cybersecurity Operations Specialist to join our security operations team and play a hands-on role in monitoring, protecting, and improving the firm's cybersecurity posture.
This position focuses on day-to-day security operations, vulnerability management, and incident response across our on-premise and cloud environments (AWS and Microsoft 365). The ideal candidate has strong technical knowledge of endpoint protection, identity management, and network security, combined with an analytical mindset and attention to detail suitable for a regulated financial environment.
Key Responsibilities:
Security Operations & Monitoring
Monitor and investigate alerts from CrowdStrike Falcon XDR, Microsoft Defender, and Intune.
Conduct triage and escalation of suspicious activities in coordination with infrastructure and IT teams.
Maintain visibility and reporting through Tenable Security Center and Nessus vulnerability scans.
Support log analysis, correlation, and event tracking through integrated dashboards or SIEM platforms.
Vulnerability & Patch Management
Perform routine vulnerability assessments and track remediation status.
Collaborate with system administrators to ensure timely patching of Windows, Linux, and network devices.
Validate risk reduction and patch compliance before closing findings.
Endpoint & Identity Security
Administer and monitor Symantec Endpoint Protection Manager (EPM) and Microsoft Intune policies.
Enforce endpoint encryption (Corporate Laptop), application control, and posture management.
Manage Microsoft Entra (Azure AD) identity policies, MFA enforcement, and conditional access rules.
Review privileged account usage and assist in quarterly access recertification.
Network & Cloud Protection
Support network segmentation, VPN access, and firewall change reviews on Juniper platforms.
Monitor ZScaler logs for anomalous web traffic or policy violations.
Assist with AWS and Microsoft 365 security baselines, configuration hardening, and identity governance.
Security Awareness & Compliance
Administer and report on employee phishing and training campaigns via KnowBe4.
Support audit requests (FINRA, SEC, SOC1/2) by preparing evidence and log samples.
Maintain documentation of incidents, vulnerabilities, and security control tests.
Incident Response & Reporting
Participate in incident containment, investigation, and remediation.
Collect forensic artifacts (logs, screenshots, binaries) as directed by the CISO.
Prepare post-incident summaries and lessons-learned documentation.
Qualifications:
Required
Bachelor's degree in Information Security, Computer Science, or related field (or equivalent experience).
3-5 years of experience in security operations, SOC, or IT security support.
Working knowledge of EDR/XDR platforms (CrowdStrike, Defender), vulnerability scanners (Nessus), and firewall/IDS systems.
Understanding of Windows/Linux administration, TCP/IP networking, and cloud identity management.
Strong analytical, documentation, and communication skills.
Preferred
Experience with regulated financial institutions (FINRA, SEC, NFA, CFTC).
Certifications such as CompTIA Security+, CySA+, Microsoft Certified: Security Operations Analyst, or GIAC GSEC.
Familiarity with scripting or automation (PowerShell, Python) for security tasks.
If you are interested in this role, then please click APPLY NOW. For other opportunities available at Akkodis, or any questions, feel free to contact me at *********************************.
Equal Opportunity Employer/Veterans/Disabled
Benefits offerings include but are not limited to:
• 401(k) with match
• Medical insurance
• Dental Insurance
• Vision assistance
• Paid Holidays Off
To read our Candidate Privacy Information Statement, which explains how we will use your information, please visit ******************************************
The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable:
· The California Fair Chance Act
· Los Angeles City Fair Chance Ordinance
· Los Angeles County Fair Chance Ordinance for Employers
· San Francisco Fair Chance Ordinance
Cyber Security Engineer
Information security analyst job in New York, NY
JOB FUNCTION
The Cybersecurity Engineer will be responsible for implementing and maintaining the firm's cybersecurity technology solutions, monitoring for security incidents and vulnerabilities, coordinating end user activities, and participating in the investigation and response of any breaches or attacks. The ideal candidate will be a self-starter who can work both independently and collaboratively with diverse technical and business teams. He or she will report to the Chief Information Security Officer. Additional responsibilities include:
Managing the vulnerability management program, including internal and external scanning, monitoring threat feeds, news sources, and vendor bulletins for risks and tracking remediation
Maintaining and monitoring control baselines, hardening standards, asset/coverage metrics, and configuration compliance
Monitoring and documenting key performance indicators (KPIs) and governance, risk, and compliance (GRC) evidence
Suggesting and evaluating new technologies
Educating employees on security best practices to reduce the risk of human error
Collaborating with the Cloud, Systems, Network, Database, Desktop, and Development engineering teams on risk identification, analysis, and remediation
Assisting with vendor due diligence
Assisting with physical security infrastructure projects, maintenance, and updates
QUALIFICATIONS
The ideal candidate should have the following experience:
3+ years of experience in a Security Engineer role
Proficiency with managing EDR solutions, SIEM, network security, cloud security, mobile security, vulnerability management, identity and access management, encryption, and a solid understanding of operating systems like Windows and Linux
Strong ability to analyze security data, identify threats, and create effective solutions
Ability to document and communicate technical information clearly to both technical and non-technical audiences
Scripting/automation experience a plus
The ideal candidate possesses the following traits:
Creativity: the ability to deploy different approaches and be resourceful.
Intellectual curiosity: passion for learning and investigating a broad range of subject matter; satisfaction derived from the consumption and understanding of information and increasing knowledge base.
Accountability: ownership of individual responsibilities and work product.
Strong people skills: ability to build relationships internally and externally and to be versatile in engaging with different constituents.
Software Security Engineer
Information security analyst job in New York, NY
Software Security Engineer (Agentic AI Platform)
We are partnered with a fast moving AI company that recently closed an eight figure seed round and is now building the core technical foundation that will support their next phase of growth. The founders are experienced second time operators moving with serious velocity and they have brought us in to help make a mission critical early hire.
This is a rare opportunity to join at the ground level and take full ownership of the infrastructure, security posture, and enterprise readiness of a product already gaining strong traction with financial and enterprise customers.
What You Will Do
Design build and maintain scalable secure and resilient cloud infrastructure for a high performance AI platform.
Define and implement cloud security standards authentication guardrails and enterprise grade controls such as SSO RBAC and audit logging.
Lead the companies readiness for SOC2 and ISO compliance and partner closely with the founders to navigate enterprise requirements.
Own the technical architecture for any infrastructure or security blockers encountered with large customers.
Build robust observability systems including metrics logging and tracing to support reliability at scale.
Design and ship production systems end to end from concept to architecture to deployment.
Collaborate with AI engineering and product teams to ensure infrastructure supports rapid iteration growth and enterprise expansion.
