14 vulnerability analyst jobs at 13 companies in New York

1mo
Save
Mark Applied
Hide
Cybersecurity Threat & Vulnerability Analyst
Newark or New Jersey or New York or Pennsylvania or Connecticut or Delaware
$98k-$133k/yr RemoteFull Time
Horizon Blue Cross Blue Shield of New Jersey
Horizon Blue Cross Blue Shield of New Jersey: Provides health insurance and managed care products in New Jersey.
5+ YOE5+ years information security experience with 3+ years focused on vulnerability identification, assessment, and remediation; HS diploma required; bachelors preferred; required/ preferred security certifications (CISSP, GCTI, GIAC, CompTIA Security+, CEH); strong knowledge of vulnerability management, CVSS, OS platforms, and threat intelligence.
Nessus, Qualys, InsightVM (Nexpose), Recorded Future, ThreatConnect/ThreatStream, H-ISAC, NJCCIC, Microsoft PowerPoint, Visio, Microsoft Excel
1w
Save
Mark Applied
Hide
Vulnerability Management SME / Product Analyst
New York City or New Jersey
$81k-$92k/yr HybridFull Time
Capgemini
CapgeminiEuronext Paris: CAP: Provides global IT consulting and digital transformation services.
8+ YOERequires 8+ years in vulnerability management, cybersecurity, or product analysis; expertise in vulnerability lifecycles, risk prioritization, requirements gathering, stakeholder management, and enterprise security platforms.
ServiceNow Vulnerability Response, Qualys, Tenable, Rapid7, CVE, CVSS, CWE, CPE, KEV, EPSS
2mo
Save
Mark Applied
Hide
Security Analyst
Orchard Park, New York, United States
$68k-$85k/yr OnsiteFull Time
Spectrum Health & Human Services
Spectrum Health & Human Services: Provides behavioral health, addiction recovery, and community support services.
3+ YOE3-5+ years in cybersecurity or security operations, bachelor's degree or equivalent, hands-on SIEM/EDR experience, incident response, vulnerability management, and knowledge of HIPAA/HITRUST/NIST.
SIEM, Splunk, Microsoft Sentinel, QRadar, EDR/XDR, CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, Carbon Black, ServiceNow, Jira, IDS/IPS, SOAR, Active Directory, Windows, Linux, Azure, AWS, Google Cloud, Microsoft 365, TCP/IP
1mo
Save
Mark Applied
Hide
Business Analyst
Dublin or New York City or Los Angeles or Boston
$85k-$136k/yr HybridFull Time
Ross Stores
Ross StoresNASDAQ: ROST: Operates an off-price retail chain selling clothing and home goods.
3+ YOEUndergraduate degree or equivalent experience; 3–5 years in vulnerability remediation or security operations; strong Linux, Java remediation, reporting, communication, threat analysis, and enterprise process optimization skills.
Linux, Java
1mo
Save
Mark Applied
Hide
Senior SOC Analyst
Great Neck, New York, United States
HybridFull Time
FlexTrade Systems
FlexTrade Systems: Provider of multi-asset execution and order management trading software.
5+ YOE5+ years in SOC, security operations, or incident response; proficiency with SIEM and EDR platforms; vulnerability management, threat hunting, scripting, and incident response experience. CISSP required or strongly preferred.
Splunk, Microsoft Sentinel, Sumo Logic, CrowdStrike Falcon, Microsoft Defender, Entra, Purview, Tenable, Qualys, Rapid7, MITRE ATT&CK, Python, PowerShell, Bash, AWS, Azure, GCP, MISP, Recorded Future, OpenCTI, KAPE, Volatility, Velociraptor
1w
Save
Mark Applied
Hide
Senior Security Analyst
Arizona or Delaware or Florida or Georgia or Maryland or Michigan or North Carolina or Nebraska or New Jersey or New York or Pennsylvania or South Carolina or Tennessee or Texas or Wisconsin
$77k-$82k/yr RemoteFull Time
Energage
Energage: Provides an employee engagement platform and workplace culture analytics
3+ YOEBachelor's degree or equivalent experience; 3+ years in information security or cybersecurity; experience with compliance frameworks, risk assessments, vulnerability management, cloud security, SIEM, identity management, and privacy compliance.
Secure Software Development Lifecycle (SSDLC), SIEM, Data Loss Prevention (DLP), AWS, Azure, Google Cloud, Identity and Access Management (IAM)
3d
Save
Mark Applied
Hide
Information Security Analyst
New York City, New York, United States
$75k-$80k/yr RemoteFull Time
Willkie Farr & Gallagher
Willkie Farr & Gallagher: International law firm providing comprehensive legal services.
2+ YOERequires 2–5 years of information security experience, bachelor's degree, current industry certifications, vulnerability and threat management expertise, security tools experience, and strong analytical and communication skills.
Qualys, Tenable, Rapid7, SIEM, IDS/IPS, DLP, Python, PowerShell, NOC, AV, FW
2d
Save
Mark Applied
Hide
Technical Compliance Analyst
New York City or San Francisco
$120k-$185k/yr HybridFull Time
Snorkel AI
Snorkel AI: Software platform for programmatic AI data development and labeling.
2+ YOERequires 2–5 years in technical compliance, IT audit, or GRC; SOC 2 Type I/II and ITGC audit expertise; cloud, IAM, CI/CD, encryption, vulnerability management, and Vanta, Drata, Jira, and KnowBe4 experience.
