1

Security Analyst Jobs in Commack, NY (NOW HIRING)

IGA Analyst

New York, NY · On-site

$65 - $70/hr

Job Title : IT Security Identity and Access Management . Duration : 12 Months Type : Hybrid . Years ... The IGA Analyst will play a critical role in strengthening the organization's identity security ...

Senior SOC Analyst

Great Neck, NY · On-site

$120 - $180/hr

Security Monitoring & Incident Response * Monitor, triage, and investigate security alerts across ... Analyze and prioritize vulnerabilities using CVSS scores, threat intelligence, and asset ...

Sr Lead SAP Security & Audit

New York, NY · On-site +1

$144K - $192K/yr

The Senior SAP Security Analyst will play a critical role in managing the software development lifecycle of SAP Security at Curtiss-Wright. This position requires expertise in SAP Security, risk, and ...

GRC Analyst

New York, NY · On-site

$150K - $200K/yr

The Role Rogo is hiring a GRC Analyst to support our customer trust, security assurance, and ... You will work closely with security, engineering, legal, and go-to-market teams to ensure Rogo ...

About the job Juni or Data Analyst (Remote) As the Data Analyst for the Security Analytics & Innovation team you will help in the development, deployment and administration of Analytical Products as ...

Showing results 41-60

Security Analyst information

See Commack, NY salary details

$40.9K

$111.1K

$146K

How much do security analyst jobs pay per year?

As of Sep 4, 2026, the average yearly pay for security analyst in Commack, NY is $111,149.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,800.00 and $134,600.00 per year, depending on experience, location, and employer.

What is a security analyst?

Security Analysts are professionals responsible for protecting an organization’s computer systems and networks from cyber threats. They monitor networks for security breaches, investigate suspicious activities, and implement security measures to prevent future attacks. Security Analysts also conduct vulnerability assessments, respond to incidents, and ensure compliance with security policies and regulations. Their work helps safeguard sensitive data and maintain the integrity of information systems.

What do security analysts do?

Security analysts evaluate information systems and recommend security measures and protocols to protect a company’s sensitive data from security threats. Security administrators implement their recommendations and put suggested protocols into action. As a security analyst, your job duties include monitoring security access, performing audits of internal and external network security programs, analyzing breaches to inform future security system measures, and training colleagues in security awareness and proper procedures. You also collaborate with outside vendors on security plans, which may include website applications, container, or cloud-based solutions.

What are the key skills and qualifications needed to thrive as a security analyst, and why are they important?

To thrive as a Security Analyst, you need a solid understanding of cybersecurity principles, risk assessment, and network security, often backed by a degree in computer science or a related field. Familiarity with tools like SIEM platforms, intrusion detection systems, and certifications such as CompTIA Security+ or CISSP are commonly required. Analytical thinking, attention to detail, and strong problem-solving abilities help Security Analysts excel in identifying vulnerabilities and responding to threats. These skills are crucial for protecting organizational assets, ensuring compliance, and maintaining a robust security posture.

What are some common challenges security analysts face when responding to security incidents, and how can they effectively manage these situations?

Security Analysts often encounter challenges such as rapidly evolving threats, the need to analyze large volumes of data, and coordinating responses across different teams. Responding quickly while accurately diagnosing incidents requires excellent technical skills and clear communication. To manage these situations effectively, successful analysts prioritize continuous learning, use automation tools to streamline repetitive tasks, and establish well-defined incident response procedures. Collaborating with IT, legal, and management teams is also crucial for a coordinated and effective response.

What is the difference between Security Analyst vs Network Security Analyst?

AspectSecurity AnalystNetwork Security Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, Cisco CCNA Security
Work EnvironmentIT security teams, cybersecurity firms, corporate securityNetwork operations centers, IT departments, cybersecurity teams
ResponsibilitiesMonitor security systems, analyze threats, implement security measuresSecure network infrastructure, monitor network traffic, prevent intrusions

Security Analysts focus on overall cybersecurity, including threat detection and incident response, while Network Security Analysts specialize in protecting network infrastructure and traffic. Both roles require similar certifications and often work in overlapping environments, but their core responsibilities differ in scope and focus.

What does a security analyst actually do?

A security analyst monitors and protects an organization’s computer systems and networks from cyber threats. They analyze security data, respond to incidents, implement security measures, and often use tools like intrusion detection systems and firewalls. Certifications such as CISSP or CompTIA Security+ can enhance their effectiveness in this role.

What qualifications do I need to be a security analyst?

A security analyst typically needs a bachelor's degree in cybersecurity, computer science, or a related field. Relevant skills include knowledge of network security, threat detection, and experience with security tools and protocols; certifications like CompTIA Security+ or CISSP can enhance job prospects.

