Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Bond, Schoeneck & King PLLC, a law firm with a strong information security program, seeks a Security Analyst to support the IT Department in a hybrid role across Buffalo, Albany, Rochester, or Syracuse, NY.
The role emphasizes monitoring security events, incident response, vulnerability management, identity governance, and compliance support to protect confidential client, attorney, and firm data while enabling effective legal practice.
Bond, Schoeneck & King, PLLC, a law firm of 300 attorneys in over 30 practice groups, is accepting applications for a full-time Security Analyst to support our Information Technology Department. This position supports and advances the Firm’s information security program by protecting confidential client, attorney, and business information across firm systems, cloud platforms, endpoints, networks, and third-party services. The Security Analyst partners with IT, attorneys, administrative departments, vendors, and leadership to reduce cyber risk while enabling the efficient practice of law. This is a hybrid opportunity that can be based out of the following office locations:Buffalo, NY, Albany, NY, Rochester, NY, Syracuse, NY.
Monitor, investigate, and respond to security events with sound judgment, clear documentation, and timely escalation
Help mature the Firm’s security operations, vulnerability management, identity governance, awareness and reporting capabilities
Translate technical security issues into practical risk language for IT leadership and non-technical stakeholders
Monitor alerts and telemetry from SIEM, XDR/EDR, email security, identity, cloud, network, and vulnerability management platforms
Triage suspicious activity, validate severity, correlate indicators, and document findings in clear incident or case records
Recommend tuning, automation, and process improvements to reduce noise and improve detection quality
Assist with identification, containment, eradication, recovery and post-incident documentation for cybersecurity incidents
Escalate material events promptly with evidence, impact assessment, business context, and recommended next steps
Contribute to playbooks, tabletop exercises, lessons learned, and continuous improvement of incident response procedures
Support recurring vulnerability scanning, risk prioritization, remediation tracking, and exception documentation
Partner with infrastructure, application teams to address vulnerabilities based on exploitability, business criticality, and client confidentiality risk
Prepare status updates and metrics that show remediation progress, aging risk, recurring issues, and barriers to closure
Assist with access reviews, privileged access monitoring, conditional access, MFA compliance, and joiner/mover/leaver control validation
Support protection of sensitive firm and client information through monitoring, policy enforcement, encryption, data loss prevention, and secure collaboration practices
Identify access or configuration gaps that could affect confidentiality, ethical wall obligations, or client expectations
Maintain security documentation, standard operating procedures, control evidence, expectation records, and management reporting materials
Use recognized security frameworks and standards to help align security practices with firm risk tolerance and professional services expectations
Support security awareness campaigns, phishing simulations, targeted guidance, and practical education for attorneys and staff
Support identifying recurring user behavior risks and recommend training, technical controls, or process refinements
Bachelor’s Degree in cyber security, computer science, engineering, or related field is required
Security Certifications such as Security+, CySA+, SSCP, CISSP Associate, AZ-500, SC-200, Sc-300, or similar credentials.
Experience: 2+ years of experience in a cybersecurity or IT role.
Technical Skills: Proficiency in using cybersecurity tools such as SIEM (Security Information and Event Management), IDS/IPS (Intrusion Detection System/Intrusion Prevention System), EDR (Endpoint Detection and Response), and vulnerability scanners.
Analytical Skills: Strong analytical and problem-solving skills. Ability to analyze complex data sets and identify patterns and anomalies.
Communication Skills: Excellent verbal and written communication skills. Ability to communicate technical information to non-technical stakeholders.
Attention to Detail: High level of attention to detail and accuracy. Ability to work under pressure and manage multiple tasks simultaneously.
Team Player: Ability to work effectively as part of a team and collaborate with colleagues from various departments.
Proficiency in information security frameworks, including ISO 27000, NIST, or COBIT.
Knowledge of security standards such as HIPAA, NIST, PCI, SOX, DFARS, FISMA, NYDFS, and others.
Participate in a 24x7 on call rotation.
Some travel may be required to Regional Offices
At Bond, exceptional work product and a collegial work environment are cornerstones of our success. We are committed to the communities in which we live and work. Bond has long recognized the value, both to its team and to our communities, of active participation in and support of charitable, governmental, professional and community-based organizations. This position's salary range is between $95,000 to $105,000, negotiable based on years’ experience.
Bond, Schoeneck & King PLLC provides all employees and applicants an equal employment opportunity in the manner required by law in all aspects of employment regardless of race, color, religion, creed, national origin, age, sex, sexual orientation, gender identity or expression, marital status, military status, disability, predisposing genetic characteristics, domestic violence victim status or any other status protected by local, state or federal law. We thank all applicants for their interest and will contact those candidates who are under consideration.