9 vulnerability management analyst jobs at 9 companies in New York

2w
Save
Mark Applied
Hide
Vulnerability Management SME / Product Analyst
New York City or New Jersey
$81k-$92k/yr HybridFull Time
Capgemini
CapgeminiEuronext Paris: CAP: Global leader in consulting, digital transformation, and engineering services.
8+ YOERequires 8+ years in vulnerability management, cybersecurity, or product analysis; expertise in vulnerability lifecycles, risk prioritization, requirements gathering, stakeholder management, and enterprise security platforms.
ServiceNow Vulnerability Response, Qualys, Tenable, Rapid7, CVE, CVSS, CWE, CPE, KEV, EPSS
1mo
Save
Mark Applied
Hide
Cybersecurity Threat & Vulnerability Analyst
Newark or New Jersey or New York or Pennsylvania or Connecticut or Delaware
$98k-$133k/yr RemoteFull Time
Horizon Blue Cross Blue Shield of New Jersey
Horizon Blue Cross Blue Shield of New Jersey: Not-for-profit New Jersey health insurer providing medical, dental, vision, and prescription coverage to individuals, employers, and public programs.
5+ YOE5+ years information security experience with 3+ years focused on vulnerability identification, assessment, and remediation; HS diploma required; bachelors preferred; required/ preferred security certifications (CISSP, GCTI, GIAC, CompTIA Security+, CEH); strong knowledge of vulnerability management, CVSS, OS platforms, and threat intelligence.
Nessus, Qualys, InsightVM (Nexpose), Recorded Future, ThreatConnect/ThreatStream, H-ISAC, NJCCIC, Microsoft PowerPoint, Visio, Microsoft Excel
2mo
Save
Mark Applied
Hide
Security Analyst
Orchard Park, New York, United States
$68k-$85k/yr OnsiteFull Time
Spectrum Health & Human Services
Spectrum Health & Human Services: Nonprofit behavioral-health organization providing mental-health, addiction, crisis, housing, and community services in Western New York.
3+ YOE3-5+ years in cybersecurity or security operations, bachelor's degree or equivalent, hands-on SIEM/EDR experience, incident response, vulnerability management, and knowledge of HIPAA/HITRUST/NIST.
SIEM, Splunk, Microsoft Sentinel, QRadar, EDR/XDR, CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, Carbon Black, ServiceNow, Jira, IDS/IPS, SOAR, Active Directory, Windows, Linux, Azure, AWS, Google Cloud, Microsoft 365, TCP/IP
2mo
Save
Mark Applied
Hide
Senior SOC Analyst
Great Neck, New York, United States
HybridFull Time
FlexTrade Systems
FlexTrade Systems: Private financial technology providing customizable multi-asset execution and order management systems to buy- and sell-side institutions.
5+ YOE5+ years in SOC, security operations, or incident response; proficiency with SIEM and EDR platforms; vulnerability management, threat hunting, scripting, and incident response experience. CISSP required or strongly preferred.
Splunk, Microsoft Sentinel, Sumo Logic, CrowdStrike Falcon, Microsoft Defender, Entra, Purview, Tenable, Qualys, Rapid7, MITRE ATT&CK, Python, PowerShell, Bash, AWS, Azure, GCP, MISP, Recorded Future, OpenCTI, KAPE, Volatility, Velociraptor
1d
Save
Mark Applied
Hide
Senior Security Analyst, IT
New York, New York, United States
HybridFull Time
IFM Investors
IFM Investors: Pension-fund-owned global asset manager serving institutional investors across infrastructure, debt and private equity.
10+ YOE10+ years of IT operational support experience, tertiary IT qualification, and strong technical information security expertise across Microsoft, Azure, cloud, networking, security operations, risk frameworks, and vulnerability management.
Microsoft, Microsoft Azure, NIST, Essential Eight
1w
Save
Mark Applied
Hide
Technical Compliance Analyst
New York City or San Francisco
$120k-$185k/yr HybridFull Time
Snorkel AI
Snorkel AI: The frontier AI data lab helping teams build the data and environments behind high-performing frontier and agentic AI.
2+ YOERequires 2–5 years in technical compliance, IT audit, or GRC; SOC 2 Type I/II and ITGC audit expertise; cloud, IAM, CI/CD, encryption, vulnerability management, and Vanta, Drata, Jira, and KnowBe4 experience.
Vanta, Drata, Jira, KnowBe4, AWS, GCP, Azure, IAM, CI/CD, Terraform, AWS Config, AWS KMS, NIST SP 800-53, NIST SP 800-171 Rev 3, FedRAMP, CMMC 2.0
1w
Save
Mark Applied
Hide
Information Security Risk Analyst
New York City, New York, United States
$90k-$125k/yr HybridFull Time
Sumitomo Mitsui Trust Bank (U.S.A.) Limited
Sumitomo Mitsui Trust Bank (U.S.A.) Limited: Japanese-owned U.S. trust bank providing global custody and securities-lending services mainly to institutional investors.
3+ YOERequires 3+ years managing vulnerability tools and conducting risk assessments, with expertise in network devices, Microsoft Windows environments, NIST frameworks, and strong analytical and communication skills.
Firewalls, IPS, IDS, NDR, NAC, Microsoft Windows, DHCP, DNS, Active Directory, NIST Cybersecurity Framework, SP 800-53, Cyber Risk Institute Profile v2.x, Qualys, Tenable, CISA Known Exploited Vulnerabilities (KEV) catalog
1mo
Save
Mark Applied
Hide
Threat Intelligence Analyst, Associate - Security Operations
New York, New York, United States
$135k-$170k/yr OnsiteFull Time
Blackstone
BlackstoneNYSE: BX: The world's largest alternative asset manager.
2+ YOE2+ years in CTI or security operations, experience with MITRE ATT&CK, TIPs/SIEM, ASM and vulnerability management, Python scripting, and applying AI/LLMs to automate intelligence workflows.
MITRE ATT&CK, Splunk, Splunk SPL, Sigma, YARA, KQL, Python, LLMs, ChatGPT, OpenAI, Claude, Anthropic, Gemini, GitHub Copilot, Cursor, Mandiant ASM, CrowdStrike Falcon Surface, Microsoft Defender EASM, AWS, Azure, CVSS, EPSS, CISA KEV
5d
Save
Mark Applied
Hide
Senior Staff GRC Analyst - Strategic Account Partner
Vancouver or New York City or Washington or London or Galway or Budapest or Munich or Bengaluru or Singapore or Sydney
HybridFull Time
Diligent
Diligent: Private GRC SaaS providing governance, risk, compliance, audit, and ESG software to boards and organizational leaders.
5+ YOERequires 5+ years in security GRC, customer assurance, consulting, or IT audit; hands-on audit leadership; deep SOC 2 and ISO 27001 knowledge; technical cloud, identity, encryption, logging, and vulnerability management expertise.
SOC 2, ISO 27001, NIST CSF, GDPR, HIPAA, DORA, cloud architecture, encryption, identity, logging, vulnerability management, trust center platforms, AI-assisted assurance tooling, large language models, AI