1

Phishing Email Analyst Jobs in Rochester, NY (NOW HIRING)

Phishing Email Analyst information

See Rochester, NY salary details

$30.6K

$72.3K

$128.3K

How much do phishing email analyst jobs pay per year?

As of Aug 19, 2026, the average yearly pay for phishing email analyst in Rochester, NY is $72,284.00, according to ZipRecruiter salary data. Most workers in this role earn between $51,800.00 and $85,800.00 per year, depending on experience, location, and employer.

What is a phishing email analyst?

Phishing Email Analysts are cybersecurity professionals who specialize in identifying, analyzing, and responding to phishing emails. Their primary role is to detect suspicious emails, investigate their origins and intent, and help protect organizations from email-based cyber threats. They often collaborate with IT and security teams to develop strategies and training programs that minimize the risk of phishing attacks. By analyzing trends and reporting incidents, they contribute to enhancing the overall security posture of a company.

What skills and qualifications are needed to be a phishing email analyst?

To thrive as a Phishing Email Analyst, you need strong analytical skills, knowledge of cybersecurity principles, and experience with threat detection—often supported by degrees in IT or cybersecurity and relevant certifications. Familiarity with email security gateways, SIEM tools, and phishing simulation platforms is typically required. Attention to detail, critical thinking, and effective communication are vital soft skills in this role. These competencies enable accurate identification and response to phishing threats, helping protect organizations from cyberattacks.

What challenges do phishing email analysts face in identifying sophisticated phishing attempts?

Phishing Email Analysts often encounter challenges with increasingly sophisticated phishing campaigns that use advanced social engineering tactics and mimic legitimate communications. Attackers may employ tactics like domain spoofing, well-crafted language, and even personalized details to evade detection. Analysts must stay vigilant, continuously update their knowledge on emerging threats, and collaborate closely with IT security teams to refine detection protocols. Regular training and awareness of the latest phishing trends are essential to effectively differentiate between genuine and malicious emails.

What is the difference between Phishing Email Analyst vs Security Analyst?

AspectPhishing Email AnalystSecurity Analyst
CredentialsCertifications like CompTIA Security+, CEH often preferredCertifications like CISSP, Security+ common
Work EnvironmentFocus on email security, threat detection, and analysisBroader security responsibilities including network, system, and data protection
Employer & IndustryFinancial institutions, tech companies, cybersecurity firmsAll industries, including finance, healthcare, government
Search & Comparison IntentUnderstanding specific email threat rolesBroader cybersecurity roles and responsibilities

The Phishing Email Analyst specializes in identifying and mitigating email-based threats, focusing on phishing attacks and email security. In contrast, a Security Analyst has a broader scope, covering various security domains beyond email. Both roles require similar certifications and are vital in protecting organizational assets, but their focus areas differ significantly.

What are popular job titles related to Phishing Email Analyst jobs in Rochester, NY?

For Phishing Email Analyst jobs in Rochester, NY, the most frequently searched job titles are:

What job categories do people searching Phishing Email Analyst jobs in Rochester, NY look for?

The top searched job categories for Phishing Email Analyst jobs in Rochester, NY are:

What cities near Rochester, NY are hiring for Phishing Email Analyst jobs?

Cities near Rochester, NY with the most Phishing Email Analyst job openings:

