1

Cybersecurity Risk Analyst Jobs in New York (NOW HIRING)

The position combines advanced incident response, digital forensics, threat detection, vulnerability management, cybersecurity analytics, governance, risk and compliance (GRC), and security ...

Showing results 41-60

Cybersecurity Risk Analyst information

See New York salary details

$16

$44

$72

How much do cybersecurity risk analyst jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for cybersecurity risk analyst in New York is $44.29, according to ZipRecruiter salary data. Most workers in this role earn between $32.60 and $53.89 per hour, depending on experience, location, and employer.

What does a cybersecurity risk analyst do?

A Cybersecurity Risk Analyst is responsible for identifying, assessing, and mitigating risks related to an organization’s information systems and data. They evaluate potential threats and vulnerabilities, develop strategies to minimize risks, and ensure compliance with security policies and regulations. Their work helps protect sensitive data and maintain the integrity and confidentiality of digital assets. Analysts often collaborate with IT and business teams to implement security controls and respond to security incidents.

What are the key skills and qualifications needed to thrive as a cybersecurity risk analyst, and why are they important?

To thrive as a Cybersecurity Risk Analyst, you need a deep understanding of information security principles, risk management frameworks, and typically hold a degree in computer science or a related field. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM is highly valued. Strong analytical thinking, effective communication, and attention to detail help you identify risks and convey complex information to stakeholders. These skills and qualifications are vital to proactively safeguard organizational assets and ensure compliance in an evolving threat landscape.

What are some common challenges faced by cybersecurity risk analysts when working with cross-functional teams?

Cybersecurity Risk Analysts often collaborate with IT, compliance, and business units to assess and mitigate risks. A common challenge is translating complex technical risks into language that non-technical stakeholders can understand and act upon. Additionally, balancing security requirements with business objectives may require negotiation and creative problem-solving. Effective communication and relationship-building skills are key to ensuring that security recommendations are adopted across the organization.

What is the difference between Cybersecurity Risk Analyst vs Cybersecurity Analyst?

AspectCybersecurity Risk AnalystCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Primary FocusAssessing and managing security risksMonitoring, detecting, and responding to security threats
Work EnvironmentRisk management teams, security departmentsSecurity operations centers, IT teams
Industry UsageFinance, healthcare, governmentAll industries with cybersecurity needs

While both roles involve cybersecurity, the Cybersecurity Risk Analyst primarily focuses on identifying and mitigating security risks, whereas the Cybersecurity Analyst concentrates on monitoring and responding to security incidents. Understanding these differences helps organizations assign the right roles for their security needs.

How much do cybersecurity risk analysts make?

Cybersecurity risk analysts typically earn a median annual salary of around $85,000 to $110,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries, especially in high-demand industries.
Infographic showing various Cybersecurity Risk Analyst job openings in New York as of August 2026, with employment types broken down into 1% As Needed, 85% Full Time, 11% Part Time, and 3% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution, with an average salary of $92,128 per year, or $44.3 per hour.

