1

Sr Risk And Vulnerability Analyst Jobs in New York

* A Vulnerability Analyst II with a data focus is responsible for improving the quality, consistency ... A solid understanding of vulnerability management tools, security concepts, and risk-based ...

Senior Risk Analyst

Newark, NJ · On-site

$135 - $165/hr

Role Overview The Senior Risk Analyst role is critical in protecting the business from fraud and financial loss by proactively monitoring transaction trends, flagging suspicious behavior, and ...

The Senior Risk Analyst role is critical in protecting the business from fraud and financial loss by proactively monitoring transaction trends, flagging suspicious behavior, and contributing to the ...

The Senior Risk Analyst role is critical in protecting the business from fraud and financial loss by proactively monitoring transaction trends, flagging suspicious behavior, and contributing to the ...

The Senior Risk Analyst will help to shape the risk management function for the U.S. Exchange business, working directly with trading, product, legal, and operations to stand up governance ...

Senior Risk Analyst

Newark, NJ · On-site

$70 - $110/hr

Analyze large sets of data to identify risk trends, including chargebacks, returns, and unusual volume spikes. * Create and refine rules, alerts, and reports in risk monitoring tools to flag ...

The Senior, Risk Advisory Services is responsible for providing risk consulting and issues ... Obtains information, documents and data from clients to support the completion of analysis and ...

The Senior, Risk Advisory Services is responsible for providing risk consulting and issues ... Obtains information, documents and data from clients to support the completion of analysis and ...

This senior individual contributor role sits at the intersection of risk management, statistical ... analytics, and new data sources. * Connect risk, vulnerability, asset, GRC, and engineering ...

Cyber Risk Lead

Manhattan, NY · On-site

$180 - $210/hr

This senior individual contributor role sits at the intersection of risk management, statistical ... analytics, and new data sources. * Connect risk, vulnerability, asset, GRC, and engineering ...

Portfolio Analysis * Limit Recommendations * Client Margining * Risk Monitoring * Limit Overshoot ... Risk Limits: * Proposes new limits and / or renewals on upcoming expired limits to MARK senior ...

next page

Showing results 1-20

Sr Risk And Vulnerability Analyst information

What does a Sr Risk and Vulnerability Analyst do?

A Sr Risk and Vulnerability Analyst is responsible for identifying, assessing, and mitigating risks and vulnerabilities within an organization’s information systems and processes. They conduct security assessments, analyze potential threats, and recommend strategies to protect assets and data. Their role often involves collaborating with IT, compliance, and management teams to develop risk management policies and respond to emerging security issues. Additionally, they may lead vulnerability testing and ensure the organization meets regulatory and industry standards for cybersecurity.

What are the key skills and qualifications needed to thrive as a Sr Risk and Vulnerability Analyst, and why are they important?

To thrive as a Sr Risk and Vulnerability Analyst, you need in-depth knowledge of cybersecurity principles, risk assessment methodologies, and a relevant degree or certifications such as CISSP or CEH. Proficiency with vulnerability scanning tools (e.g., Nessus, Qualys), SIEM systems, and risk management frameworks (like NIST or ISO 27001) is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you interpret complex data and collaborate across teams. These competencies are vital for identifying threats, reducing organizational risk, and ensuring robust security defenses.

What are some common challenges faced by a Sr Risk and Vulnerability Analyst, and how can they be addressed?

Sr Risk and Vulnerability Analysts often encounter challenges such as staying updated with rapidly evolving threats, managing a large volume of vulnerabilities, and effectively communicating risks to non-technical stakeholders. Addressing these challenges involves continuous learning, leveraging automated tools for vulnerability management, and developing strong reporting and presentation skills to translate technical findings into actionable business insights. Collaboration with IT, security teams, and business leaders is essential to prioritize and remediate risks efficiently.

What is the difference between Sr Risk And Vulnerability Analyst vs Risk Analyst?

