1

Cybersecurity Contractor Jobs in New York (NOW HIRING)

Engineering Manager, Cybersecurity

Jersey City, NJ ยท Hybrid

$115K - $156K/yr

Oversee offshore contractor engagements, including deliverables, work quality, and coordination with vendor and resource management. * Serve as the governance lead for all cybersecurity matters ...

Engineering Manager, Cybersecurity

Jersey City, NJ ยท On-site

$115K - $156K/yr

Oversee offshore contractor engagements, including deliverables, work quality, and coordination with vendor and resource management. * Serve as the governance lead for all cybersecurity matters ...

Director, Cybersecurity Engineering

Rahway, NJ ยท Hybrid

$156K - $247K/yr

If you are passionate about cybersecurity and innovation, and thrive in a dynamic environment, we ... As a federal contractor, we comply with all affirmative action requirements for protected veterans ...

Cyber Security Lead OT

Bethpage, NY ยท On-site

$113K - $153K/yr

Job Number: 7464 External Description: Cyber Security Lead -OT Date: Mar 11, 2026 Location ... oversee contractors, vendors, or project teams. Occasional travel to operational sites may be ...

Cyber Security Lead OT

Bethpage, NY ยท Hybrid

$113K - $153K/yr

Cyber Security Lead -OT Date: Mar 11, 2026 Location: Bethpage, NY, US Company: LIPAPRD Requisition ... oversee contractors, vendors, or project teams. Occasional travel to operational sites may be ...

... cybersecurity concepts to non-technical stakeholders Financial Services Industry experience is requires Note: This is a part time position - 5-10 hours per week. KPMG LLP ("KPMG") seeks a contractor ...

next page

Showing results 1-20

Cybersecurity Contractor information

See New York salary details

$62.4K

$145.5K

$203.5K

How much do cybersecurity contractor jobs pay per year?

As of Aug 22, 2026, the average yearly pay for cybersecurity contractor in New York is $145,465.00, according to ZipRecruiter salary data. Most workers in this role earn between $121,400.00 and $164,100.00 per year, depending on experience, location, and employer.

What does a cybersecurity contractor do?

A cybersecurity contractor is an independent professional or specialist hired to protect an organization's digital assets and information systems from cyber threats. Their responsibilities can include assessing security risks, implementing protection measures, conducting penetration testing, and responding to security breaches. Unlike full-time employees, contractors are typically engaged for specific projects or time periods, providing expertise on-demand. They may work on tasks such as compliance audits, security architecture design, or incident response. The role requires up-to-date knowledge of cybersecurity tools, tactics, and regulations.

What are some common challenges faced by cybersecurity contractors when integrating with new client teams?

Cybersecurity contractors often face challenges when joining new client teams, such as quickly understanding the existing IT infrastructure and navigating different security protocols. Building trust and effective communication with in-house staff is essential, especially when proposing changes to established processes. Contractors must also adapt to varying organizational cultures and be prepared to align their work with both technical and business priorities to ensure a smooth and effective collaboration.

What are the key skills and qualifications needed to thrive as a cybersecurity contractor, and why are they important?

To thrive as a Cybersecurity Contractor, you need a strong understanding of network security, risk assessment, and incident response, typically supported by a degree in computer science or information security and relevant certifications. Familiarity with tools such as SIEM platforms, vulnerability scanners, firewalls, and certifications like CISSP or CEH are highly valued. Excellent problem-solving skills, attention to detail, and strong communication abilities help you adapt to diverse client environments and explain technical concepts clearly. These competencies are essential for protecting organizational assets, ensuring compliance, and effectively mitigating cyber threats.

What is the difference between Cybersecurity Contractor vs Cybersecurity Analyst?

AspectCybersecurity ContractorCybersecurity Analyst
CredentialsCertifications like CISSP, CEH, CompTIA Security+Certifications like Security+, CISSP, GIAC
Work EnvironmentTemporary or project-based, often freelance or consultingFull-time, in-house or remote security team member
Employer & Industry UsageHired by organizations for specific security projectsEmployed by companies to monitor and improve security posture

Cybersecurity Contractors typically work on short-term projects with specific goals, often as freelancers or consultants, while Cybersecurity Analysts are usually full-time employees responsible for ongoing security monitoring and analysis. Both roles require similar certifications and work within the same industry environments, but their employment structures and responsibilities differ.

What cities in New York are hiring for Cybersecurity Contractor jobs?

Cities in New York with the most Cybersecurity Contractor job openings:

Infographic showing various Cybersecurity Contractor job openings in New York as of August 2026, with employment types broken down into 71% Full Time, 13% Part Time, and 16% Contract. Highlights an 86% Physical, 2% Hybrid, and 12% Remote job distribution, with an average salary of $145,465 per year, or $69.9 per hour.

Engineering Manager, Cybersecurity

Forbes

Jersey City, NJ โ€ข Hybrid

$115K - $156K/yr

Full-time

Re-posted 9 days ago


Job description

Forbes is seeking an Engineering Manager, Cybersecurityย responsible for protecting Forbes' corporate technology environment and consumer-facing digital platforms through the design, implementation, and continuous improvement of cybersecurity controls, processes, and governance. This is a hands-on technical leadership role reporting to the Vice President, Corporate Technology, with formal people-management responsibility for a small distributed team of onshore employees and offshore contractors.