Cyber Security Analyst

City of New York

Manhattan, NY • On-site

Full-time

Re-posted 9 days ago


City Of New York rating

7.2

Company rating: 7.2 out of 10

Based on 81 frontline employees who took The Breakroom Quiz

623rd of 848 rated public administrative organizations


Job description

Job Description

DCAS's mission is to make city government work for all New Yorkers. From managing New York City's most iconic courthouses and municipal buildings, to purchasing over $1 billion annually in goods and services for more than 80 City agencies. What we do ensures that all agencies can deliver on their mission. Our reach
touches every facet of City government and is instrumental to the successful day-to-day operations of the City of New York. Our commitment to equity, effectiveness, and sustainability guides our work providing City agencies with the critical resources and support needed to succeed, including:
- Recruiting, hiring, and training City employees.
- Managing 56 public buildings.
- Acquiring, selling, and leasing City property.
- Purchasing over $1 billion in goods and services for City agencies.
- Overseeing the greenest municipal vehicle fleet in the country.
- Leading the City's efforts to reduce carbon emissions from government operations.
When you work at DCAS, you're not just working for one agency, but in service to all of them. It's an opportunity to provide meaningful support, quality customer service, and help protect the future of New York City for generations to come. Visit our website at NYC.GOV/DCAS to learn more about the work we do.
DCAS Information Technology works in conjunction with the NYC Office of Technology and Innovation (OTI) on the daily management and support of the DCAS computer network. DCAS IT team members are responsible for the agencies software and hardware needs, the development and maintenance of applications, maintenance of the DCAS internet and intranet (DCASConnect) sites, the DCAS Help Desk, telecommunications services and equipment for DCAS employees, and the Cyber Security program to thwart any attempts at unauthorized access to the network
The Infrastructure Engineer reports directly to the agency Chief Information Security Officer (CISO), responsible for protecting, monitoring, and enhancing the infrastructure and security posture of NYC Department of Citywide Administrative Services information systems, applications, networks, and cloud environments. The position combines advanced incident response, digital forensics, threat detection, vulnerability management, cybersecurity analytics, governance, risk and compliance (GRC), and security operations functions. The role serves as a technical escalation point for cybersecurity incidents, supports enterprise security initiatives, conducts cybersecurity assessments and audits, develops policies and procedures, and collaborates with City agencies, vendors, and stakeholders to improve cyber resilience and operational security.
- Assist the Agency CISO in ensuring cybersecurity-related change management and CI/CD processes align with NIST separation of duties requirements.
- Support the CISO with agency cyber awareness training, security onboarding and readiness assurance, and knowledge transfer for cloud-based applications.
- Lead and coordinate cybersecurity incident response, digital forensics, malware analysis, threat hunting, containment, eradication, recovery, and post-incident activities.
- Monitor and analyze security events, alerts, logs, and threat intelligence using SIEM, endpoint protection, cloud security, and monitoring platforms.
- Perform vulnerability assessments, risk analyses, remediation tracking, validation testing, and reporting across infrastructure, applications, cloud environments, and endpoints.
- Conduct cybersecurity audits, control assessments, risk reviews, and compliance evaluations aligned with NIST CSF, NIST SP 800-53, CIS Controls, Zero Trust principles, and Citywide cybersecurity policies.
- Develop and maintain cybersecurity policies, standards, procedures, playbooks, incident response plans, and operational documentation.
- Support Identity and Access Management (IAM) operations, including SSO, MFA, RBAC, access reviews, provisioning, deprovisioning, and privileged access governance.
- Analyze cybersecurity metrics, trends, vulnerabilities, incidents, and operational performance indicators; develop executive-level reports and recommendations.
- Partner with internal technology teams, application owners, vendors, City agencies, and external partners to improve cybersecurity capabilities and remediation outcomes.
- Support cloud security reviews, application security assessments, secure application onboarding, and software security initiatives.
- Provide technical leadership, mentoring, and guidance to junior cybersecurity staff and cross-functional stakeholders.
- Assist with audit readiness, evidence collection, regulatory compliance activities, and cybersecurity governance initiatives.
- Research emerging threats, technologies, attack techniques, and industry best practices to strengthen defensive capabilities.
To Apply:
Please go to www.nyc.gov/jobs, or www.nyc.gov/ess for current NYC employees, and search for Job ID #788324.
No phone calls, faxes or personal inquiries permitted. Only those candidates under consideration will be contacted.
IT INFRASTRUCTURE ENGINEER - 95714

Qualifications

1. A baccalaureate degree from an accredited college in computer science, engineering or a related field and four years of satisfactory full-time experience related to datacenter engineering and operations, cloud engineering and operations, complex IT infrastructure engineering; or,
2. A baccalaureate degree from an accredited college and eight years of satisfactory full-time experience related to datacenter engineering and operations, cloud engineering and operations, complex IT infrastructure engineering; or,
3. Education and/or experience which is equivalent to "1" or "2" above.

Additional Information

The City of New York is an inclusive equal opportunity employer committed to recruiting and retaining a diverse workforce and providing a work environment that is free from discrimination and harassment based upon any legally protected status or protected characteristic, including but not limited to an individual's sex, race, color, ethnicity, national origin, age, religion, disability, sexual orientation, veteran status, gender identity, or pregnancy.


What City Of New York employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom