Cyber Security Analyst, Level 2

Nyc-Employees-Retirement-Sys

New York (NY)

On-site

USD 90,000 - 120,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

55a Program
Public Service Loan Forgiveness

Job summary

City of New York is seeking an Information Security Analyst to monitor alerts, investigate threats, and support security operations across the agency. The role includes access provisioning, log analysis, vulnerability reviews, and enhancing security controls within our SIEM and related tools.

The position also focuses on Business Continuity planning, risk assessment, and incident response coordination. NY residency is required, with a pathway to city benefits and loan forgiveness programs.

Qualifications

  • Bachelor’s degree or equivalent with cyber security credits; or related combination of education/experience as described in the minimum qualifications.
  • Three years of experience in cyber security or related areas may substitute educational requirements.
  • Security certifications encouraged (e.g., CISSP, CompTIA Security+).

Responsibilities

  • Monitor alerts and perform log analysis to detect suspicious activity; triage incidents.
  • Support development and testing of Business Continuity Plan (BCP) and Disaster Recovery (DR) plans; conduct tabletop exercises.
  • Assist Enterprise Risk Management by identifying and reporting security risks and monitoring KRIs.

Skills

Cybersecurity Threat Management
Security Frameworks & Controls
Incident Response
Cloud Security Architecture
Security Tooling Proficiency
Business Continuity & Resilience
BC/DR Plan Development
Testing & Simulation
Resilience Standards
Enterprise Risk Management
Regulatory Compliance
Third-Party Risk Management
Data Analytics & Scripting

Education

Bachelor’s degree with 24 cyber security credits

Tools

SIEM
EDR
DLP
Firewall
Vulnerability scanners

Job description

CANDIDATES MUST BE PERMANENT IN THE CYBER SECURITY ANALYST CIVIL SERVICE TITLE OR HAVE A COMPARABLE CIVIL SERVICE TITLE TO APPLY

The Information Security Analyst supports day-to-day security operations by monitoring alerts, investigating potential threats, and helping protect systems, networks, and data. This role will support many functions of the Information Security Program which include, access provisioning, log analysis for fraud mitigation, security accreditations of new products and services, vulnerability reviews and follow up remediation of vulnerabilities associated to our new pension platform, reviews of indicators or compromise to be applied to NYCERS security controls for awareness, monitoring and incident response of our SIEM and security tools for suspicious activity, triage alerts and elevate incidents to senior analysts, support phishing analysis and malware investigations, support phishing simulations and user awareness campaigns, assist with security reports and dashboards, help update playbooks, policies, procedures, standards, and guidelines, participate in basic risk assessments, and promote security best practices, across the agency.

Key Responsibilities
  • Information and Cyber Security: Understanding of networking, familiarity with applications and operating systems, knowledge of cyber security concepts, and willingness to manage, fine tune, and optimize security tools, such as SIEM, Endpoint Detection, Fraud mitigation tools, Intrusion Detection, etc. (training provided). Additional skills include possessing or willing to obtain a security certification (CompTIA Security+, Google Cybersecurity professional, CISSP, etc.), detail oriented, good written and oral communications, comfortable interaction with agency colleagues, ability to follow procedures and ask questions.
  • Business Continuity: The Information Security Analyst will play a critical role in strengthening organizational resilience by leading the development, support, and testing of the comprehensive Business Continuity Plan (BCP). This includes conducting regular Business Impact Analyses (BIA) to establish Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO), maintaining up-to-date recovery documentation, and providing continuity training across business units. The candidate will design and facilitate annual tabletop exercises simulating cyberattacks or system outages, document the results, and track remediation actions to close identified gaps.
  • Enterprise Risk Management: Additionally, this role will directly assist with the Enterprise Risk Management (ERM) program by identifying, analyzing, and cataloging security risks within the central corporate risk register. The analyst will partner with various agency divisions and the head of Enterprise Risk Management to develop risk mitigation strategies, monitor key risk indicators (KRIs), and prepare detailed risk profile reports and dashboards for senior leadership.