This individual will own cybersecurity across two complementary domains: corporate technology security, spanning identity and access management, endpoint protection, network and cloud security, email and phishing defense, and compliance; and web platform security, spanning cloud infrastructure, source code and pipeline security, vulnerability management, and client-side protection for Forbes' digital properties. The role also serves as the governance lead for all cybersecurity matters across the organization, partnering closely with Infrastructure, Engineering, QA, Product, Legal, and Corporate Technology teams. The ideal candidate is both a technical security expert and a business-minded collaborator, capable of balancing security requirements with operational efficiency and business objectives.

This is a hybrid position based at Forbes' Jersey City headquarters, with an expectation of working in the office 2-3 days per week. Candidates should reside in New Jersey, New York, or the greater New York City metropolitan area.

Responsibilities:

Leadership and Governance

  • Lead, mentor, and manage a distributed team of onshore employees and offshore contractors supporting corporate technology and web platform security.
  • Manage direct reports, goal setting, performance reviews, professional development, and day-to-day prioritization of work.
  • Oversee offshore contractor engagements, including deliverables, work quality, and coordination with vendor and resource management.
  • Serve as the governance lead for all cybersecurity matters across the organization, setting direction, standards, and priorities.
  • Develop and maintain company-wide cybersecurity policies, standards, procedures, and technical documentation.
  • Partner with Legal on vendor security preparation and review, including NDAs, data processing agreements (DPAs), and vendor risk assessments.
  • Manage cybersecurity projects, operational requests, and remediation initiatives, ensuring timely execution and resolution.
  • Support PCI and other compliance initiatives, audits, and security assessments, including evidence collection and questionnaire responses.
  • Maintain security metrics, reporting, and operational dashboards to provide visibility into organizational risk.
  • Monitor emerging cybersecurity threats and vulnerabilities, recommending improvements to strengthen Forbes' security posture.
  • Serve as the organization's designated HIPAA Security Officer, ensuring compliance with the HIPAA Security Rule and overseeing the protection of electronic protected health information (ePHI).

Corporate Technology Security

  • Administer and secure the enterprise identity and access management (SSO/MFA) platform, including authentication policies, identity lifecycle automation, and privileged access controls.
  • Manage endpoint detection and response (EDR) and endpoint protection across the enterprise device fleet.
  • Manage enterprise network security, including next-generation firewalls, switching infrastructure, and cloud network environments.
  • Secure the enterprise cloud identity and directory environment, including conditional access, session controls, and account hygiene.
  • Manage email security and phishing defense, including phishing investigation and triage, security awareness training, and phishing simulation programs.
  • Lead security incident investigations and response efforts, coordinating remediation and root-cause analysis activities.

Web and Digital Platform Security

  • Manage cloud network architecture and security controls for Forbes' consumer-facing digital platforms.
  • Oversee source code and development platform security, including repository access controls, secrets management, and CI/CD pipeline security.
  • Own the vulnerability scanning and vulnerability management program across web properties and infrastructure, driving remediation with Engineering.
  • Lead client-side security for web properties, including governance of third-party scripts and tags and browser-side protections.
  • Partner with Engineering, QA, and Product teams to embed security requirements and best practices throughout the software development lifecycle.

The ideal candidate:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related technical field.
  • CISSP, CCSP, CISM, Security+ and/or GIAC certifications preferred.
  • 7+ years of cybersecurity experience, including cloud security, infrastructure security, network security, or security engineering.
  • Experience leading and developing security engineers, including distributed and offshore team members or contractors.
  • Experience with the HIPAA Security Rule and protecting electronic protected health information (ePHI) is preferred
  • Experience managing enterprise productivity suites, identity and access management platforms, public cloud platforms, and endpoint protection and threat detection solutions.
  • Hands-on experience with enterprise firewalls, network infrastructure, and cloud networking across multiple cloud providers.
  • Practical experience applying AI tools to security and engineering workflows, such as automation, detection, triage, and reporting, and familiarity with governing safe AI adoption across an enterprise.
  • Strong scripting and automation skills for security workflow and identity lifecycle automation.
  • Experience supporting PCI audits, compliance assessments, and security reviews.
  • Deep understanding of identity management, privileged access controls, authentication, and authorization principles.
  • Skilled in leading investigations, incident response, vulnerability management, and threat analysis.
  • Experience developing and maintaining security policies, standards, and governance processes.
  • Experience partnering with legal and procurement teams on vendor security reviews and contract preparation.
  • Proven ability to balance strategic security initiatives with hands-on technical execution.
  • Exceptional communication skills with the ability to explain complex security concepts to both technical and non-technical stakeholders.

The annual base salary range for this role is $165,000 - $175,000.

Forbes has estimated the compensation range set forth above in good faith.ย  The compensation range is what we believe we will offer, and ultimately pay, a successful candidate.ย  In determining this range, we consider the experience, level of education (if applicable to the role), knowledge, skills, and abilities required to be had by a successful candidate as well as the budget and the company's pay rates, generally. This said, we may have to make changes to our compensation estimates and job descriptions from time to time and we expressly reserve the right to do so.ย  Should we make any such changes, this advertisement will be revised to reflect such revisions.ย  We encourage you to occasionally re-visit this advertisement to ensure that you are abreast of any changes.ย 

#LI-RL1
#LI-HYBRID