1

Cyber Security Risk Assessment Jobs in New York (NOW HIRING)

They will help shape Cyber Command's approach to risk management, build new risk frameworks and processes, and assess and monitor NYC agencies' cybersecurity risks. Responsibilities will include ...

They will help shape Cyber Command's approach to risk management, build new risk frameworks and processes, and assess and monitor NYC agencies' cybersecurity risks. Responsibilities will include ...

They will help shape Cyber Command's approach to risk management, build new risk frameworks and processes, and assess and monitor NYC agencies' cybersecurity risks. Responsibilities will include ...

Showing results 21-40

Cyber Security Risk Assessment information

See New York salary details

$62.4K

$145.5K

$203.5K

How much do cyber security risk assessment jobs pay per year?

As of Sep 5, 2026, the average yearly pay for cyber security risk assessment in New York is $145,465.00, according to ZipRecruiter salary data. Most workers in this role earn between $121,400.00 and $164,100.00 per year, depending on experience, location, and employer.

What is a cyber security risk assessment?

A cyber security risk assessment is a process used to identify, evaluate, and prioritize potential threats and vulnerabilities that could negatively impact an organization's information systems. By analyzing assets, threats, vulnerabilities, and impacts, organizations can determine the likelihood and consequences of cyber incidents. The goal is to implement appropriate measures to reduce risks to acceptable levels, ensuring data protection and regulatory compliance. Regular risk assessments help organizations stay ahead of evolving cyber threats and make informed security decisions.

What are some common challenges faced by professionals conducting cyber security risk assessments?

Professionals in cyber security risk assessment often face challenges such as keeping up with rapidly evolving threats, effectively communicating technical risks to non-technical stakeholders, and ensuring comprehensive coverage across complex IT environments. Balancing thoroughness with tight deadlines can also be demanding, as assessments must be both detailed and timely. Collaborating with various departments to gather accurate information and maintain up-to-date asset inventories is crucial for effective risk analysis and mitigation.

What are the key skills and qualifications needed to thrive in cyber security risk assessment, and why are they important?

To excel in Cyber Security Risk Assessment, you need a solid understanding of information security principles, risk management frameworks, and often a degree in cybersecurity, IT, or related fields. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM are commonly required. Analytical thinking, attention to detail, and strong communication skills help professionals effectively assess risks and convey findings to stakeholders. These skills are crucial for identifying vulnerabilities, prioritizing threats, and ensuring the organization’s data and systems are adequately protected.

What is the difference between Cyber Security Risk Assessment vs Cyber Security Analyst?

AspectCyber Security Risk AssessmentCyber Security Analyst
Primary FocusIdentifying and evaluating security risks and vulnerabilitiesMonitoring, analyzing, and responding to security threats
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment teams, consulting firms, security departmentsSecurity operations centers, IT departments, incident response teams

While both roles require similar certifications and work within cybersecurity, a Cyber Security Risk Assessment focuses on evaluating potential vulnerabilities and risks to an organization’s assets. In contrast, a Cyber Security Analyst actively monitors and responds to security threats, ensuring ongoing protection. Understanding these differences helps organizations assign the right responsibilities to each role.

What are risk assessments in cybersecurity?

In cybersecurity, a risk assessment is a process that a Cyber Security Risk Assessment professional uses to identify, evaluate, and prioritize potential security threats and vulnerabilities within an organization's information systems. It involves analyzing assets, threats, and existing controls to determine the level of risk, helping organizations implement appropriate security measures and comply with standards like ISO 27001 or NIST. Regular risk assessments are essential for maintaining a strong security posture and managing evolving cyber threats.

What are popular job titles related to Cyber Security Risk Assessment jobs in New York?

For Cyber Security Risk Assessment jobs in New York, the most frequently searched job titles are:

What job categories do people searching Cyber Security Risk Assessment jobs in New York look for?

The top searched job categories for Cyber Security Risk Assessment jobs in New York are:

What cities in New York are hiring for Cyber Security Risk Assessment jobs?

Cities in New York with the most Cyber Security Risk Assessment job openings:

Infographic showing various Cyber Security Risk Assessment job openings in New York as of August 2026, with employment types broken down into 88% Full Time, 10% Part Time, and 2% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $145,465 per year, or $69.9 per hour.

Clinical Engineering Cyber Specialist

MaxIT Consulting - Max Corporate Group

New York, NY

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 4 days ago


Job description

Clinical Engineering Cyber Specialist

Far Rockaway, New York | Onsite | Full-Time | Direct Hire

MaxIT Consulting – Max Corporate Group is seeking an experienced Clinical Engineering Cyber Specialist for a healthcare technology environment in New York.

This position focuses on the cybersecurity of connected medical devices and healthcare technology infrastructure. The successful candidate will lead critical technical activities involving medical device security controls, vulnerability management, risk assessment, asset cybersecurity data, network segmentation, and healthcare regulatory compliance.

This is a hands-on individual-contributor role that requires a combination of biomedical or medical device experience and healthcare cybersecurity expertise.

The Opportunity

You will work closely with Clinical Engineering, Healthcare Technology Management, hospital IT, Information Security teams, and medical device manufacturers to protect connected medical equipment and reduce cybersecurity risk.

The role combines technical cybersecurity execution, medical device knowledge, vulnerability remediation, risk analysis, compliance support, and cross-functional coordination.

Candidates should be comfortable working directly with medical-device inventories, manufacturers, hospital technology teams, security frameworks, and regulated healthcare environments.

Key Responsibilities
  • Lead the collection and maintenance of cybersecurity Critical Data Elements for medical devices within CMMS platforms.
  • Gather and maintain manufacturer cybersecurity documentation and recommendations.
  • Conduct cybersecurity risk assessments based on asset data, manufacturer guidance, and identified vulnerabilities.
  • Oversee secure configuration of medical devices in accordance with cybersecurity standards and manufacturer requirements.
  • Lead planned vulnerability remediation activities, including patching and device upgrades.
  • Coordinate urgent and unplanned remediation activities involving high-risk or zero-day vulnerabilities.
  • Work directly with medical device manufacturers on cybersecurity remediation and technical issues.
  • Investigate cybersecurity alerts affecting medical devices and determine appropriate response actions.
  • Analyze high and critical vulnerabilities and develop remediation recommendations.
  • Track and report vulnerability-management and remediation activities.
  • Support testing and validation of network segmentation controls in coordination with hospital IT.
  • Participate in IT projects that may affect connected medical devices and clinical technology.
  • Identify opportunities to strengthen cybersecurity practices across Healthcare Technology Management and IT.
  • Maintain quality and accuracy of cybersecurity data and documentation within CMMS.
  • Support cybersecurity education and awareness for HTM and biomedical teams.
  • Coach BMET professionals on cybersecurity hygiene and secure device configuration.
  • Support hospital and enterprise audits involving cybersecurity and regulatory requirements.
Required Qualifications
  • Minimum of 3 years of relevant functional experience.
  • Bachelor's degree or equivalent professional experience.
  • Previous biomedical, biomed, clinical engineering, or hands-on medical device experience.
  • Demonstrated healthcare cybersecurity experience.
  • Experience working with connected medical devices in a hospital, healthcare technology, or medical-device environment.
  • Knowledge of medical device cybersecurity controls and risk-assessment practices.
  • Experience with vulnerability management, remediation, patching, or cybersecurity incident response.
  • Familiarity with CMMS platforms used to manage medical-device assets and documentation.
  • Strong understanding of cybersecurity frameworks such as NIST and/or ISO.
  • Knowledge of healthcare and medical-device regulatory requirements including FDA, Joint Commission, and HIPAA.
  • Understanding of network segmentation concepts and their application to connected medical devices.
  • Strong analytical, communication, and cross-functional collaboration skills.
  • Ability to lead technical initiatives independently and coordinate across multiple technical teams.
  • Valid driver's license and acceptable driving record.
Preferred Qualifications

Relevant cybersecurity certifications are considered a plus, including:

  • CISSP
  • HCISPP
  • CEH
  • CompTIA Security+

Experience within hospital systems, Healthcare Technology Management organizations, clinical engineering departments, biomedical environments, or medical-device manufacturers will be especially valuable.

Technical Focus

Strong candidates should demonstrate experience across several of the following areas:

  • Medical device cybersecurity
  • Biomedical equipment
  • Clinical Engineering
  • Healthcare Technology Management
  • CMMS
  • Vulnerability management
  • Patch management
  • Zero-day response
  • Medical device risk assessments
  • Cybersecurity controls
  • Secure configuration
  • Network segmentation
  • NIST
  • ISO
  • FDA cybersecurity requirements
  • HIPAA
  • Joint Commission standards
  • Hospital IT
  • Information Security
  • Medical device manufacturers
What Success Looks Like

The successful candidate will combine cybersecurity expertise with a practical understanding of medical-device environments.

Relevant accomplishments may include:

  • Improving cybersecurity visibility across medical-device inventories
  • Leading vulnerability and patch-remediation efforts
  • Responding to high-risk or zero-day medical-device vulnerabilities
  • Conducting medical-device cybersecurity risk assessments
  • Improving CMMS cybersecurity data quality
  • Implementing or validating security controls
  • Supporting network segmentation initiatives
  • Coordinating cybersecurity remediation with device manufacturers
  • Supporting regulatory or cybersecurity audits
  • Improving security awareness across biomedical and HTM teams
Benefits

The benefits package may include:

  • Medical, dental, and vision coverage
  • Wellness programs
  • 401(k) plan with matching contributions
  • Paid time off
  • Company holidays
  • Professional development opportunities
  • Tuition reimbursement
  • Career growth opportunities
Work Arrangement

This is an onsite position based in Far Rockaway, Queens, New York.

Candidates should live within a practical daily commuting distance of the work location.

Relocation assistance is not available.

Work Authorization

Candidates must be legally authorized to work in the United States for any employer.

Visa sponsorship is not available for this position, now or in the future.

How to Apply

Please submit your application through this platform with an updated resume and relevant professional information.

Candidates should be prepared to provide details regarding:

  • Biomedical or medical-device experience
  • Healthcare cybersecurity experience
  • CMMS experience
  • Vulnerability and risk-management experience
  • NIST and/or ISO knowledge
  • FDA, HIPAA, and Joint Commission exposure
  • Relevant cybersecurity certifications
  • Current location
  • Valid driver's license
  • Work authorization status

If you combine hands-on medical-device experience with strong healthcare cybersecurity capabilities, we would like to hear from you.