Vanta, Drata, Jira, KnowBe4, AWS, GCP, Azure, IAM, CI/CD, Terraform, AWS Config, AWS KMS, NIST SP 800-53, NIST SP 800-171 Rev 3, FedRAMP, CMMC 2.0
2mo
Save
Mark Applied
Hide
Information Security Analyst
Krakow or Hyderabad or New York City or Chicago or London or Singapore or Hong Kong or Tokyo or United States or Europe or Asia
HybridFull Time
Pico
Pico: Provides managed infrastructure and data services to financial markets.
5+ YOE5+ years IT experience in information security; experience with firewall/IDS, SIEM, Linux, cloud (AWS/GCP), Fortinet and Firepower; risk and vulnerability assessment experience; bachelor's degree or equivalent; CCNA/CISSP/cloud security certs desirable.
IDS, Firepower IDS, Fortinet, SIEM, TCP/IP, Linux, Identity and Access Management (IAM), AWS, GCP, SANS, GIAC, COBIT, NIST
3w
Save
Mark Applied
Hide
Senior Analyst, Tech GRC M&A (25878)
Long Island City, New York, United States
$90k-$135k/yr OnsiteFull Time
Estée Lauder Companies
Estée Lauder CompaniesNYSE: EL: Manufacturer and marketer of prestige beauty and skincare products.
Experience in application security, secure SDLC, vulnerability assessment (SAST/DAST/IAST), threat modeling, CI/CD and cloud/container security, strong programming/scripting skills, and ability to consult across technical teams.
C#, C/C++, Java, JavaScript, PowerShell, Python, REST, SOAP, SOA, Bitbucket, Jenkins, JIRA, Artifactory, Nexus, git, Application Engine, SQL, Ansible, DeMisto, Docker, Kubernetes, SAST, DAST, IAST
2d
Save
Mark Applied
Hide
Information Security Risk Analyst
New York City, New York, United States
$90k-$125k/yr HybridFull Time
Sumitomo Mitsui Trust Bank
Sumitomo Mitsui Trust BankTokyo Stock Exchange: 8309: Providing trust banking and specialized asset management services worldwide.
3+ YOERequires 3+ years managing vulnerability tools and conducting risk assessments, with expertise in network devices, Microsoft Windows environments, NIST frameworks, and strong analytical and communication skills.
Firewalls, IPS, IDS, NDR, NAC, Microsoft Windows, DHCP, DNS, Active Directory, NIST Cybersecurity Framework, SP 800-53, Cyber Risk Institute Profile v2.x, Qualys, Tenable, CISA Known Exploited Vulnerabilities (KEV) catalog
4d
Save
Mark Applied
Hide
Sr Staff Threat Intelligence Analyst
New York City, New York, United States
$140k-$180k/yr RemoteFull Time
NBCUniversal
NBCUniversalNASDAQ: CMCSA: Produces and distributes entertainment content and theme park experiences.
10+ YOERequires 10+ years in cybersecurity with strong cyber threat intelligence experience, advanced analysis of malware, network traffic, and vulnerabilities, threat intelligence platform and SIEM experience, and strategic communication and mentoring skills.
Threat Intelligence Platforms (TIPs), Security Information and Event Management (SIEM), Python, MITRE ATT&CK, Kill Chain
3w
Save
Mark Applied
Hide
Senior Analyst, Tech GRC M&A
Long Island City, New York, United States
$90k-$135k/yr OnsiteFull Time
The Estée Lauder Companies
The Estée Lauder CompaniesNYSE: EL: Manufactures and markets prestige skincare, makeup, and fragrance products.
Experienced application security professional versed in SDLC/DevSecOps, vulnerability assessment (SAST/DAST/IAST), threat modeling, CI/CD and cloud/container security; strong programming/scripting skills and ability to mentor teams.
C#, C/C++, Java, JavaScript, PowerShell, Python, REST, SOAP, SAST, DAST, IAST, Bitbucket, Jenkins, JIRA, Artifactory, Nexus, git, Ansible, DeMisto, Docker, Kubernetes
3d
Save
Mark Applied
Hide
Government Information Specialist (Privacy Analyst)
Charlotte Amalie or Christiansted or Guaynabo or Mayaguez or Texas or Utah or Vermont or Virginia or Washington or West Virginia or Wisconsin or Wyoming or Alabama or Alaska or Arizona or Arkansas or California or Colorado or Connecticut or Delaware or District of Columbia or Florida or Georgia or Hawaii or Idaho or Illinois or Indiana or Iowa or Kansas or Kentucky or Louisiana or Maine or Maryland or Massachusetts or Michigan or Minnesota or Mississippi or Missouri or Montana or Nebraska or Nevada or New Hampshire or New Jersey or New Mexico or New York or North Carolina or North Dakota or Ohio or Oklahoma or Oregon or Pennsylvania or Rhode Island or South Carolina or South Dakota or Tennessee
$90k-$145k/yr HybridFull Time
IRS Office of Chief Counsel
IRS Office of Chief Counsel: Represents the IRS in tax litigation and legal matters.
1+ YOERequires one year of GS-11-equivalent specialized experience applying privacy and disclosure guidance, conducting risk assessments, analyzing program vulnerabilities, and preparing communications and reports.
Privacy, Civil Liberties Impact Assessments (PCLIAs), Safeguarding Personally Identifiable Information Data Extracts (SPIIDE), Microsoft Word, Microsoft Excel