Security Administrator

Genesee Regional Bank

Rochester, NY • On-site

Full-time

Posted 8 days ago


Job description

SALRY RANGE: $93,500 - $105,500
PRIMARY RESPONSIBILITY:
The Security Administrator (SA) is responsible for the day-to-day execution of operational and technical activities supporting the Bank's Information Security Program. Reporting administratively to the Chief Technology Officer and operating under the functional security direction of the Bank's CISO or designated CISO advisor, the SA administers, monitors, and optimizes the Bank's core security technologies and recurring security processes. Responsibilities include security alert triage, incident response support, vulnerability management coordination, access reviews, security awareness administration, technical control configuration, evidence maintenance, reporting, and remediation tracking. The SA executes established security priorities and promptly escalates material risks, incidents, policy exceptions, and control deficiencies to the CISO and appropriate management.
ESSENTIAL FUNCTIONS:
  • Manage and administer core security tools and systems, including email security, endpoint protection, identity security, and data security and compliance platforms, including data classification, information protection, and data loss prevention capabilities.
  • Monitor systems and tools to detect anomalous or malicious activity across endpoints and networks.
  • Own and resolve security related user support tickets, including reports of malware, email compromise, and other security incidents. Perform initial triage, review available logs, correlate activity, preserve relevant evidence, determine preliminary scope and severity, and promptly escalate matters in accordance with the Incident Response Plan.
  • Monitor, investigate, document, and disposition security alerts across the Bank's security platforms. Identify monitoring gaps, recurring root causes, tuning opportunities, and conditions requiring escalation.
  • Support containment, eradication, and recovery activities in coordination with the CISO, CTO, managed security providers, and other members of the Incident Response Team. Perform preliminary technical analysis and evidence collection and coordinate advanced forensic analysis with internal or external resources when required.
  • Review and coordinate tickets and alerts generated by the Bank's MDR, SOC, and other managed security providers, ensuring appropriate internal follow-up, escalation, and closure.
  • Monitor and administer controls intended to detect or prevent unauthorized data access, data exfiltration and inappropriate transmission of sensitive information.
  • Administer the access review process to ensure user access is appropriately provisioned.
  • Administer operational components of the vulnerability management program, including scan monitoring, result validation, asset and owner coordination, remediation tracking, exception documentation, and reporting. Technical system owners remain responsible for implementing assigned remediation actions.
  • Oversee phishing simulation campaigns, track results, and provide remedial training as needed. Educate and train end users via vendor-based tools, grass roots education campaigns, and bank provided self-service training.
  • Support the administration and streamlining of the bank's Privileged Access Management system, defining and maintaining roles, and developing and maintaining appropriate documentation.
  • Support the CISO-led Information Security Risk Assessment process.
  • Administer technical controls supporting the Bank's approved records-retention requirements within assigned technology platforms.
  • Support policy and procedure maintenance by documenting operational practices, technical control configurations, and implementation evidence to promote consistency and audit readiness.
  • Maintain thorough documentation, diagrams, inventories, evidence, procedures related to assigned security responsibilities.
  • Support implementation and ongoing operation of activities aligned with the Bank's Information Security Program and CISO-established priorities.
  • Work with the CTO and the IT team to implement and execute the CISO's information security roadmap to ensure an efficient and effective security posture.
  • Prepare and present Information Security related reports to management.
  • Active participation in demonstrating the behaviors outlined in the GRB Experience.

EDUCATION AND EXPERIENCE:
  • Associate's Degree in Cybersecurity, Information Technology or related field and a minimum of 5 years previous experience in Information Security Administration, Security Operations, or System Administration with a focus in Security, or the equivalent combination of education and experience.
  • Demonstrated experience administering Microsoft security and compliance technologies, including Microsoft Defender, Entra ID, Microsoft 365 security controls, and Microsoft Purview, or comparable enterprise platforms.
  • Working knowledge of the NIST Cybersecurity Framework and other relevant information security frameworks. Familiarity with FFIEC guidance, GLBA requirements, and banking regulatory expectations is preferred.
  • Experience within a regulated financial institution or similarly regulated environment is preferred.
  • Strong communication skills to explain technical security risks to end users and compliance requirements to business stakeholders.
  • Ability to multi-task and manage multiple priorities.
  • Self-starter and motivated to make improvements, learn, and evolve.

COMPETENCIES:
  • Provide a remarkable client experience. Greet clients with warmth, genuine interest and a smile.
  • Lead by example. Identify current or potential problems, take ownership and see them through to resolution.
  • Act as a unified team. Possess strong interpersonal skills including the ability to proactively communicate with and help others, within and across departments.
  • Ability to work independently. Seek and incorporate feedback on your performance from management, coworkers and clients.
  • Demonstrated proficiency with enterprise computing, security administration, and common productivity and collaboration technologies.
  • Strong verbal, written, analytical, problem-solving, and customer service skills, with the ability to communicate effectively with both technical and non-technical audiences.
  • Ability to handle highly confidential information with sensitivity, tact and discretion.
  • Ability to learn new technology and practices quickly.

PHYSICAL DEMANDS:
While performing the duties of this job, the employee is regularly required to use hands or fingers, handle, or feel and reach with hands and arms. The employee frequently is required to stand, sit, climb or balance, and talk or hear. The employee regularly is required to walk and stoop, kneel, and climb stairs. The employee must occasionally lift and/or move up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, and ability to adjust focus.
WORK ENVIRONMENT:
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. The work environment is indoor and climate controlled.
Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
Genesee Regional Bank is an equal opportunity organization. We recruit, employ, train, compensate, and promote without regard to race, religion, color, national origin, age, sex, disability, veteran status, or any other basis protected by applicable federal, state, or local law.
THIS JOB DESCRIPTION IS SUBJECT TO CHANGE AT ANY TIME.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.