What We Are Looking For
Three or more years of hands on experience across backend engineering infrastructure or security engineering.
Strong cloud security fundamentals with Azure experience especially helpful.
A proven ability to architect and maintain production grade cloud systems.
Experience building secure scalable services with strong engineering rigor.
Comfort working directly with fast moving founders in an AI native environment.
Experience preparing for or leading SOC2 or ISO compliance efforts is a major plus.
Location
New York City.
Compensation
$200k - $300k Base Salary + Founding Level Equity
At CodeRed Partners we are committed to supporting equal opportunity employers and helping build diverse and inclusive teams. People are at the center of everything we do and we are proud to partner with companies shaping the future of AI through technical excellence trust and authentic collaboration.
Chief Information Security Officer
Information security analyst job in New York, NY
Chief Information Security Officer (CISO)
📍
💰
Base Salary:
Up to $325,000 + Bonus + Equity
🏢
Our Client:
A Blockchain & Digital Asset Infrastructure Company
About Our Client
Our client is a fast-growing organization building infrastructure, software, and services that support the next generation of blockchain and digital asset ecosystems. They power secure transactions, institutional-grade solutions, and high-performance platforms used across the crypto economy.
As the business scales, they are expanding their leadership team with a Chief Information Security Officer (CISO) who will own the strategic direction, operations, and continuous improvement of all information and cybersecurity initiatives.
Role Overview
The CISO will set the long-term vision for security across the entire organization, covering infrastructure, products, employee environments, and customer-facing systems. This leader will ensure that the company's digital asset capabilities, blockchain networks, APIs, and cloud environments meet the highest standards of protection, resilience, and regulatory readiness.
This role requires an executive who can operate across technical, operational, and strategic levels-partnering with engineering, legal, compliance, product, and leadership teams.
Key Responsibilities
Design and drive a holistic security strategy covering infrastructure security, application security, product security, data governance, and operational risk.
Safeguard digital asset environments, including wallets, key management systems, consensus mechanisms, and blockchain-based services.
Build and lead an advanced threat detection, monitoring, and incident response program, ensuring rapid response and clear communication pathways.
Collaborate with engineering teams to integrate secure development practices into blockchain, smart contract, and cloud-native workflows.
Establish and maintain security controls, audits, and certifications, ensuring alignment with industry frameworks and regulatory expectations.
Oversee vendor security, supply-chain risk management, and third-party assessments.
Develop a culture of security throughout the business, including training, policy development, and ongoing risk awareness.
Provide regular reports and briefings to the executive team on emerging threats, risk posture, and security roadmap progress.
Experience & Qualifications
15+ years of experience in cybersecurity, with at least 5 years leading security organizations or programs at scale.
Strong experience in blockchain security, digital asset custody, exchange or infrastructure security, or related crypto-native environments.
Demonstrated success leading enterprise security programs that span cloud infrastructure, distributed systems, and high-availability environments.
Skilled in working with frameworks such as SOC 2, ISO 27001, NIST, and global data protection standards.
Expertise in cloud security (AWS, GCP, Azure), network security architecture, identity management, and DevSecOps.
Comfortable operating in fast-moving, engineering-driven environments.
Professional certifications (CISSP, CISM, CCISO, etc.) are a strong plus.
Information Security Architect
Information security analyst job in New York, NY
Title: Information Security Architect
On-site/Remote/Hybrid: Hybrid 3 days onsite/2 days remote.
Duration: 12 Months
Work Hours: 37.5 Hours/Week.
Interview Process: 1-2 Rounds
Job Description:
This position is responsible for assisting in the development, implementation, and support of security architectures and solutions including security frameworks and roadmaps within the corporate business and Operational units across the agencies. It also includes securing enterprise information by determining security requirements, planning, implementing, and testing security systems with a team player environment. The following desired knowledge, skills, and abilities are required for this position. Knowledge of and experience in developing and documenting security architecture and plans, including strategic, tactical and project plans. Knowledge of common information security management frameworks. Excellent technical knowledge of mainstream operating systems and a wide range of security technologies, such as network security appliances, identity and access management systems, anti-malware solutions, automated policy compliance tools and desktop security tools. Ability to develop, document and maintain security policies, processes, procedures, and standards. Knowledge of network infrastructure including routers, switches, firewalls and the associated network protocols and concepts. Strong analytical skills required to analyze security requirements and relate such requirements to the appropriate security controls.
Responsibilities include the following.
Determine security requirements by evaluating business strategies and requirements; researching information security standards; conducting system security and vulnerability analyses; studying architecture/platform; identifying integration issues; preparing cost estimates.
Plan security systems by evaluating network and security technologies; developing requirements for local area networks, wide area networks, virtual private networks, routers, firewalls, and related security and network devices; designs public key infrastructures, including use of certification authorities and digital signatures as well as hardware and software; adhering to industry standards.
Implement security systems by specifying intrusion detection methodologies and equipment; directing equipment and software installation and calibration; preparing preventive and reactive measures; creating, transmitting, and maintaining keys; providing technical support; completing documentation.
Upgrade security systems by monitoring security environment; evaluating and implementing enhancements.
Prepare system security reports by collecting, analyzing, and summarizing data and trends. Track and understand emerging security practices and standards by participating in educational opportunities, reading professional publications and participating in professional organisation.
Senior Cyber Security Engineer (IAM, PAM, SOAR)
Information security analyst job in New York, NY
Senior Cyber Security Engineer, NYC Hybrid (3 Days a week Onsite)
Our client is a financial services provider and they're looking for a senior engineer with real depth in Python OO and CyberArk or Swimlane to step into a high impact role. This is a hands-on position in a stable environment where you will own serious engineering problems and build the next generation of identity and PAM controls.
What you will work on:
• Engineering CyberArk (IAM/PAM) integrations and custom PAM solutions
• Building Python based tooling, APIs, and automation that matter
• Strengthening enterprise identity platforms across a complex environment
• Collaborating with senior architects while still owning the code
What we are looking for:
• Python object-oriented engineering, not scripting
• CyberArk (IAM/PAM) or Swimlane (SOAR) engineering experience
• Infrastructure security background
• 15+ years' experience in Engineering and/or Cyber Security
• Experience in financial services or large enterprise is a plus
Who usually fits this role:
• Identity and PAM platform engineers
• SOAR engineers who build with Python
• Infra security engineers tired of purely operational work
Senior Security Engineer
Information security analyst job in New York, NY
You will provide guidance and technical support to clients deploying security integrations. You'll act as the technical partner, providing strategic guidance around complex systems to secure a digital environment. Interacting directly with the client, you'll partner closely with client personnel to guide and suggest integrations to better serve their success. Your thorough understanding of our product integrations contributes to the development of new principles and concepts - providing detailed analysis around what's working, what's not, and what could be better.
