1

Security Risk Assessment Jobs in New York (NOW HIRING)

You'll lead and conduct vendor security risk assessments end to end - integrate AI to improve accuracy, evaluate control effectiveness, quantify risk to the business, and partner with risk owners to ...

You'll lead and conduct vendor security risk assessments end to end - integrate AI to improve accuracy, evaluate control effectiveness, quantify risk to the business, and partner with risk owners to ...

Conduct security risk assessments and develop mitigation strategies. * Provide training and documentation on Workday security policies. MANDATORY SKILLS/EXPERIENCE Note: Candidates who do not have ...

Conduct security risk assessments and develop mitigation strategies. * Provide training and documentation on Workday security policies. MANDATORY SKILLS/EXPERIENCE Note: Candidates who do not have ...

Strong risk assessment and analytical skills * Technical understanding of enterprise security architecture * Excellent communication and stakeholder management skills * Proven ability to lead and ...

Strong risk assessment and analytical skills * Technical understanding of enterprise security architecture * Excellent communication and stakeholder management skills * Proven ability to lead and ...

Strong risk assessment and analytical skills * Technical understanding of enterprise security architecture * Excellent communication and stakeholder management skills * Proven ability to lead and ...

Showing results 21-40

Security Risk Assessment information

See New York salary details

$11

$55

$76

How much do security risk assessment jobs pay per hour?

As of Sep 5, 2026, the average hourly pay for security risk assessment in New York is $55.15, according to ZipRecruiter salary data. Most workers in this role earn between $44.71 and $65.77 per hour, depending on experience, location, and employer.

What is a security risk assessment?

A Security Risk Assessment job involves identifying, analyzing, and mitigating potential security threats to an organization's systems, data, and operations. Professionals in this role evaluate vulnerabilities, assess risks, and recommend security controls to protect against cyber threats, fraud, and compliance issues. They work with IT teams, management, and stakeholders to ensure security measures align with business objectives and regulatory requirements. This job often requires knowledge of cybersecurity frameworks, risk management methodologies, and relevant industry standards.

What are the key skills and qualifications needed for security risk assessment?

To thrive in Security Risk Assessment, a strong background in risk analysis, information security principles, and regulatory compliance is essential, often supported by a degree in cybersecurity or related fields. Familiarity with risk assessment tools, frameworks like NIST or ISO 27001, and certifications such as CISSP or CISA are highly valued. Exceptional attention to detail, analytical thinking, and effective communication skills set top professionals apart in this role. These competencies enable accurate identification of potential security threats and development of strategic mitigation plans, which are crucial for safeguarding organizational assets.

What are some common challenges faced in a security risk assessment role?

Professionals in Security Risk Assessment often face the challenge of keeping up with constantly evolving cyber threats and adapting assessment methodologies accordingly. Balancing thorough analysis with the need to provide timely recommendations can be demanding, especially when collaborating with multiple departments or stakeholders. Additionally, communicating complex risk findings to non-technical audiences requires both clarity and diplomacy. Overcoming these challenges is critical for delivering actionable insights that drive effective security decision-making and protect organizational assets.

What are the most commonly searched types of Security Risk Assessment jobs in New York?

The most popular types of Security Risk Assessment jobs in New York are:

What are popular job titles related to Security Risk Assessment jobs in New York?

For Security Risk Assessment jobs in New York, the most frequently searched job titles are:

What job categories do people searching Security Risk Assessment jobs in New York look for?

The top searched job categories for Security Risk Assessment jobs in New York are:

Infographic showing various Security Risk Assessment job openings in New York as of August 2026, with employment types broken down into 60% Full Time, and 40% Contract. Highlights an 100% In-person job distribution, with an average salary of $114,707 per year, or $55.1 per hour.

Information Security Risk Analyst (SOC)

SUMITOMO MITSUI TRUST BANK, LIMITED

Manhattan, NY • On-site

$90K - $125K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 15 days ago


Job description

This role is located in New York City and will require a hybrid work schedule of at least 2 days in office per week.


This role is for Officer level candidates. 



About the Bank

Sumitomo Mitsui Trust Bank, Limited was established through the merger of The Sumitomo Trust and Banking Co., Ltd with Chuo Mitsui Trust and Banking, Ltd. on April 1, 2012. We are one of the largest asset managers in Asia and number one among Japanese financial institutions by AUM, with approximately $850 Billion USD in AUM. The Bank provides an assortment of financial solutions and manages a broad spectrum of financial products across its global branches.
Department Overview:

The Americas Division (“AD”) was established in the Sumitomo Mitsui Trust Bank, Limited, New York Branch) (“SMTBNY”) to perform corporate functions and supervise U.S. entities. Established under the AD are the “Global Banking Unit (“GBU”), Americas Division” and “Global Markets Unit (“GMU”), Americas Division” which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch wide framework that is in-line with the Head Office and regulatory requirements and addresses Confidentiality, Integrity, and Availability for information assets. IRG establishes appropriate policies, procedures, measurement, and monitoring processes to proactively assess and evaluate and cyber security and information security risks inherent in the Branch Operations. IRG is directly involved in all information and cyber security related projects, matters and issues.


Your Role Overview:

The Security Operations Center (SOC) Analyst is responsible for monitoring, detecting, investigating, and responding to cybersecurity events and alerts across the organization’s technology environment. This role serves as a frontline defender within the Information Risk Governance Department, identifying potential threats, investigating suspicious activities, and supporting incident response efforts in order to protect the confidentiality, integrity, and availability of organizational assets.


Your Duties and Responsibilities:

  1. Monitor and analyze security events and alerts generated by security systems such as the Security Information and Event Management (SIEM) system, Endpoint Detection & Response (EDR) system, Firewalls, Network Access Control (NAC), Network Detection & Response (NDR) system, and Intrusion Detection and Prevention (IDS/IPS) systems. 
  2. Triage and analyze security alerts to determine severity, scope, and potential impact and business risk.
  3. Investigate suspicious system, network, and user activity, escalating potential security incidents to the Incident Response Team and Management as appropriate.
  4. Maintain awareness of the evolving cybersecurity landscape including emerging threats, attack techniques, vulnerabilities, and indicators of compromise (IoC)
  5. Conduct proactive threat-hunting activities to identify, investigate, and mitigate emerging threats, anomalous behavior, and potential indicators of compromise that may evade existing security controls.
  6. Participate as a member of the Incident Response Team during cybersecurity incidents and investigations. Tasks include documenting incident findings, actions taken, and to collect system log evidence and forensic artifacts.
  7. Maintain, administer, and tune SIEM and NDR Security tools including ongoing optimization of detection rules, use cases, dashboards, reports, and alert configurations.
  8. Liaise and coordinates with vendors, service providers, and contracts to support security operations and incident response activities.
  9. Assists with internal and external audits, regulatory examinations, and information security assessments.
  10. Assists with the evaluation, testing, and comparative analysis of security monitoring and SOC-related technologies.
  11. Serves as the subject matter expert (SME) for assigned security monitoring and detection platforms.
  12. Maintains procedures, playbooks, and documentation related to security monitoring and incident response processes.
  13. Performs other duties and responsibilities as assigned by management.


Your Qualifications:
  1. Bachelor’s degree or equivalent in Information Technology, Cybersecurity/Information Security, or a related field with 3+ years of experience. 
  2. Minimum of three (3) years of experience in cybersecurity, security operations, or a related technical field.
  3. Strong understanding of security principles, frameworks, and best practices.
  4. Experience with security monitoring, event analysis, and threat detection technologies.
  5. Experience with incident investigation and response
  6. Excellent communication and problem solving skills
  7. Knowledge of threat intelligence concepts, frameworks, and operational use cases.
  8. Understanding of Cloud Security principles and controls.
  9. Strong knowledge of Microsoft Windows Server 2019/2022/2025 and Active Directory environments.
  10. Strong knowledge of networking protocols, architecture, and security concepts
  11. Strong understanding of firewall technologies and security controls
  12. Strong understanding and correlation skills of security logs, including Windows Event logs, Active Directory, DNS, proxy, firewall, EDR, and Cloud platform logs. 
  13. Strong knowledge and prior experience with SIEM platforms and security event correlation tools.
  14. Strong knowledge and prior experience with User and Entity Behavioral Analytics (UEBA) and behavioral analysis tools.
  15. Working knowledge of Amazon Web Services (AWS) architecture, services, and operations.
  16. Working knowledge of Linux systems would be a plus
  17. Excellent analytical, organization, and multi-tasking skills with strong attention to detail and accuracy.
  18. Prior experience in the Financial institution or banking industry would be preferred.



Why you should join SuMi Trust:SuMi Trust embraces flexible ways of working when the business and role permits. We provide employees with a hybrid working model, allowing for in-office work and work from home. Our diverse and inclusive environment along with our global presence enables us to collaborate and communicate to meet our business needs. We believe that efficient teams need truth, loyalty, and a strong sense of purpose to balance risk and their targets. We make sustainable business decisions to improve our society and the world. We believe that each person brings a unique value that drives the business though their creativity and passion.
  • The Employee Benefits package includes: Paid Time Off, medical, HSA, vision, dental, FSA, 401(k), profit sharing, legal plan, cancer indemnity plan, disability insurance, life insurance, employee assistance program, commuter benefits, business travel accident, paid volunteer day, paid memberships, paid seminars, and tuition assistance.
  • We offer many socialization opportunities for wellness, financial wellbeing, runs/walks, team building, happy hours, and activities to support the Sustainable Developmental Goals.

Check out our LinkedIn for our employee experience: https://www.linkedin.com/company/smtbny



We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, disability status, protected veteran status or any other characteristic protected by law. SuMi Trust provides reasonable accommodations for employees and applicants with disabilities consistent with applicable law. If you need a reasonable accommodation during the application