What cities near Commack, NY are hiring for Security Analyst jobs?

Cities near Commack, NY with the most Security Analyst job openings:

Infographic showing various Security Analyst job openings in Commack, NY as of August 2026, with employment types broken down into 80% Full Time, 18% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $111,149 per year, or $53.4 per hour.

IGA Analyst

Crox Consulting Inc

New York, NY • On-site

$65 - $70/hr

Contractor

Re-posted 18 days ago


Job description

Job Title : IT Security Identity and Access Management .

Duration : 12 Months

Type : Hybrid .

Years of Experience : Tier -3 , 7 ~ 9 yrs .

GENERAL INFORMATION :

**PLEASE NOTE THIS POSITION WILL ALLOW CONSULTANT TO WORK A HYBRID REMOTE SCHEDULE.
UPON START DATE CONSULTANT WILL BE REQUIRED TO WORK FIRST MONTH FULLY ONSITE. ONCE WORK CAPABILITY IS ESTABLISHED, CONSULTANT WILL BE ALLOWED TO WORK A HYBRID REMOTE SCHEDULE CONSISTING OF 3 DAYS ONSITE/ 2 DAYS REMOTE. ASLO HOURS PER WEEK IS 37.5 NO OVERTIME**
Overview: The IGA Analyst will play a critical role in strengthening the organization’s identity security posture across corporate, frontline, and operational technology (OT) environments. This role will focus on onboarding applications into the enterprise IGA platform, modernizing authentication through FIDO2 and passwordless technologies, and reducing technical debt through effective governance and lifecycle management controls.
The ideal candidate has hands-on experience with major IGA, PAM, and MFA platforms, possesses a strong understanding of Active Directory and Entra ID, and can collaborate with cross-functional teams to implement scalable identity controls that align with Zero Trust principles.

KEY RESPONSIBILITIES
**Application Onboarding & Integration**
* Partner with application owners to onboard and certify applications within the IGA platform (e.g., SailPoint, Saviynt, or Oracle).
* Define and enforce access models, entitlements, and approval workflows for new and existing applications.
* Establish least-privilege and segregation-of-duties (SoD) controls within IGA.
**Identity Security Posture & Technical Debt Reduction**
* Identify and remediate identity risks such as orphaned accounts, excessive entitlements, and privileged access sprawl.
* Contribute to ongoing cleanup initiatives for AD, Entra ID, and connected systems to align with modern identity hygiene standards.
* Support implementation of risk-based access policies and automated lifecycle management processes.

**Authentication Modernization**
* Support the adoption of phishing-resistant authentication methods, including FIDO2 security keys and passwordless sign-ins.
* Collaborate with MFA and SSO platform teams to migrate legacy authentication flows to modern protocols (e.g., WebAuthn, OIDC, SAML).
* Evaluate user experience, security impact, and deployment readiness across diverse user populations (corporate, frontline, OT).
**Federation & Access Management**
* Configure and manage federated SSO integrations via Entra ID and other IdPs.
* Apply conditional access and adaptive authentication policies based on user risk, device health, and context.
* Coordinate with PAM teams to align privileged session management with federated access controls.
**Cross-Domain Collaboration**
* Partner with security architecture, IAM engineering, and compliance teams to ensure IGA controls meet enterprise and regulatory standards.
* Document and report on metrics related to access certifications, compliance posture, and identity lifecycle performance.
* Provide operational support for IGA platform maintenance, upgrades, and new integrations.

QUALIFICATIONS
* Bachelor’s degree in Information Security, Computer Science, or related field (or equivalent experience).
* 3–5 years of hands-on experience in Identity Governance & Administration (IGA).
* Strong knowledge of Active Directory, Entra ID, and federated authentication protocols (SAML, OIDC, OAuth2).
* Familiarity with one or more of the following platforms:

IGA: SailPoint, Saviynt, Oracle IDCS
PAM: BeyondTrust, CyberArk, ManageEngine PAM360
MFA/SSO: Microsoft Entra ID, Duo, Okta, Ping Identity
Working knowledge of Zero Trust, FIDO2, passwordless, and phishing-resistant MFA concepts.
Experience applying IGA controls for diverse user types (corporate, frontline, OT).
Strong analytical, documentation, and communication skills; ability to collaborate across technical and business teams.

ADDITIONAL SKILLS AND INFORMATION :

Experience with identity lifecycle automation and role-based access control (RBAC) modeling.
Understanding of privilege escalation risks, identity threat detection, and compliance frameworks (NIST 800-63B, CIS, TSA, etc.).
Scripting knowledge (PowerShell, Python, or SQL) for data analysis or automation.
Familiarity with cloud identity models (Azure, AWS, GCP).