1

Senior Information Security Risk Analyst Jobs in Rochester, NY

Security Administrator

Rochester, NY · On-site

$93K - $105K/yr

Support the CISO-led Information Security Risk Assessment process. * Administer technical controls ... Strong verbal, written, analytical, problem-solving, and customer service skills, with the ability ...

Senior SAP Security Analyst

Rochester, NY · On-site

$94K - $123K/yr

... Risk Compliance (GRC), SAP BusinessObjects BI (BOBJ), and Solution Manager. * Develop SAP security ... Ability to communicate complex information, concepts or ideas in a confident and well-organized ...

Senior Cyber Security Manager

Fairport, NY · On-site

$105K - $142K/yr

Reduce security risk in engineering and product operations environments * Identity & Access ... Translate group-level information security policies into practical business-unit controls ...

Senior Cyber Security Manager

Fairport, NY · On-site

$105K - $142K/yr

Reduce security risk in engineering and product operations environments * Identity & Access ... Translate group-level information security policies into practical business-unit controls ...

Senior Cyber Security Manager

Fairport, NY

$105K - $142K/yr

Reduce security risk in engineering and product operations environments * Identity & Access ... Translate group-level information security policies into practical business-unit controls ...

Showing results 21-40

Senior Information Security Risk Analyst information

See Rochester, NY salary details

$31

$57

$74

How much do senior information security risk analyst jobs pay per hour?

As of Sep 10, 2026, the average hourly pay for senior information security risk analyst in Rochester, NY is $57.67, according to ZipRecruiter salary data. Most workers in this role earn between $44.81 and $64.76 per hour, depending on experience, location, and employer.

What does a senior information security risk analyst do?

A Senior Information Security Risk Analyst is responsible for identifying, evaluating, and mitigating risks to an organization's information systems and data. They conduct risk assessments, develop security policies, and recommend measures to protect against cyber threats and vulnerabilities. Additionally, they work closely with IT and business teams to ensure compliance with regulations and industry standards, and they often play a key role in incident response and security awareness training.

What are the key skills and qualifications needed to thrive as a senior information security risk analyst?

A Senior Information Security Risk Analyst requires a deep understanding of cybersecurity frameworks, risk assessment methodologies, and regulatory compliance, usually backed by a degree in information security or a related field. Familiarity with tools like risk management software (e.g., Archer, RSA), SIEM systems, and certifications such as CISSP, CISM, or CRISC are typically expected. Exceptional analytical thinking, attention to detail, and strong communication skills set top performers apart in this role. These competencies are crucial to effectively identify, evaluate, and mitigate security risks, ensuring the organization's information assets remain protected against evolving threats.

How does a senior information security risk analyst typically collaborate with other departments to manage organizational risk?

A Senior Information Security Risk Analyst regularly works with various departments such as IT, legal, compliance, and business units to identify and address security risks. This collaboration often includes conducting risk assessments, reviewing new projects for potential vulnerabilities, and providing guidance on security best practices. Effective communication skills are essential, as the analyst must translate technical risks into business impacts and help teams implement appropriate controls. Close teamwork ensures that security is integrated into all business processes and that the organization remains compliant with relevant regulations.

What is the difference between Senior Information Security Risk Analyst vs Information Security Analyst?

AspectSenior Information Security Risk AnalystInformation Security Analyst
CertificationsCISSP, CISA, CRISCCISSP, Security+, CEH
Work EnvironmentFocus on risk assessment, policy development, and strategic planningImplementing security measures, monitoring, and incident response
Employer & Industry UsageFinancial, healthcare, and large enterprises with complex security needsVariety of industries, including tech, retail, and government

Senior Information Security Risk Analysts typically handle advanced risk assessments and strategic security planning, often requiring certifications like CISSP or CISA. Information Security Analysts focus on implementing security controls and monitoring systems. Both roles are vital in maintaining organizational security but differ in scope and seniority.

What are popular job titles related to Senior Information Security Risk Analyst jobs in Rochester, NY?

For Senior Information Security Risk Analyst jobs in Rochester, NY, the most frequently searched job titles are:

What job categories do people searching Senior Information Security Risk Analyst jobs in Rochester, NY look for?

The top searched job categories for Senior Information Security Risk Analyst jobs in Rochester, NY are:

What cities near Rochester, NY are hiring for Senior Information Security Risk Analyst jobs?

Cities near Rochester, NY with the most Senior Information Security Risk Analyst job openings:

Infographic showing various Senior Information Security Risk Analyst job openings in Rochester, NY as of August 2026, with employment types broken down into 1% As Needed, 74% Full Time, 22% Part Time, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $119,956 per year, or $57.7 per hour.

Security Administrator

Rochester, NY • On-site

Genesee Regional Bank
Commercial Banking • 51 - 200 employees

Full-time

Re-posted 8 hours ago


Key responsibilities

  • Administer, monitor, and optimize the Bank's core security technologies and recurring security processes.

  • Monitor systems and tools to detect anomalous or malicious activity and support incident response activities.

  • Manage security alerts, coordinate vulnerability management, review access, and support security policy and procedure maintenance.


Job description

SALRY RANGE: $93,500 - $105,500
PRIMARY RESPONSIBILITY:
The Security Administrator (SA) is responsible for the day-to-day execution of operational and technical activities supporting the Bank's Information Security Program. Reporting administratively to the Chief Technology Officer and operating under the functional security direction of the Bank's CISO or designated CISO advisor, the SA administers, monitors, and optimizes the Bank's core security technologies and recurring security processes. Responsibilities include security alert triage, incident response support, vulnerability management coordination, access reviews, security awareness administration, technical control configuration, evidence maintenance, reporting, and remediation tracking. The SA executes established security priorities and promptly escalates material risks, incidents, policy exceptions, and control deficiencies to the CISO and appropriate management.
ESSENTIAL FUNCTIONS:
  • Manage and administer core security tools and systems, including email security, endpoint protection, identity security, and data security and compliance platforms, including data classification, information protection, and data loss prevention capabilities.
  • Monitor systems and tools to detect anomalous or malicious activity across endpoints and networks.
  • Own and resolve security related user support tickets, including reports of malware, email compromise, and other security incidents. Perform initial triage, review available logs, correlate activity, preserve relevant evidence, determine preliminary scope and severity, and promptly escalate matters in accordance with the Incident Response Plan.
  • Monitor, investigate, document, and disposition security alerts across the Bank's security platforms. Identify monitoring gaps, recurring root causes, tuning opportunities, and conditions requiring escalation.
  • Support containment, eradication, and recovery activities in coordination with the CISO, CTO, managed security providers, and other members of the Incident Response Team. Perform preliminary technical analysis and evidence collection and coordinate advanced forensic analysis with internal or external resources when required.
  • Review and coordinate tickets and alerts generated by the Bank's MDR, SOC, and other managed security providers, ensuring appropriate internal follow-up, escalation, and closure.
  • Monitor and administer controls intended to detect or prevent unauthorized data access, data exfiltration and inappropriate transmission of sensitive information.
  • Administer the access review process to ensure user access is appropriately provisioned.
  • Administer operational components of the vulnerability management program, including scan monitoring, result validation, asset and owner coordination, remediation tracking, exception documentation, and reporting. Technical system owners remain responsible for implementing assigned remediation actions.
  • Oversee phishing simulation campaigns, track results, and provide remedial training as needed. Educate and train end users via vendor-based tools, grass roots education campaigns, and bank provided self-service training.
  • Support the administration and streamlining of the bank's Privileged Access Management system, defining and maintaining roles, and developing and maintaining appropriate documentation.
  • Support the CISO-led Information Security Risk Assessment process.
  • Administer technical controls supporting the Bank's approved records-retention requirements within assigned technology platforms.
  • Support policy and procedure maintenance by documenting operational practices, technical control configurations, and implementation evidence to promote consistency and audit readiness.
  • Maintain thorough documentation, diagrams, inventories, evidence, procedures related to assigned security responsibilities.
  • Support implementation and ongoing operation of activities aligned with the Bank's Information Security Program and CISO-established priorities.
  • Work with the CTO and the IT team to implement and execute the CISO's information security roadmap to ensure an efficient and effective security posture.
  • Prepare and present Information Security related reports to management.
  • Active participation in demonstrating the behaviors outlined in the GRB Experience.

EDUCATION AND EXPERIENCE:
  • Associate's Degree in Cybersecurity, Information Technology or related field and a minimum of 5 years previous experience in Information Security Administration, Security Operations, or System Administration with a focus in Security, or the equivalent combination of education and experience.
  • Demonstrated experience administering Microsoft security and compliance technologies, including Microsoft Defender, Entra ID, Microsoft 365 security controls, and Microsoft Purview, or comparable enterprise platforms.
  • Working knowledge of the NIST Cybersecurity Framework and other relevant information security frameworks. Familiarity with FFIEC guidance, GLBA requirements, and banking regulatory expectations is preferred.
  • Experience within a regulated financial institution or similarly regulated environment is preferred.
  • Strong communication skills to explain technical security risks to end users and compliance requirements to business stakeholders.
  • Ability to multi-task and manage multiple priorities.
  • Self-starter and motivated to make improvements, learn, and evolve.

COMPETENCIES:
  • Provide a remarkable client experience. Greet clients with warmth, genuine interest and a smile.
  • Lead by example. Identify current or potential problems, take ownership and see them through to resolution.
  • Act as a unified team. Possess strong interpersonal skills including the ability to proactively communicate with and help others, within and across departments.
  • Ability to work independently. Seek and incorporate feedback on your performance from management, coworkers and clients.
  • Demonstrated proficiency with enterprise computing, security administration, and common productivity and collaboration technologies.
  • Strong verbal, written, analytical, problem-solving, and customer service skills, with the ability to communicate effectively with both technical and non-technical audiences.
  • Ability to handle highly confidential information with sensitivity, tact and discretion.
  • Ability to learn new technology and practices quickly.

PHYSICAL DEMANDS:
While performing the duties of this job, the employee is regularly required to use hands or fingers, handle, or feel and reach with hands and arms. The employee frequently is required to stand, sit, climb or balance, and talk or hear. The employee regularly is required to walk and stoop, kneel, and climb stairs. The employee must occasionally lift and/or move up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, and ability to adjust focus.
WORK ENVIRONMENT:
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. The work environment is indoor and climate controlled.
Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
Genesee Regional Bank is an equal opportunity organization. We recruit, employ, train, compensate, and promote without regard to race, religion, color, national origin, age, sex, disability, veteran status, or any other basis protected by applicable federal, state, or local law.
THIS JOB DESCRIPTION IS SUBJECT TO CHANGE AT ANY TIME.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.