AspectSr Risk And Vulnerability AnalystRisk Analyst
CertificationsCertifications like CISSP, CISA often preferredSimilar certifications, often entry to mid-level
Work EnvironmentFocus on cybersecurity vulnerabilities and risk management in ITBroader risk assessment across financial, operational, or strategic areas
Employer & Industry UsageCommon in cybersecurity, IT, finance sectorsUsed across various industries including finance, insurance, and consulting

The Sr Risk And Vulnerability Analyst specializes in identifying and mitigating cybersecurity vulnerabilities, often requiring advanced certifications and experience. In contrast, a Risk Analyst has a broader scope, assessing risks across multiple business areas. Both roles require analytical skills but differ in focus and industry application.

What job categories do people searching Sr Risk And Vulnerability Analyst jobs in New York look for?

The top searched job categories for Sr Risk And Vulnerability Analyst jobs in New York are:

What cities in New York are hiring for Sr Risk And Vulnerability Analyst jobs?

Cities in New York with the most Sr Risk And Vulnerability Analyst job openings:

Infographic showing various Sr Risk And Vulnerability Analyst job openings in New York as of August 2026, with employment types broken down into 57% Full Time, and 43% Contract. Highlights an 100% In-person job distribution.

Threat & Vulnerability Analyst

Newark, NJ • On-site, Remote


Horizon Blue Cross Blue Shield of New Jersey
Insurance Services • 5 - 10K employees

8.3

Company rating: 8.3 out of 10

Based on 23 frontline employees who took The Breakroom Quiz

133rd of 315 rated insurance

People enjoy working here

Good employer

Paid breaks


Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 23 days ago


Job description

Horizon Blue Cross Blue Shield of New Jersey empowers our members to achieve their best health. For over 90 years, we have been New Jersey's health solutions leader driving innovations that improve health care quality, affordability, and member experience. Our members are our neighbors, our friends, and our families. It is this understanding that drives us to better serve and care for the 3.5 million people who place their trust in us. We pride ourselves on our best-in-class employees and strive to maintain an innovative and inclusive environment that allows them to thrive. When our employees bring their best and succeed, the Company succeeds.

About the Role

This role works closely with the Enterprise Business and Technology Solutions (EBTS) Division to develop, implement, and enhance processes that identify, assess, and remediate vulnerabilities across Horizon's technology environment. The analyst is responsible for performing internal and external vulnerability assessments, managing vulnerability scanning programs, establishing security standards, and evaluating exceptions and false-positive findings.
The position plays a key role in reducing organizational risk by partnering with technology teams to prioritize and remediate vulnerabilities, developing long-term security solutions, and supporting threat intelligence and threat hunting initiatives. The incumbent will stay current on emerging threats, industry standards, and security trends, providing regular updates and recommendations to leadership regarding risks requiring remediation.

What You'll Do

  • Develop and enhance vulnerability scanning strategies to ensure comprehensive coverage across Horizon's enterprise environment.

  • Conduct internal and external vulnerability assessments and validate scan results.

  • Apply established vulnerability management standards to classify vulnerabilities based on severity, exploitability, and business risk.

  • Categorize and prioritize assets according to criticality and organizational impact.

  • Partner with EBTS teams to develop and execute vulnerability remediation plans in accordance with established service level agreements (SLAs).

  • Track and report remediation activities to ensure timely resolution of identified vulnerabilities.

  • Analyze emerging cyber threats and assess potential impacts to Horizon's technology environment.

  • Communicate current risk exposure, remediation efforts, and security recommendations to senior leadership and key stakeholders.

  • Develop, maintain, and present weekly and monthly vulnerability management metrics and executive reports.

  • Create, update, and maintain policies, standards, procedures, and process documentation related to vulnerability management and threat intelligence operations.

  • Ensure security controls, policies, and standards are operating effectively to satisfy audit and regulatory requirements.

  • Assist in the development and maturation of a threat hunting program by documenting threat scenarios, response playbooks, and use cases.

  • Collaborate with internal teams to investigate, validate, and resolve vulnerability findings, false positives, and remediation exceptions.

  • Support continuous improvement initiatives aimed at strengthening the organization's overall cybersecurity posture

What You Bring

Education/Experience:

  • High School Diploma or GED required.

  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field preferred.

  • Relevant experience may be considered in lieu of a degree.

Experience:
  • Minimum of five (5) years of Information Security experience required.

  • At least three (3) years of experience focused on vulnerability identification, assessment, and remediation.

  • Experience working within a large enterprise environment preferred.

  • Experience supporting security audits, regulatory compliance reviews, and risk management programs preferred.

Certifications:
  • One or more of the following certifications is required or strongly preferred:

  • CISSP (Certified Information Systems Security Professional)

  • GCTI (GIAC Cyber Threat Intelligence)

  • GIAC certifications

  • CompTIA Security+

  • Certified Ethical Hacker (CEH)

Knowledge:
  • Strong understanding of cybersecurity frameworks and methodologies, including Cyber Kill Chain, Defense-in-Depth, and related security models.

  • Comprehensive knowledge of vulnerability management and patch management processes and their respective remediation approaches.

  • Deep understanding of indicators of compromise (IOCs), advanced persistent threats (APTs), cybercrime techniques, and attacker tactics, techniques, and procedures (TTPs).

  • Knowledge of operating systems including Windows, Linux/Unix, and macOS.

  • Experience with vulnerability management platforms such as Nessus, Qualys, InsightVM (Nexpose), or similar solutions.

  • Knowledge of Center for Internet Security (CIS) benchmarks and Critical Security Controls.

  • Familiarity with threat intelligence platforms and sources such as Recorded Future, ThreatConnect/ThreatStream, H-ISAC, NJCCIC, and similar resources.

  • Understanding of audit, regulatory, and compliance requirements related to cybersecurity programs.

Skills & Abilities:
  • Proven ability to prioritize vulnerabilities and systems based on risk, asset criticality, and business impact.

  • Experience utilizing CVSS scoring and risk-based vulnerability management methodologies.

  • Strong analytical, investigative, and problem-solving skills.

  • Excellent verbal and written communication skills, including the ability to present technical information to both technical and non-technical audiences.

  • Experience creating executive-level dashboards, scorecards, and presentations using tools such as Microsoft PowerPoint, Visio, and Excel.

  • Experience developing and documenting security processes, standards, and procedures.

  • Ability to facilitate cross-functional collaboration and drive vulnerability remediation efforts across multiple teams.

  • Experience negotiating remediation plans, exception requests, SLA extensions, and false-positive determinations.

  • Strong project management, organizational, and time-management skills.

  • Ability to manage multiple priorities in a fast-paced environment.

  • Demonstrated attention to detail and commitment to operational excellence.

  • Self-motivated and capable of working independently while maintaining effective communication with stakeholders.

  • Strong interpersonal skills with the ability to build partnerships and influence outcomes across the organization.

Why Horizon?

At Horizon, you'll do meaningful work that directly improves lives-while being supported by a missiondriven organization that values expertise, collaboration, and growth. We believe that when our people thrive, our communities do too. If you are passionate about making an impact, we'd love to hear from you!

Salary Range:

$97,800 - $133,455

This compensation range is specific to the job level and takes into account the wide range of factors that are considered in making compensation decisions, including but not limited to: education, experience, licensure, certifications, geographic location, and internal equity. This range has been created in good faith based on information known to Horizon at the time of posting. Compensation decisions are dependent on the circumstances of each case. Horizon also provides a comprehensive compensation and benefits package which includes:

  • Comprehensive health benefits (Medical/Dental/Vision)

  • Retirement Plans

  • Generous PTO

  • Incentive Plans

  • Wellness Programs

  • Paid Volunteer Time Off

  • Tuition Reimbursement

Disclaimer:

Horizon BCBSNJ employees must live in New Jersey, New York, Pennsylvania, Connecticut or Delaware. This job summary has been designed to indicate the general nature and level of work performed by colleagues within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of colleagues assigned to this job.

Horizon Blue Cross Blue Shield of New Jersey is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, protected veteran status or status as an individual with a disability and any other protected class as required by federal, state or local law. Horizon will consider reasonable accommodation requests as part of the recruiting and hiring process.



What Horizon Blue Cross Blue Shield of New Jersey employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom