14 vulnerability analyst jobs at 13 companies in New York
1mo
Save
Mark Applied
Hide
1mo
Cybersecurity Threat & Vulnerability Analyst
Newark or New Jersey or New York or Pennsylvania or Connecticut or Delaware
$98k-$133k/yrRemoteFull Time
Horizon Blue Cross Blue Shield of New Jersey: Provides health insurance and managed care products in New Jersey.
5+ YOE5+ years information security experience with 3+ years focused on vulnerability identification, assessment, and remediation; HS diploma required; bachelors preferred; required/ preferred security certifications (CISSP, GCTI, GIAC, CompTIA Security+, CEH); strong knowledge of vulnerability management, CVSS, OS platforms, and threat intelligence.
Nessus, Qualys, InsightVM (Nexpose), Recorded Future, ThreatConnect/ThreatStream, H-ISAC, NJCCIC, Microsoft PowerPoint, Visio, Microsoft Excel
CapgeminiEuronext Paris: CAP: Provides global IT consulting and digital transformation services.
8+ YOERequires 8+ years in vulnerability management, cybersecurity, or product analysis; expertise in vulnerability lifecycles, risk prioritization, requirements gathering, stakeholder management, and enterprise security platforms.
Spectrum Health & Human Services: Provides behavioral health, addiction recovery, and community support services.
3+ YOE3-5+ years in cybersecurity or security operations, bachelor's degree or equivalent, hands-on SIEM/EDR experience, incident response, vulnerability management, and knowledge of HIPAA/HITRUST/NIST.
SIEM, Splunk, Microsoft Sentinel, QRadar, EDR/XDR, CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, Carbon Black, ServiceNow, Jira, IDS/IPS, SOAR, Active Directory, Windows, Linux, Azure, AWS, Google Cloud, Microsoft 365, TCP/IP
Ross StoresNASDAQ: ROST: Operates an off-price retail chain selling clothing and home goods.
3+ YOEUndergraduate degree or equivalent experience; 3–5 years in vulnerability remediation or security operations; strong Linux, Java remediation, reporting, communication, threat analysis, and enterprise process optimization skills.
FlexTrade Systems: Provider of multi-asset execution and order management trading software.
5+ YOE5+ years in SOC, security operations, or incident response; proficiency with SIEM and EDR platforms; vulnerability management, threat hunting, scripting, and incident response experience. CISSP required or strongly preferred.
Splunk, Microsoft Sentinel, Sumo Logic, CrowdStrike Falcon, Microsoft Defender, Entra, Purview, Tenable, Qualys, Rapid7, MITRE ATT&CK, Python, PowerShell, Bash, AWS, Azure, GCP, MISP, Recorded Future, OpenCTI, KAPE, Volatility, Velociraptor
Arizona or Delaware or Florida or Georgia or Maryland or Michigan or North Carolina or Nebraska or New Jersey or New York or Pennsylvania or South Carolina or Tennessee or Texas or Wisconsin
$77k-$82k/yrRemoteFull Time
Energage: Provides an employee engagement platform and workplace culture analytics
3+ YOEBachelor's degree or equivalent experience; 3+ years in information security or cybersecurity; experience with compliance frameworks, risk assessments, vulnerability management, cloud security, SIEM, identity management, and privacy compliance.
Secure Software Development Lifecycle (SSDLC), SIEM, Data Loss Prevention (DLP), AWS, Azure, Google Cloud, Identity and Access Management (IAM)
Willkie Farr & Gallagher: International law firm providing comprehensive legal services.
2+ YOERequires 2–5 years of information security experience, bachelor's degree, current industry certifications, vulnerability and threat management expertise, security tools experience, and strong analytical and communication skills.
Snorkel AI: Software platform for programmatic AI data development and labeling.
2+ YOERequires 2–5 years in technical compliance, IT audit, or GRC; SOC 2 Type I/II and ITGC audit expertise; cloud, IAM, CI/CD, encryption, vulnerability management, and Vanta, Drata, Jira, and KnowBe4 experience.
Krakow or Hyderabad or New York City or Chicago or London or Singapore or Hong Kong or Tokyo or United States or Europe or Asia
HybridFull Time
Pico: Provides managed infrastructure and data services to financial markets.
5+ YOE5+ years IT experience in information security; experience with firewall/IDS, SIEM, Linux, cloud (AWS/GCP), Fortinet and Firepower; risk and vulnerability assessment experience; bachelor's degree or equivalent; CCNA/CISSP/cloud security certs desirable.
Estée Lauder CompaniesNYSE: EL: Manufacturer and marketer of prestige beauty and skincare products.
Experience in application security, secure SDLC, vulnerability assessment (SAST/DAST/IAST), threat modeling, CI/CD and cloud/container security, strong programming/scripting skills, and ability to consult across technical teams.
3+ YOERequires 3+ years managing vulnerability tools and conducting risk assessments, with expertise in network devices, Microsoft Windows environments, NIST frameworks, and strong analytical and communication skills.
Firewalls, IPS, IDS, NDR, NAC, Microsoft Windows, DHCP, DNS, Active Directory, NIST Cybersecurity Framework, SP 800-53, Cyber Risk Institute Profile v2.x, Qualys, Tenable, CISA Known Exploited Vulnerabilities (KEV) catalog
NBCUniversalNASDAQ: CMCSA: Produces and distributes entertainment content and theme park experiences.
10+ YOERequires 10+ years in cybersecurity with strong cyber threat intelligence experience, advanced analysis of malware, network traffic, and vulnerabilities, threat intelligence platform and SIEM experience, and strategic communication and mentoring skills.
Threat Intelligence Platforms (TIPs), Security Information and Event Management (SIEM), Python, MITRE ATT&CK, Kill Chain
The Estée Lauder CompaniesNYSE: EL: Manufactures and markets prestige skincare, makeup, and fragrance products.
Experienced application security professional versed in SDLC/DevSecOps, vulnerability assessment (SAST/DAST/IAST), threat modeling, CI/CD and cloud/container security; strong programming/scripting skills and ability to mentor teams.
Government Information Specialist (Privacy Analyst)
Charlotte Amalie or Christiansted or Guaynabo or Mayaguez or Texas or Utah or Vermont or Virginia or Washington or West Virginia or Wisconsin or Wyoming or Alabama or Alaska or Arizona or Arkansas or California or Colorado or Connecticut or Delaware or District of Columbia or Florida or Georgia or Hawaii or Idaho or Illinois or Indiana or Iowa or Kansas or Kentucky or Louisiana or Maine or Maryland or Massachusetts or Michigan or Minnesota or Mississippi or Missouri or Montana or Nebraska or Nevada or New Hampshire or New Jersey or New Mexico or New York or North Carolina or North Dakota or Ohio or Oklahoma or Oregon or Pennsylvania or Rhode Island or South Carolina or South Dakota or Tennessee
$90k-$145k/yrHybridFull Time
IRS Office of Chief Counsel: Represents the IRS in tax litigation and legal matters.
1+ YOERequires one year of GS-11-equivalent specialized experience applying privacy and disclosure guidance, conducting risk assessments, analyzing program vulnerabilities, and preparing communications and reports.
Privacy, Civil Liberties Impact Assessments (PCLIAs), Safeguarding Personally Identifiable Information Data Extracts (SPIIDE), Microsoft Word, Microsoft Excel