Senior Security Risk & Technical Assurance Analyst

Gambit Technologies

New York (NY)

Hybrid

USD 130,000 - 170,000

Full time

3 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Gambit Technologies in New York City is seeking a Senior Security Risk & Technical Assurance Analyst to join a small security team reporting to the CISO. The role blends governance, risk, and hands-on testing across vendor risk reviews, technical validation, and security controls within DLP and the stack.

7+ years of-depth in GRC and hands-on security, with knowledge of NIST CSF, 800-53, CIS, MITRE ATT&CK. CISSP/CISA/CRISCGPEN/OSCP count.

Qualifications

  • 7+ years of experience across GRC and hands-on security.
  • Knowledge of NIST CSF, 800-53, CIS, MITRE ATT&CK.
  • Certifications such as CISSP, CISA, CRISC, GPEN, OSCP are valuable.

Responsibilities

  • Lead vendor risk assessments and security reviews.
  • Perform hands-on technical validation and threat assessment.
  • Evaluate evidence from SOC 2, breach-notification terms, and CVE reachability.
  • Contribute across the security stack and DLP.
  • Interact with counsel on terms and risk posture.

Skills

GRC experience
Hands-on security testing
Vendor risk assessment
NIST CSF
MITRE ATT&CK
CIS controls
Security controls

Tools

Splunk
CrowdStrike
Netskope
Qualys
Gurucul
Symantec ProxySG
Swimlane
BlinkOps

Job description

Senior Security Risk & Technical Assurance Analyst

NYC, hybrid. NYC metro candidates only.

My client is a large private philanthropy in Manhattan. Public health, climate, education, government innovation, the arts. Real money going out the door to real programs. The security team is small and close-knit, you report into the CISO directly, and there aren't four layers between your recommendation and the decision. When you say don't buy that tool, that's usually the end of it.

The other thing that makes this one different: you're not just writing the risk, you're proving it. Roughly 40% vendor risk and security reviews, 30% hands-on technical validation, the rest across the security stack and DLP. So you'll read a SOC 2 and know when the evidence is too old or too narrow to count, sit with counsel on breach notification terms, then go test whether that critical CVE is actually reachable here instead of trusting the severity score.

Small team means broad scope. You'll touch Splunk, CrowdStrike, Netskope, Qualys, Gurucul, Symantec ProxySG, Swimlane, and BlinkOps. Nobody expects mastery of all eight.

Looking for 7+ years with genuine depth on both the GRC side and the hands-on side. NIST CSF, 800-53, CIS, MITRE ATT&CK. CISSP, CISA, CRISC, GPEN, and OSCP all count.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Risk & Technical Assurance Leader
Senior Security Risk & Technical Assurance Leader

Gambit Technologies • New York (NY)

Hybrid
USD 130,000 - 170,000
Senior Security Client Solution Architect (Remote)
Senior Security Client Solution Architect (Remote)

Myriad360 • New York (NY)

On-site
USD 250,000 - 275,000
Unlimited Paid Time Off (PTO)
Incentive compensation plans
Company-funded 401k contributions
+3
Senior Security Client Solution Architect (Remote)
Senior Security Client Solution Architect (Remote)

Myriad360 • Houston (TX)

On-site
USD 250,000 - 275,000
Unlimited Paid Time Off (PTO)
Company-funded 401k contributions
Zero-cost employer-covered health insurance
+2
Senior Security Analyst
Senior Security Analyst

Valon Mortgage • United States

Hybrid
USD 120,000 - 160,000
Remote options
Health insurance
Parental leave
+1
Security Risk Assessment Specialist/ Security Analyst
Security Risk Assessment Specialist/ Security Analyst

Mindlance • Hopewell (NJ)

On-site
USD 95,000 - 130,000
Senior Security Client Solution Architect (Remote)
Senior Security Client Solution Architect (Remote)

Myriad360 • Detroit (MI)

On-site
USD 250,000 - 275,000
Unlimited PTO
Incentive compensation plans
Company-funded 401k
+4
Senior Security Client Solution Architect (Remote)
Senior Security Client Solution Architect (Remote)

Myriad360 • Cleveland (OH)

On-site
USD 250,000 - 275,000
Unlimited PTO
Company‑funded 401k contributions
Zero‑cost health insurance
+1
Senior Security Client Solution Architect (Remote)
Senior Security Client Solution Architect (Remote)

Myriad360 • Chicago (IL)

On-site
USD 250,000 - 275,000
Unlimited Paid Time Off (PTO)
Incentive compensation plans
Company-funded 401k contributions
+3
Senior Security Client Solution Architect (Remote)
Senior Security Client Solution Architect (Remote)

Myriad360 • Los Angeles (CA)

On-site
USD 250,000 - 275,000
Unlimited Paid Time Off (PTO)
Incentive compensation plans
Company-funded 401k contributions
+3
Senior Security Client Solution Architect (Remote)
Senior Security Client Solution Architect (Remote)

Myriad360 • Columbus (OH)

On-site
USD 250,000 - 275,000
Unlimited PTO
Incentive compensation plans for all员工
Company-funded 401k contributions
+2