You enjoy implementation work, are proactive about resolving potential concerns, and operate well around strict best practices that enable our clients on their road to a more secure digital world. You're creative, innovative, and you love a challenge - learning how integrations might work better around new products and technologies.
Responsibilities
Communicate with the customer(s), sales teams, peers, engineering and support teams as appropriate
Understand the customer environment, requirements, and security roadmap to implement the appropriate security solution
Configure, implement, and maintain Security Operating Platform
Optimize and migrate policies and objects from the existing environment to our Next-Gen Firewall
Test and validate the migration environment
Coordinate and execute cutover to production
Provide guidance on code upgrades
Facilitate the development of new application and threat signatures
Interact with our Technical Assistance Center (TAC) to understand and diagnose support cases
Some travel may be required, dependent on customer request
You work with the customer's security & network teams to build confidence across the business units impacted by the change
Experience
High level of experience with Panorama and log collectors
NGFW
Global Protect
BS in Computer Science, MIS, business, or equivalent education/training/experience
Minimum of 5 years' experience with network/security solutions and technologies (BGP, SD-WAN concepts, VXLAN and general routing and switching)
Minimum of 3 years' experience leading security solutions in large environments)
Detailed technical experience in the installation, configuration, and operation of high-end firewall appliances, ideally Palo Alto Networks products
You're experienced in internetworking, LAN, and WAN technologies
You have a good understanding of Internet protocols and applications
Any of the following industry certifications or equivalent experience is a plus: CISSP, CCNA, PCNSE, JNCIE-SEC
You effectively handle multiple projects and work calmly in high pressure
You're an excellent writer, with strong verbal communication skills, with demonstrable ability to communicate to senior leaders and technical peers
Lead Security Engineer
Information security analyst job in New York, NY
Lead Security Engineer - Hands-On Role with Leadership Opportunity
We're looking to hire a senior-level Security Engineer who's ready to step up and take the lead. Someone who's still very hands-on technically but also enjoys mentoring others, setting direction, and building scalable solutions that make a real difference.
Title: Lead Security Engineer
Salary: $160,000 to 190,000 +Bonus
Location: Queens, NY (Hybrid)
This role sits at the center of engineering, operations, and security-you'll be working directly with software and infrastructure teams to make sure security is embedded into everything we do. You won't just be managing tools; you'll help shape how security is done across the company.
If you're based in the NYC area and looking for the next serious step in your career-where your ideas are heard and your work actually drives change-this is worth a conversation.
What the Role Looks Like:
You'll lead and mentor a small but growing team of security engineers, helping them grow while staying deep in the tech yourself.
Work with internal teams to design and implement security solutions-cloud security, PAM, app and system hardening, etc.
You'll be the one connecting the dots between development, infrastructure, and security-building relationships across teams and making sure security is part of the process from the start.
Help optimize and improve the tools we already have, and figure out what's missing.
What We're Hoping You Bring:
A few years of experience leading or mentoring other security engineers-you don't need to have managed huge teams, but you've helped others level up.
Solid technical background (5+ years in security engineering) and experience with on-prem and cloud security solutions (AWS or Azure).
Hands-on knowledge of privileged access, identity management, system hardening, and network security.
Strong instincts for risk, practical problem-solving, and keeping systems both secure and usable.
Someone who communicates clearly, doesn't get lost in buzzwords, and works well with people across teams.
Nice to Have, But Not Dealbreakers:
Certifications like CISSP, CEH, CISM
Experience with Linux security or scripting
Familiarity with CI/CD pipelines and how security fits into DevOps
Why This Role Might Be Right for You:
You're ready for more responsibility and leadership, but don't want to give up the technical side of the work.
You want to be part of a stable company with real backing and complex challenges to work on.
Sr Technical Security Engineer
Information security analyst job in New York, NY
Sr. Technical Security Engineer, W2 remote Minimum Requirements
5+ years of experience in application or product security, with a track record of securing desktop and mobile applications.
Strong understanding of secure architecture for thick clients, including local storage protection, inter-process communication, JavaScript engines, OS-level security features, and web security standards (CSP, same-origin policy, TLS/HTTPS).
Experience with mobile (iOS/Android) and desktop (Windows/mac OS/Linux) application security models.
Proficiency in GenAI security, modern cryptography, certificate management, secure authentication (OAuth, WebAuthn, FIDO2), and secure session handling.
Knowledge of OS-level hardening techniques, sandboxing, privilege separation, and secure use of platform APIs.
Hands-on experience with secure coding practices in at least one systems language (C++, Rust, Go) and one application language (Kotlin, Swift, C#).
Familiarity with static/dynamic analysis tools, fuzzing, penetration testing, and reverse engineering for client applications.
Experience embedding security into the software development lifecycle (threat modeling, code reviews, secure design patterns).
Ability to manage incident response and vulnerability remediation for thick client environments.
Strong cross-team communication skills and ability to write clear developer-facing security guidelines.
Lead Security Engineer - Trading Technology
Information security analyst job in Great Neck, NY
The Team:
The Security Engineering Lead will be responsible for designing, building, and maintaining the organization's security infrastructure. This role requires a highly skilled professional who can lead a team of engineers, implement innovative security solutions, and ensure the resilience of the organization's systems and networks. The ideal candidate will have extensive experience in security engineering, a strong technical background, and the ability to manage and deliver complex security projects.
**This Role does NOT provide sponsorship**
Salary: $150k-$190k base w/ 20% bonus
Responsibilities:
Leadership and Management: Lead and mentor a team of security engineers, fostering a culture of continuous learning and innovation. Build and scale a global team to meet organizational needs.
Architecting Security Solutions: Assist teams in designing and implementing advanced security solutions, including cloud security, privilege access management and application/system security.
Collaboration: Partner with software development, infrastructure, and operations teams to embed security into the development lifecycle and operational processes.
Performance Optimization: Regularly evaluate and optimize existing security tools and technologies to ensure maximum efficacy and efficiency.
Training and Knowledge Sharing: Develop and deliver technical security training to engineers and other staff, ensuring a strong organizational security posture.
Documentation and Reporting: Create detailed documentation for security systems and processes, and provide regular project reports senior management.
Required Skills and Experience:
Experience (3+ year) in people leadership roles, nurturing security engineers into high-performing teams.
Experience (5+ years) in a security engineering role, focusing on designing and implementing security solutions and managing security infrastructure, both on-premise and cloud.
Experience working with privilege and identity management solutions.
Experience with operating system security and system hardening.
Knowledge of network security principles, protocols, and technologies.
Strong analytical and problem-solving skills, with the ability to assess risks and develop appropriate security controls.
Excellent communication and interpersonal skills, with the ability to effectively communicate complex security concepts to technical and non-technical stakeholders.
Ability to work independently, prioritize tasks, and manage multiple projects simultaneously.
Strong leadership skills, with the ability to mentor and guide junior team members.
Skills and Experience That Would Help You Stand Out:
A bachelor's degree in Computer Science, Information Security, or a related field. A master's degree is a plus.
Professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or Certified Information Security Manager (CISM) are highly desirable.
Linux security experience
Familiarity with DevSecOps and integrating security into CI/CD pipelines.
Scripting experience.
Senior Cloud Security Engineer (Infrastructure and Security) - New York - Competitive Salary + Competitive Package + Opportunity to work with an Ambitious, Young, Growing Organisation!
Information security analyst job in New York, NY
This young and agile company, providing identity risk solutions is currently seeking a Senior Cloud Security Engineer with a focus on Infrastructure and Security to join their growing team.
You will assist with the continuous maturation of their Cloud Security services within the Security division.
This is an excellent opportunity for an experienced Cloud Security Engineer with experience in both Infrastructure and Security to take the next step into a challenging position with a company offering significant growth potential.
About the Company:
Founded in the last 10 years, they are one the fastest growing companies in their space.
They are a fast-growing company that have built a platform that allows finance organisations and fintechs to strengthen their security defences.
Their mission is to allow companies to manage their identity and fraud risk.
Everything they do is entrenched in achieving engineering excellence.
Their culture is not corporate, and they like to trust their employees to take on a lot of responsibility and have input into the shape of growth of the organisation.
About the Senior Cloud Security Engineer (Infrastructure and Security) Vacancy:
What you will be doing:
• Serve as a cloud security subject matter expert, advise on and implementing best practices
• Respond to security incidents and provide timely and appropriate solutions
• Conduct cloud security risk assessments and audits
• Conduct investigations into security incidents and potential threats
• Take part in on call rotations for incident response and remediation
• Assist with policy management, security audits, and due diligence for cloud security concerns
• Advise on, configuring, and managing a variety of security tools
• Keep informed about and respond to emerging security threats and vulnerabilities
• Assist with cloud security reviews of potential vendors
Ideal Requirements for the Senior Cloud Security Engineer (Infrastructure and Security) Vacancy:
• Several years of experience working in a similar role with a focus on Cloud Security in AWS
• Experience provisioning infrastructure in AWS using Terraform, CloudFormation, CDK, or similar tools
• Experience configuring VPCs, route tables, NACLs, Security Groups, iptables, Web Application Firewall, Config, GuardDuty, Inspector, KMS, IAM, etc.
• In depth knowledge of AWS security best practices around systems hardening, monitoring, and incident response
• Experience taking part in an on-call rotation
• You are passionate about securing infrastructure, reducing risk, and protecting data!
• You are a subject matter expert on cloud security in AWS
• You have a solid understanding of network architecture and protocols
• You can advise on cloud security policies and procedures
Apply to the Role:
Roles like these are snapped up very quickly, so act now if you do not want to miss out! Reply to this advert or email your CV to **********************
Information Technology Analyst
Information security analyst job in New York, NY
Job Title: Information Technology Analyst I
Duration: 3 Months assignment with possible extension
Schedule: 7a-3p - 5 days/week (including weekends). Hours if resource works Saturday &/or Sunday will be 9a-5p regardless of shift they are booked for.
Pay Range: $25 - $28/Hour
Requirements:
Bachelors or equivalent exp (R).
Degree in computer science (P).
1-2 yr exp (P).
Excellent analytical, problem solving , written and verbal communication skills, strong customer service skills. (R).
Ability to work within a team environment (R).
“Pride Health offers eligible employee's comprehensive healthcare coverage (medical, dental, and vision plans), supplemental coverage (accident insurance, critical illness insurance and hospital indemnity), 401(k)-retirement savings, life & disability insurance, an employee assistance program, legal support, auto, home insurance, pet insurance, and employee discounts with preferred vendors”
Network Security Analyst
Information security analyst job in White Plains, NY
We invite you to review our current business services professionals openings to learn about the opportunities available across the firm.
About Us
Skadden, Arps, Slate, Meagher & Flom LLP has forged a reputation as one of the most prestigious law firms in the world. Relying on innovation, intellect, teamwork and tenacity, our lawyers deliver the highest quality advice and novel solutions to our clients' legal issues. We are known for handling the most complex transactions, litigation/controversy issues, and regulatory matters, as well as for the strong partnerships we build with clients and each other. Our attorneys, who reflect a broad range of experiences and perspectives, work together seamlessly across 50-plus practices and 21 offices in the world's major financial centers.
The Opportunity
We are seeking two Network Security Analysts to join our Firm. These positions will be based in our White Plains office (hybrid), and please note the roles have different shift times, listed below. The Network Security Analysts are responsible for implementing and supporting network security solutions for the Firm and, implementing and enforcing practical solutions to secure the Firm's internal and external network infrastructure.
Available Shift Times (EST- Hybrid)
1.) Saturday - Sunday: 7:00 a.m. - 8:00 p.m. EST & Monday 7:00 a.m. - 7:00 p.m.
2.) Monday - Friday: 2:00 p.m. - 10:00 p.m.
Note: The scheduled hours listed may be flexible and will be discussed during the interview process.
Responsibilities
Performs daily review of automated security reports and escalate as necessary.
Responds to system generated security alerts and coordinate responses.
Assists with internal audits, vulnerability scans and risk assessments.
Assists with annual penetration testing, review of findings and tracking issue resolution.
Participates in evaluating new technologies or new versions of existing products.
Works with project teams to implement secure network connectivity solutions.
Writes and maintains technical documentation including procedures and troubleshooting guides.
Demonstrates effective interpersonal, written and verbal communication skills to facilitate effective work relationships with others.
Manages Firm resources responsibly.
Complies with and understands Firm operation, policies and procedures.
Performs other related duties as assigned.
Qualifications
Knowledge of relevant firm computer software programs (e.g., Outlook, Excel, PowerPoint), with the ability to learn new software and operating systems
Proficient with Access, Project and Visio
Thorough knowledge of network management and security technologies and approaches
Thorough knowledge of security techniques, latest protocols and defenses
Proficient with Microsoft Active Directory and Operating Systems
Basic ability to program scripts and batch files
Demonstrates effective interpersonal and communication skills, both verbally and in writing
Demonstrates close attention to detail
Excellent analytical, troubleshooting, organizational, and planning skills
Ability to handle multiple projects and shifting priorities
Ability to handle sensitive matters and maintain confidentiality
Ability to organize and prioritize work
Ability to work well in a demanding and fast-paced environment
Ability to work well independently as well as effectively within a team
Ability to use discretion and exercise independent and sound judgment
Flexibility to adjust hours and work the hours necessary to meet operating and business needs
Education/Experience
Bachelor's degree or equivalent
Minimum of two years' experience in multi-national enterprise IT
Culture & Life at Skadden
What makes Skadden special is our people and the culture, community and spirit of collaboration we have created. We believe in teamwork and inspiring each other to be our best in an atmosphere that promotes professionalism and excellence in all that we do. We know that inclusion and drawing on the strength of a wide spectrum of talent only make us better and is vital to the firm's success. Our goal is for everyone at the firm to enjoy a challenging career with opportunities for development and growth and to support the well-being of our attorneys and business services professionals.
Benefits
The overall well-being of our team is important to us. We offer generous benefits to help you achieve wellness in all areas of your life.
Competitive salaries and year-end discretionary bonuses.
Comprehensive health care (medical, dental, vision), savings plan/401(k) and voluntary benefits.
Generous paid time off.
Paid leave options, including parental.
In-classroom, remote, and on-demand learning and professional development opportunities.
Robust well-being classes and programs.
Opportunities to give back and make an impact in local communities.
For further details, please visit: *******************************************************
Skadden is an Equal Opportunity Employer (Disability/Vet/other protected categories). For more information, please visit Skadden.com/careers.
The starting base salary for this position is expected to be within the range listed under Salary Details. Actual salary will be determined based on skills, experience (to the extent relevant) and other-job related factors, consistent with applicable law.
Salary Details
$125,000 -$140,000
EEO Statement
Skadden is an Equal Opportunity Employer. It does not discriminate against applicants or employees based on any legally impermissible factor including, but not limited to, race, color, religion, creed, sex, national origin, ancestry, age, alienage or citizenship status, marital or familial status, domestic partnership status, caregiver status, sexual orientation, gender, gender identity or expression, change of sex or transgender status, genetic information, medical condition, pregnancy, childbirth or related medical conditions, sexual and reproductive health decisions, disability, any protected military or veteran status, or status as a victim of domestic or dating violence, sexual assault or offense, or stalking.
Applicants who require an accommodation during the application process should contact Lara Bell at **************.
Skadden Equal Employment Opportunity Policy
Skadden Equal Employment Opportunity Policy
Applicants Have Rights Under Federal Employment Law
Applicants Have Rights Under Federal Employment Law
In accordance with the Transparency in Coverage Rule,
click here to review machine-readable files made available by UnitedHealthcare:
Transparency in Coverage
Auto-ApplyPrincipal Security Information Analyst
Information security analyst job in New York, NY
Principal Information Security Analyst (Tier 2) As a Principal Information Security Analyst within Gen Digital's global Security Operations Center (SOC), you will play a key role in strengthening threat detection and response across the organization. The role focuses on improving SOC monitoring and detection processes through technical expertise, continuous development, and close collaboration with other security teams.
In this position, you will serve as a senior specialist, leading automation and detection engineering efforts, mentoring junior analysts and contributing to projects that enhance security visibility and overall SOC performance.
Operating in a follow-the-sun model, the SOC ensures 24/7 global coverage, with regional teams working during their respective business hours and sharing on-call responsibilities for weekend.
Key Responsibilities:
* Monitor, analyze, and correlate security alerts and events across multiple platforms (SIEM, WAF, EDR, email, cloud, network, and threat intelligence tools) to identify and validate suspicious or malicious activity
* Continuously develop and fine-tune detection rules, correlation searches, security policies, and dashboards to improve visibility, reduce false positives, and increase alert accuracy across security platforms
* Support and mentor Tier 1 analysts in alert triage, escalation quality, and use of tools
* Collaborate with security engineers on automation and enrichment initiatives to streamline operational workflows and improve detection efficiency
* Maintain complete and up-to-date documentation for all detection use cases, workflows and process improvements
* Participate in security projects and collaborate with internal stakeholders (e.g., Incident Response, Security Engineering, Application Security, and IT) to enhance detection coverage, visibility, and response capabilities
* Support the execution of incident response playbooks
Qualification and Work Experience:
* 3-5 years of hands-on experience in SOC operations, cybersecurity monitoring, or related areas such as detection engineering or threat analysis
* Solid understanding of networking concepts (TCP/IP, DNS, HTTP/S) and how they apply to security monitoring and threat analysis
* Strong knowledge of cybersecurity principles, common attack techniques, and threat types (e.g., phishing, malware, brute force, web application attacks)
* Proven experience working with security logs, alerts, and structured data across multiple platforms (SIEM, EDR, WAF, cloud, and network telemetry)
* Hands-on experience with SIEM platforms - Splunk preferred - including detection content development, rule tuning, and dashboard creation
* Familiarity with Web Application Firewall (WAF) technologies and the ability to analyze or tune related alerts and policies
* Understanding of cloud security concepts and experience with monitoring tools for major providers (AWS, Azure, GCP)
* Working knowledge of scripting or automation (e.g., Python, PowerShell, or API-based integrations) to support analysis and enrichment workflows
* Experience using AI-based tools to support daily SOC operations, including data analysis, investigation, documentation, and collaboration
* Strong analytical and problem-solving skills with attention to detail and curiosity for continuous learning
* Effective communication and documentation skills in English, both written and verbal
* Experience collaborating across teams (e.g., Security Engineering, Incident Response, Application Security) on detection improvements or automation projects
* Prior experience in a Security Operations Center (SOC) or similar environment is highly preferred
* Familiarity with the fintech environment or experience supporting financial services infrastructure is considered a strong advantage
#LI-AS1
Gen is proud to be an equal-opportunity employer, committed to diversity and inclusivity. We base employment decisions on merit, experience, and business needs, without considering race, color, national origin, age, religion, sex, pregnancy, genetic information, disability, medical condition, marital status, sexual orientation, gender identity or expression, military or veteran status, or other unlawful factors. Gen prohibits discrimination based on these protected characteristics and recruits talented candidates from diverse backgrounds.
We consider individuals with arrest and conviction records and do not discriminate against employees for discussing their own pay or that of other employees or applicants. Learn more about pay transparency.
To conform to U.S. export control regulations, applicant should be eligible for any required authorizations from the U.S. Government.
Auto-ApplyInformation Security Specialist
Information security analyst job in New York, NY
Information Security Specialist Job Responsibilities:
Safeguards information system assets by identifying and solving potential and actual security problems.
Information Security Specialist Job Duties:
Protects system by defining access privileges, control structures, and resources.
Recognizes problems by identifying abnormalities; reporting violations.
Implements security improvements by assessing current situation; evaluating trends; anticipating requirements.
Determines security violations and inefficiencies by conducting periodic audits.
Upgrades system by implementing and maintaining security controls.
Keeps users informed by preparing performance reports; communicating system status.
Maintains quality service by following organization standards.
Maintains technical knowledge by attending educational workshops; reviewing publications.
Contributes to team effort by accomplishing related results as needed.
Information Security Specialist Skills and Qualifications:
System Administration, Network Security, Problem Solving, Information Security Policies, Informing Others, Process Improvement, On\-Call, Network Troubleshooting, Firewall Administration, Network Protocols, Routers, Hubs, and Switches. "}}],"is Mobile":false,"iframe":"true","job Type":"Full time","apply Name":"Apply Now","zsoid":"641401441","FontFamily":"Verdana, Geneva, sans\-serif","job OtherDetails":[{"field Label":"Industry","uitype":2,"value":"Technology"},{"field Label":"City","uitype":1,"value":"Brooklyn"},{"field Label":"State\/Province","uitype":1,"value":"New York"}],"header Name":"Information Security Specialist","widget Id":"**********00072311","is JobBoard":"false","user Id":"**********00133003","attach Arr":[],"custom Template":"3","is CandidateLoginEnabled":true,"job Id":"**********00267067","FontSize":"12","location":"Brooklyn","embedsource":"CareerSite","indeed CallBackUrl":"https:\/\/recruit.zoho.com\/recruit\/JBApplyAuth.do","logo Id":"2qf78d018cc5be94b40bbbcb719566377b192"}
Manager, Information Security Compliance
Information security analyst job in New York, NY
Department Description At Disney, we're storytellers. We make the impossible, possible. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader. Walt's passion was to continuously envision new ways to move audiences around the world-a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences - and we're constantly looking for new ways to enhance these exciting experiences.
The Enterprise Technology mission is to deliver technological solutions that align to business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. Our group drives competitive advantage by enhancing our consumer experiences, enabling business growth, and advancing operational excellence.
The Global Information Security (GIS) organization strives to secure the magic by employing best-in-class services to assess, prevent, detect, and respond to cyber threats that present risk to The Walt Disney Company. We enable the business by integrating enterprise and business segment-specific supported services to create a robust, efficient, and adaptable cybersecurity program. Our key objectives are to:
* Secure the Magic by protecting information systems and platforms.
* Reduce Risk by proactively assessing, preventing, and detecting to prevent harm to the Company and our Guests.
* Strengthen the business through optimizing execution, application, and technology used to protect the Company.
* Innovate by investing in core capabilities to enhance operational efficiency.
Team Description:
Global Information Security (GIS) supports all of Disney's business segments, including Disney Entertainment & ESPN (DE&E). DE&E encompasses the operations of Disney's streaming services-Disney+, Hulu, ESPN+, Disney+ Hotstar, Star, and the upcoming Venu Sports streaming service-as well as Disney's broadcast and cable networks, including ABC, ESPN, FX, Disney Channels, and National Geographic. DE&E sits at the intersection of entertainment, sports, and technology, striving to connect viewers with beloved stories while advancing the streaming industry with consumer-first innovations. Security professionals supporting DE&E work with industry-leading technologies to deliver world-class, highly secure services to customers.
What You'll Do:
* Independent audit support for:
* SOX 404 ITGCs
* PII
* PCI
* ISPS
* Collaborate with Enterprise Controls and Compliance (ECC) to scope systems and respective ITGCs.
* Perform control health checks and remediation testing procedures to address issues identified via audit assessments, access control reviews, internal or external audits and/or other assessments.
* Develop and lead the Control Assurance Programs (ISPS and SOX).
* Lead Audit Readiness efforts to ensure proper system scoping and respective ITGCs, control validations and timely program onboarding.
* Participate in audit walkthrough meetings to help establish internal testing procedures to gain operational comfort in the design of the Company's automated controls.
* This includes control self-evaluations of new controls or processes that impact the effectiveness of an existing control.
* Perform impact analysis and risk assessment on deficiency findings and documentation associated with the assessment.
* Work with management and internal audit on maintaining the master Risk and Control Matrix over the systems material to Disney Entertainment and ESPN (Broadcast TV and Streaming - Hulu, Disney+, ESPN+, STAR+ products)
* Ensure for timely management response of audit findings into our corporate SOCD/SAD.
* Oversee ISPS Management Audit coordination and open action plans.
* Provide consultancy to Development leads to identify and implement automation and efficiency opportunities to meet governance and compliance demands.
* Management of GRC workflows around coordination of certifications and attestations.
* Partner with leadership to support the PCI-DSS compliance program.
* Develop training materials, coordinate training sessions, and monitor compliance with training requirements.
* Oversee and manage a team of compliance analysts, ensuring day-to-day operations run smoothly and efficiently.
* Assign tasks and projects to team members based on priorities, deadlines, and individual strengths.
* Provide executive level updates on Compliance programs
Must Haves (Years of Experience, languages, programs, tools, etc.):
* Minimum of 8 years of related work experience, with 3 in management roles
* IT SOX experience and proven experience in supporting IT audit/compliance functions
* Experience in managing people
* Thorough understanding of SOX ITGC and ICFR 404 standards and audit objectives
* Interpersonal skills with the ability to work with teams cross-functionally
* Strong verbal and written communication skills and ability to effectively communicate to technical and non-technical audiences, including developers and tech operators
* Detail-oriented but able to understand the big picture. Highly organized and efficient
* Ability to navigate through ambiguity, manage and coordinate multiple project assignments simultaneously in a fast-paced, deadline-driven environment, accepting ownership and accountability of the process and deliver on commitments
* Experience with cloud-based services, specifically AWS
Nice To Haves (see above):
* Experience and knowledge of NIST framework, ISO 27001, K-ISMS, GDPR
* Experience working with companies that have a heavy microservice architecture
Education:
Bachelor's degree in Computer Science, CPA license, Information Systems, Software, Electrical or Electronics Engineering, or comparable field of study, and/or equivalent work experience
The hiring range for this position in Glendale, CA and Santa Monica, CA is $141,900 to $190,300 per year and in New York, NY is $148,700 to $199,400 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate's geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.
