13 vulnerability analyst jobs at 12 companies in New York City, NY
1mo
Save
Mark Applied
Hide
1mo
Cybersecurity Threat & Vulnerability Analyst
Newark or New Jersey or New York or Pennsylvania or Connecticut or Delaware
$98k-$133k/yrRemoteFull Time
Horizon Blue Cross Blue Shield of New Jersey: Provides health insurance and managed care products in New Jersey.
5+ YOE5+ years information security experience with 3+ years focused on vulnerability identification, assessment, and remediation; HS diploma required; bachelors preferred; required/ preferred security certifications (CISSP, GCTI, GIAC, CompTIA Security+, CEH); strong knowledge of vulnerability management, CVSS, OS platforms, and threat intelligence.
Nessus, Qualys, InsightVM (Nexpose), Recorded Future, ThreatConnect/ThreatStream, H-ISAC, NJCCIC, Microsoft PowerPoint, Visio, Microsoft Excel
CapgeminiEuronext Paris: CAP: Provides global IT consulting and digital transformation services.
8+ YOERequires 8+ years in vulnerability management, cybersecurity, or product analysis; expertise in vulnerability lifecycles, risk prioritization, requirements gathering, stakeholder management, and enterprise security platforms.
EY: Global firm providing audit, tax, and professional consulting services.
8+ YOEMinimum 8 years in vulnerability/exposure/offensive security/security engineering; deep understanding of attack paths and misconfigurations; ability to build scalable vulnerability detection and validation solutions and communicate with senior stakeholders.
Ross StoresNASDAQ: ROST: Operates an off-price retail chain selling clothing and home goods.
3+ YOEUndergraduate degree or equivalent experience; 3–5 years in vulnerability remediation or security operations; strong Linux, Java remediation, reporting, communication, threat analysis, and enterprise process optimization skills.
City of New York: Provides municipal services and administration for New York City.
4+ YOEBachelor's degree plus related experience, 4+ years IT/infrastructure or datacenter/cloud engineering experience, expertise in incident response, forensics, vulnerability management, IAM, audits, and security operations.
Qualys, Wiz, Rapid7, Veracode, HCL AppScan, Snyk, CrowdStrike, Microsoft Defender, SolarWinds SEM, ServiceNow, Jira, GitHub Enterprise Copilot Security, GitHub Copilot, BitSight, Security Scorecard, Shodan, Air Table, Miro, Canva, SurveyMonkey, SIEM
Paterson Public Schools: Provides public K-12 education services to the Paterson community.
Bachelor of Science in Engineering or Computer Science (or equivalent experience). Experience with security assessment tools, vulnerability scanning, penetration testing, network and server management, and security platforms. Strong communication and problem-solving skills.
NMAP, Procmon, Azure, GCP, AWS, VMWare, Palo Alto, Cisco, Avaya, Extreme, HP, MS Exchange, Office 365, Microsoft Windows, Microsoft Server, Mac OS, Linux, IOS, Android, ChromeOS
Krakow or Hyderabad or New York City or Chicago or London or Singapore or Hong Kong or Tokyo or United States or Europe or Asia
HybridFull Time
Pico: Provides managed infrastructure and data services to financial markets.
5+ YOE5+ years IT experience in information security; experience with firewall/IDS, SIEM, Linux, cloud (AWS/GCP), Fortinet and Firepower; risk and vulnerability assessment experience; bachelor's degree or equivalent; CCNA/CISSP/cloud security certs desirable.
Estée Lauder CompaniesNYSE: EL: Manufacturer and marketer of prestige beauty and skincare products.
Experience in application security, secure SDLC, vulnerability assessment (SAST/DAST/IAST), threat modeling, CI/CD and cloud/container security, strong programming/scripting skills, and ability to consult across technical teams.
Tampa or Irving or Jacksonville or Jersey City or New York City
$87k-$212k/yrHybridFull Time
CitiNYSE: C: Global diversified financial services holding.
5+ YOERequires penetration testing or vulnerability assessment experience, AI and LLM literacy, security testing tools, OWASP knowledge, clear technical writing, and a bachelor's degree or equivalent practical experience.
Burp Suite, nuclei, nmap, OWASP Top 10, OWASP LLM Top 10, MITRE ATLAS, Garak, PyRIT, PromptBench, Inspect AI, Large Language Models (LLMs), MITRE ATT&CK Framework
The Estée Lauder CompaniesNYSE: EL: Manufactures and markets prestige skincare, makeup, and fragrance products.
Experienced application security professional versed in SDLC/DevSecOps, vulnerability assessment (SAST/DAST/IAST), threat modeling, CI/CD and cloud/container security; strong programming/scripting skills and ability to mentor teams.
Kura Sushi USANASDAQ: KRUS: Operates a chain of technology-driven revolving sushi restaurants.
5+ YOEBachelor's degree in cybersecurity, computer science, IT, or related field; 5+ years of cybersecurity experience; security certifications, incident response, cloud security, compliance, SIEM, vulnerability testing, and scripting skills.
Security Information and Event Management (SIEM), Splunk, Google Security Operations, QRadar, ArcSight, Optro, AuditBoard, Cross Comply, Amazon Web Services (AWS), Azure, Google Cloud Platform (GCP), Netskope, CheckPoint, Zscaler, BigID, Microsoft Purview, Python, PowerShell, Bash, NIST, ISO 27001, CIS, CCPA, PCI DSS, SOX, GDPR, Artificial Intelligence (AI), Identity & Access Management (IAM), Systems Development Life Cycle (SDLC), System and Organizational Controls (SOC), Intrusion Prevention System (IPS), Intrusion Detection System (IDS)