CYBER SECURITY ANALYST - 13633

Minimum Qualifications
  • 1. A baccalaureate degree, from an accredited college including or supplemented by twenty-four (24) semester credits in cyber security, network security, computer science, computer programming, computer engineering, information technology, information science, information systems management, network administration, or a pertinent scientific, technical or related area; or
  • 2. A four-year high school diploma or its equivalent approved by a State’s department of education or a recognized accrediting organization and three years of satisfactory experience in any of the areas described in “1” above; or
  • 3. Education and/or experience equivalent to “1” or “2”, above. College education may be substituted for up to two years of the required experience in “2” above on the basis that sixty (60) semester credits from an accredited college is equated to one year of experience. In addition, twenty-four (24) credits from an accredited college or graduate school in cyber security, network security, computer science, computer programming, computer engineering, information technology, information science, information systems management, network administration, or a pertinent scientific, technical or related area; or a certificate of at least 625 hours in computer programming from an accredited technical school (post high school), may be substituted for one year of experience.
Preferred Skills
  • Cybersecurity & Threat Management- Vulnerability & Threat Management: Proficiency in identifying system vulnerabilities, interpreting threat intelligence, and conducting comprehensive security assessments.
  • Security Frameworks & Controls: Hands-on experience mapping controls to industry-standard frameworks such as NIST CSF 2.0, NYDFS, ISO 27001, and CIS Controls.
  • Incident Response: Proven ability to monitor alerts, perform log analysis, and execute Incident Response (IR) protocols to quickly contain and mitigate cyber-attacks.
  • Cloud Security Architecture: Foundational knowledge of cloud-native security controls and remote access protections within Microsoft Azure, Salesforce, AWS, or GCP.
  • Security Tooling Proficiency: Experience utilizing security tools such as SIEM platforms, DLP, EDR, firewalls, and vulnerability scanners.
  • Business Continuity & Operational Resilience- Business Impact Analysis (BIA): Competency in conducting BIAs to identify critical business functions, resource dependencies, and potential operational disruptions.
  • BC/DR Plan Development: Experience designing, maintaining, and documenting Business Continuity (BC) and Disaster Recovery (DR) plans to ensure minimum downtime.
  • Testing & Simulation: Ability to coordinate and facilitate tabletop exercises, disaster simulations, and crisis management testing with cross-functional teams.
  • Resilience Standards: Familiarity with business continuity standards, specifically ISO 22301 (Business Continuity Management) and NIST SP 800-160.
  • Enterprise Risk Management- Risk Assessment Methodologies: Strong understanding of IT and operational risk management principles using methodologies like NIST Risk Management Framework (RMF).
  • Regulatory Compliance: Familiarity with data protection laws, industry regulations, and compliance standards.
  • Third-Party Risk Management (TPRM): Experience assessing vendor risks, reviewing SOC 2 reports, and ensuring supply chain security.
  • Data Analytics & Scripting: Capability to query data and automate repetitive risk workflows using SQL, Python, or PowerShell.
55a Program

This position is also open to qualified persons with a disability who are eligible for the 55-a Program.

Public Service Loan Forgiveness

As a prospective employee of the City of New York, you may be eligible for federal loan forgiveness programs and state repayment assistance programs. For more information, please visit the U.S. Department of Education’s website at https://studentaid.gov/pslf/.

Residency Requirement

New York City residency is generally required within 90 days of appointment. However, City Employees in certain titles who have worked for the City for 2 continuous years may also be eligible to reside in Nassau, Suffolk, Putnam, Westchester, Rockland, or Orange County. To determine if the residency requirement applies to you, please discuss with the agency representative at the time of interview.

Additional Information

The City of New York is an inclusive equal opportunity employer committed to recruiting and retaining a diverse workforce and providing a work environment that is free from discrimination and harassment based upon any legally protected status or protected characteristic, including but not limited to an individual's sex, race, color, ethnicity, national origin, age, religion, disability, sexual orientation, veteran status, gender identity, or pregnancy.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Analyst
Cyber Security Analyst

CONSUMER AND WORKER PROTECTION • New York (NY)

On-site
USD 100,000 - 140,000
Director, Information Security
Director, Information Security

Department of Building • New York (NY)

Hybrid
USD 180,000 - 240,000
Cyber Security Analyst
Cyber Security Analyst

New-York-City-Department-of-Citywide-Administrative-Services • New York (NY)

On-site
USD 100,000 - 170,000
STAFF ANALYST
STAFF ANALYST

POLICE DEPARTMENT • New York (NY)

On-site
USD 70,000 - 100,000
Health insurance
Dental coverage
Vision coverage
+6
Senior Risk Analyst
Senior Risk Analyst

OFF OF PAYROLL ADMINISTRATION • New York (NY)

On-site
USD 120,000 - 150,000
STAFF ANALYST
STAFF ANALYST

New York City Police Department • New York (NY)

On-site
USD 65,000 - 90,000
Health insurance
Union benefits (dental & vision)
Paid annual leave and sick leave
+5
Senior Threat Analyst
Senior Threat Analyst

TECHNOLOGY & INNOVATION • New York (NY)

On-site
USD 90,000 - 130,000
PEOPLE DATA & STRATEGY ANALYST
PEOPLE DATA & STRATEGY ANALYST

NYC Department of Social Services • New York (NY)

On-site
USD 75,000 - 110,000
Senior Threat Analyst
Senior Threat Analyst

New York City Office of Technology & Innovation • New York (NY)

On-site
USD 110,000 - 150,000
Hiring Plan Analyst
Hiring Plan Analyst

Department of Transportation • New York (NY)

On-site
USD 75,000 - 95,000