An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Gambit Technologies in New York City is seeking a Senior Security Risk & Technical Assurance Analyst to join a small security team reporting to the CISO. The role blends governance, risk, and hands-on testing across vendor risk reviews, technical validation, and security controls within DLP and the stack.
7+ years of-depth in GRC and hands-on security, with knowledge of NIST CSF, 800-53, CIS, MITRE ATT&CK. CISSP/CISA/CRISCGPEN/OSCP count.
Senior Security Risk & Technical Assurance Analyst
NYC, hybrid. NYC metro candidates only.
My client is a large private philanthropy in Manhattan. Public health, climate, education, government innovation, the arts. Real money going out the door to real programs. The security team is small and close-knit, you report into the CISO directly, and there aren't four layers between your recommendation and the decision. When you say don't buy that tool, that's usually the end of it.
The other thing that makes this one different: you're not just writing the risk, you're proving it. Roughly 40% vendor risk and security reviews, 30% hands-on technical validation, the rest across the security stack and DLP. So you'll read a SOC 2 and know when the evidence is too old or too narrow to count, sit with counsel on breach notification terms, then go test whether that critical CVE is actually reachable here instead of trusting the severity score.
Small team means broad scope. You'll touch Splunk, CrowdStrike, Netskope, Qualys, Gurucul, Symantec ProxySG, Swimlane, and BlinkOps. Nobody expects mastery of all eight.
Looking for 7+ years with genuine depth on both the GRC side and the hands-on side. NIST CSF, 800-53, CIS, MITRE ATT&CK. CISSP, CISA, CRISC, GPEN, and OSCP all count.