About The Walt Disney Company (Corporate):
At Disney Corporate you can see how the businesses behind the Company's powerful brands come together to create the most innovative, far-reaching and admired entertainment company in the world. As a member of a corporate team, you'll work with world-class leaders driving the strategies that keep The Walt Disney Company at the leading edge of entertainment. See and be seen by other innovative thinkers as you enable the greatest storytellers in the world to create memories for millions of families around the globe.
About The Walt Disney Company:
The Walt Disney Company, together with its subsidiaries and affiliates, is a leading diversified international family entertainment and media enterprise that includes three core business segments: Disney Entertainment, ESPN, and Disney Experiences. From humble beginnings as a cartoon studio in the 1920s to its preeminent name in the entertainment industry today, Disney proudly continues its legacy of creating world-class stories and experiences for every member of the family. Disney's stories, characters and experiences reach consumers and guests from every corner of the globe. With operations in more than 40 countries, our employees and cast members work together to create entertainment experiences that are both universally and locally cherished.
This position is with Disney Worldwide Services, Inc., which is part of a business we call The Walt Disney Company (Corporate).
Disney Worldwide Services, Inc. is an equal opportunity employer. Applicants will receive consideration for employment without regard to race, religion, color, sex, sexual orientation, gender, gender identity, gender expression, national origin, ancestry, age, marital status, military or veteran status, medical condition, genetic information or disability, or any other basis prohibited by federal, state or local law. Disney champions a business environment where ideas and decisions from all people help us grow, innovate, create the best stories and be relevant in a constantly evolving world.
Apply Now Apply Later
Current Employees Apply via My Disney Career
Explore Location
Cloud Security Specialist Information Security Engineering
Information security analyst job in New York, NY
The Cloud Security Specialist is a senior technical and leadership position responsible for implementing, managing, and continuously improving cloud security across multi cloud environments including AWS, Azure, Google Cloud, and Oracle Cloud Infrastructure (OCI).This role combines hands on technical execution with team leadership. The successful candidate will lead a team of cloud security engineers, develop secure architectures, and manage enterprise grade cloud security solutions such as Cloud Security Posture Management (CSPM), Cloud Workload Protection (CWP), Container Security, API Security, and AI Security Posture Management (AISPM).The individual will partner with cloud service, DevOps, and application teams to design secure deployments, enforce policies, and integrate automation for vulnerability remediation, threat detection, and compliance. They will also implement secure private connectivity between cloud and on premise networks using technologies such as AWS PrivateLink and Azure ExpressRoute. Required Education/Experience
* Master's Degree and with 3 years of relevant experience IT or Information security or
* Bachelor's Degree and with 5 years of relevant experience IT or Information security or
* Associate's Degree and with 6 years of relevant experience IT or Information security or
* High School Diploma/GED and with 8 years of relevant experience IT or Information security.
Preferred Education/Experience
* Master's Degree in Cybersecurity, Computer Engineering, Computer Science, Information Systems Security, Information Technology. and 3 years in Information security, Cloud Security or Cloud Architect in a senior technical role. With certifications such as CCSP, AWS Certified Security, Azure Security Engineer Associate, or GCP Cloud Security Engineer. Experience in cloud security or cloud architecture. Experience with CSPM, CWP, AISPM, and API security implementations. Handson work with identity management, hybrid connectivity (PrivateLink, ExpressRoute).
* Bachelor's Degree in Cybersecurity, Computer Engineering, Computer Science, Information Systems Security, Information Technology. and 5 years in Information security, Cloud Security or Cloud Architect in a senior technical role. With certifications such as CCSP, AWS Certified Security, Azure Security Engineer Associate, or GCP Cloud Security Engineer. Experience in cloud security or cloud architecture. Experience with CSPM, CWP, AISPM, and API security implementations. Handson work with identity management, hybrid connectivity (PrivateLink, ExpressRoute).
Relevant Work Experience
* Handson experience with at least two major cloud providers (AWS, Azure, GCP, or OCI), required.
* Implementation and management experience with CSPM, CWP, AISPM, and API security platforms, required.
* Knowledge of IAM, rolebased access control, and policy enforcement, required.
* Experience integrating cloud telemetry and logs with SIEM tools, required.
* Understanding of hybrid connectivity and private link technologies (PrivateLink, ExpressRoute), required.
* Experience with scripting (Python, PowerShell, Bash) and automation, required.
* Experience with WAF and cloud API gateway configurations, required.
* Strong understanding of cloud network fundamentals and background in cloud network security, and secure architecture design, required.
* Experience collaborating with cloud service teams for planning and remediation, required.
* Experience implementing application security best practices and training engineering teams, required.
* Familiarity with CDN operations, certificates, and brand monitoring preferred, required.
* Experience with SIEM integration, telemetry collection, and event analysis, preferred.
* Demonstrated experience leading technical teams or project groups, preferred.
* Experience with Container Security, preferred.
* Experience securing API endpoints and implementing advanced cloud application protections, preferred.
* Knowledge of AI/ML data protection and secure model deployment practices, preferred.
* Experience integrating security automation into DevSecOps workflows using Terraform or Ansible, preferred.
* Experience developing and delivering cloud security training and awareness programs, preferred.
Skills and Abilities
* Effective leadership skills
* Demonstrated problem solving skills
* Demonstrated problem solving skills
* Strong written and verbal communication skills
* Ability to drive multiple projects to successful completion
* Proactively approaches responsibilities
Licenses and Certifications
* Driver's License Required
* Other: CISSP, CCNP Security, GSEC, GCIH, CEH, or equivalent certifications. Preferred
* Other: CCSP, AWS Certified Security, Azure Security Engineer Associate, GCP Professional Cloud Security Engineer, or OCI Security Professional. Preferred
Physical Demands
* Ability to push, pull, and lift up to 25 pounds
* Sit or stand to use a keyboard, mouse, and computer for the duration of the workday
Additional Physical Demands
* The selected candidate will be assigned a System Emergency Assignment (i.e., an emergency response role) and will be expected to work non-business hours during emergencies, which may include nights, weekends, and holidays.
* The selected candidate will be assigned a System Emergency Assignment (i.e., an emergency response role) and will be expected to work non-business hours during emergencies, which may include nights, weekends, and holidays.
Core Responsibilities
* Lead and mentor a team of cloud security engineers, fostering technical excellence and professional growth.
* Architect and maintain secure multi-cloud environments across AWS, Azure, GCP, and OCI in partnership with Enterprise Architecture.
* Deploy and manage CSPM platforms to drive continuous visibility, compliance, and risk posture improvement.
* Implement CWP solutions to protect cloud workloads, prevent threats, and manage vulnerabilities effectively.
* Define and enforce IAM policies and least-privilege principles to strengthen identity security across all platforms.
* Design and secure private and hybrid connectivity using technologies such as AWS PrivateLink, Azure ExpressRoute, and Google Cloud Interconnect.
* Integrate cloud telemetry and security events with SIEM systems to enhance incident detection and response capabilities.
* Automate provisioning, configuration, and remediation workflows using IaC tools like Terraform and Ansible, supported by Python or PowerShell scripting.
* Implement and manage WAF policies and API gateways to safeguard cloud applications and services.
* Partner with DevOps and engineering teams to embed security within CI/CD pipelines and promote secure development practices.
* Collaborate with risk and architecture teams to assess emerging technologies and align them with enterprise security strategy.
* Stay informed on evolving threats, regulatory frameworks, and AI security trends to continuously improve cloud security posture.
Cyber Security Analyst
Information security analyst job in Great Neck, NY
Founded over 35 years ago, First Quality is a family-owned company that has grown from a small business in McElhattan, Pennsylvania into a group of companies, employing over 5,000 team members, while maintaining our family values and entrepreneurial spirit. With corporate offices in New York and Pennsylvania and 8 manufacturing campuses across the U.S. and Canada, the companies within the First Quality group produce high-quality personal care and household products for large retailers and healthcare organizations. Our personal care and household product portfolio includes baby diapers, wipes, feminine pads, paper towels, bath tissue, adult incontinence products, laundry detergents, fabric finishers, and dishwash solutions. In addition, we manufacture certain raw materials and components used in the manufacturing of these products, including flexible print and packaging solutions.
Guided by our values of humility, unity, and integrity, we leverage advanced technology and innovation to drive growth and create new opportunities. At First Quality, you'll find a collaborative environment focused on continuous learning, professional development, and our mission to Make Things Better .
We are actively seeking an experienced Cyber Security Analyst to join our Security Operations Center in Great Neck, New York, or work in a hybrid capacity from CT, GA, NY, NJ, PA, or SC. In this role, you will be responsible for incident detection, investigation and response, rules development tuning and improvement, defining and developing automations, and incorporating Threat Intelligence and Threat Hunting activities to enhance detection and mitigation strategies.
Primary responsibilities include:
Incident Detection and Response - Monitor and analyze alerts generated by SIEM/SOAR platforms and user reports, investigate security incidents, and execute containment and eradication procedures to minimize impact and restore normal operations.
Tuning & Optimization - Continuously refine detection rules and SOC processes to reduce false positives, enhance detection accuracy, and improve overall operational efficiency.
Research & Development - Explore emerging threats and attack techniques to develop and implement new detection rules to expand visibility and strengthen the organization's security posture.
Threat Hunting - Proactively hunt for hidden threats by analyzing logs and identifying gaps missed by existing security tools and improve security posture.
Threat Intelligence - Review threat intelligence feeds, channels and articles to identify potential risks and proactively strengthen defenses.
Automation Development - Design, implement, and maintain automation solutions to streamline SOC workflows, reduce manual effort, and accelerate incident response times.
Reporting - Prepare and present comprehensive reports on key SOC activities, metrics, and security trends to stakeholders and management.
Penetration Testing - Participate in Red and Purple Team exercises to assess and improve the effectiveness of security controls and incident response capabilities.
The ideal candidate should possess the following:
Bachelor's degree in Computer Security, Cybersecurity, Information Security, or a related field preferred. Additional relevant experience may be considered in lieu of a degree.
Experience with advanced SIEM content development, including custom correlation rules, dashboards, and reporting.
Minimum of 1 year of experience working in a Security Operations Center (SOC) environment, either in-house or with a Managed Security Service Provider (MSSP).
Proficiency in scripting languages such as Python, PowerShell, or Bash for automating security tasks and processes.
Direct involvement in end-to-end incident response, including root cause determination and post-incident reporting.
Experience monitoring and securing cloud environments (e.g., Microsoft Azure, AWS, Google Cloud Platform).
Hands-on experience working with SIEM (e.g. Splunk, Microsoft Sentinel, Qradar)
Familiarity with EDR solutions like CrowdStrike, SentinelOne, Microsoft Defender for Endpoint or Cortex XDR.
Understanding and familiarity with interpreting common log sources for monitoring and investigation (e.g. Firewall, Azure AD, Windows Security Log, Email, Proxy\URL Filtering etc.)
Solid grasp of prevalent attack types, including phishing, brute-force attacks, malware, and data exfiltration techniques.
Excellent verbal and written communication skills, with the ability to collaborate effectively with team members both within and outside the SOC.
High level of situational awareness and problem sensitivity, with the ability to proactively identify issues and escalate concerns as appropriate.
Demonstrated proactive mindset, strong sense of responsibility, and urgency in addressing security incidents and tasks.
Ability to work independently, manage multiple priorities, and succeed in a fast-paced, dynamic environment.
Strong motivation and willingness to continually learn and grow, adapting to new tools and evolving threat landscapes.
What We Offer You
We believe that by continuously improving the quality of our benefits, we can help to raise the quality of life for our team members and their families. At First Quality you will receive:
• Competitive base salary and bonus opportunities
• Paid time off (three-week minimum)
• Medical, dental and vision starting day one
• 401(k) with employer match
• Paid parental leave
• Child and family care assistance (dependent care FSA with employer match up to $2500)
• Bundle of joy benefit (year's worth of free diapers to all team members with a new baby)
• Tuition assistance
• Wellness program with savings of up to $4,000 per year on insurance premiums
• ...and more!
The estimated annual base salary range for this position is $110,000 - $140,000.
Base pay is only part of our total compensation package, which also includes an attractive annual discretionary bonus and robust suite of employee benefits for which you are eligible to participate in starting on your first day of employment.
Base pay offered will be determined on an individualized basis and we will consider your location, experience, and other job-related factors.
First Quality is committed to protecting information under the care of First Quality Enterprises commensurate with leading industry standards and applicable regulations. As such, First Quality provides at least annual training regarding data privacy and security to employees who, as a result of their role specifications, may come in to contact with sensitive data.
First Quality is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, sexual orientation, gender identification, or protected Veteran status.
Auto-Apply