1

Sr Risk And Vulnerability Analyst Jobs in Rochester, NY

Collaborate with senior management: Manage key risks, provide analysis, and highlight risk exposures and performance metrics. Also coordinate cross-functionally with business units to refine risk ...

Collaborate with senior management: Manage key risks, provide analysis, and highlight risk exposures and performance metrics. Also coordinate cross-functionally with business units to refine risk ...

Manage the ongoing credit risk of existing loan portfolios through continuous credit monitoring ... Analyze financial information and related materials and complete the credit analyses for the Bank ...

Manage the ongoing credit risk of existing loan portfolios through continuous credit monitoring ... Analyze financial information and related materials and complete the credit analyses for the Bank ...

Manage the ongoing credit risk of existing loan portfolios through continuous credit monitoring ... Analyze financial information and related materials and complete the credit analyses for the Bank ...

Senior Regional Demand Manager

Victor, NY · On-site

$118K - $169K/yr

The Senior Regional Demand Manager role is responsible for working collaboratively and in lockstep ... Excellent analytical and problem-solving skills. * Excellent written and oral communication skills.

next page

Showing results 1-20

Sr Risk And Vulnerability Analyst information

See Rochester, NY salary details

$52.8K

$108.4K

$140.6K

How much do sr risk and vulnerability analyst jobs pay per year?

As of Aug 6, 2026, the average yearly pay for sr risk and vulnerability analyst in Rochester, NY is $108,382.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,300.00 and $135,200.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Sr Risk and Vulnerability Analyst, and why are they important?

To thrive as a Sr Risk and Vulnerability Analyst, you need in-depth knowledge of cybersecurity principles, risk assessment methodologies, and a relevant degree or certifications such as CISSP or CEH. Proficiency with vulnerability scanning tools (e.g., Nessus, Qualys), SIEM systems, and risk management frameworks (like NIST or ISO 27001) is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you interpret complex data and collaborate across teams. These competencies are vital for identifying threats, reducing organizational risk, and ensuring robust security defenses.

What are some common challenges faced by a Sr Risk and Vulnerability Analyst, and how can they be addressed?

Sr Risk and Vulnerability Analysts often encounter challenges such as staying updated with rapidly evolving threats, managing a large volume of vulnerabilities, and effectively communicating risks to non-technical stakeholders. Addressing these challenges involves continuous learning, leveraging automated tools for vulnerability management, and developing strong reporting and presentation skills to translate technical findings into actionable business insights. Collaboration with IT, security teams, and business leaders is essential to prioritize and remediate risks efficiently.

What is the difference between Sr Risk And Vulnerability Analyst vs Risk Analyst?

AspectSr Risk And Vulnerability AnalystRisk Analyst
CertificationsCertifications like CISSP, CISA often preferredSimilar certifications, often entry to mid-level
Work EnvironmentFocus on cybersecurity vulnerabilities and risk management in ITBroader risk assessment across financial, operational, or strategic areas
Employer & Industry UsageCommon in cybersecurity, IT, finance sectorsUsed across various industries including finance, insurance, and consulting

The Sr Risk And Vulnerability Analyst specializes in identifying and mitigating cybersecurity vulnerabilities, often requiring advanced certifications and experience. In contrast, a Risk Analyst has a broader scope, assessing risks across multiple business areas. Both roles require analytical skills but differ in focus and industry application.

What does a Sr Risk and Vulnerability Analyst do?

A Sr Risk and Vulnerability Analyst is responsible for identifying, assessing, and mitigating risks and vulnerabilities within an organization’s information systems and processes. They conduct security assessments, analyze potential threats, and recommend strategies to protect assets and data. Their role often involves collaborating with IT, compliance, and management teams to develop risk management policies and respond to emerging security issues. Additionally, they may lead vulnerability testing and ensure the organization meets regulatory and industry standards for cybersecurity.
What are popular job titles related to Sr Risk And Vulnerability Analyst jobs in Rochester, NY? For Sr Risk And Vulnerability Analyst jobs in Rochester, NY, the most frequently searched job titles are:
What job categories do people searching Sr Risk And Vulnerability Analyst jobs in Rochester, NY look for? The top searched job categories for Sr Risk And Vulnerability Analyst jobs in Rochester, NY are:
What cities near Rochester, NY are hiring for Sr Risk And Vulnerability Analyst jobs? Cities near Rochester, NY with the most Sr Risk And Vulnerability Analyst job openings:
Infographic showing various Sr Risk And Vulnerability Analyst job openings in Rochester, NY as of July 2026, with employment types broken down into 1% Locum Tenens, 1% Internship, 82% Full Time, 11% Part Time, 1% Temporary, and 4% Contract. Highlights an 81% Physical, 5% Hybrid, and 14% Remote job distribution, with an average salary of $108,382 per year, or $52.1 per hour.

Senior Specialist, Information Security Systems Engineer

L3HHCM20

Rochester, NY

$92K - $171K/yr

Full-time

Medical, Retirement, PTO

Re-posted 14 days ago


Job description

Job Title: Information Security Systems Engineer
Job Code: 40374
Job Location: Rochester, New York
Job Schedule: 9/80 (Every Other Friday Off)
Job Description:  
The successful candidate will support a highly motivated engineering team in defining, designing, implementing, documenting, testing and sustaining security solutions on National Security Systems, or other systems engineered for our government customers, using current standards within National Institute of Standards & Technology (NIST) Risk Management Framework, Special Publications 800-37, 800-53, 800-171, and other NIST publications; Committee on National Security Systems Instruction (CNNSI) 1253, Joint SAP Implementation Guide (JSIG), and Federal Information Processing Standards (FIPS) to certify and achieve system accreditations. The successful candidate will work with system developers or commercial product vendors in the design and evaluation of state-of-the-art secure systems, networks, and database products, using methods such as encryption technology, vulnerability analysis and security management.

Essential Functions:
   Exercise skills in NIST Risk Management Framework (RMF) and all related NIST publications, to include writing System Security Plans, Security Control Traceability Matrix, Continuous Monitoring Plan, Security Assessment Plans & Procedures, Security Concept of Operations, Plan of Action and Milestones.
   Perform skills in implementing/assessing security controls, to include writing system security categorization memorandum, recommending appropriate security control overlays, define security control baseline based on defined system security categorization and approved security overlays, and apply security controls to computing/network nodes and verify implementation of security controls.
   Assist in systems/software engineering functions, to include creation of data flow diagrams, interface control documents, perform trade studies, and Static Application Security Testing (SAST) for Application Security and Development Secure Technical Implementation Guide (STIG) compliance using tools such as Fortify/Coverity and Gitlab as part of a DevSecOps Continuous Integration/Continuous Deployment (CI/CD) Pipeline, and generation of summary reports.
   Define/manage systems/security architectures including system security boundaries, vulnerability management and risk mitigation and remediation strategies within networks, systems, applications and new technology initiatives (hardware, software, firewalls, intrusion detection systems, anti-virus systems and software deployment tools); Infrastructure/Platform/Software as a Service (IaaS, PaaS, SaaS) implementations in cloud environments and development of Configuration Management Plans (CMP).
   Define/manage systems/security architectures including system security boundaries in on-premises data center systems and ultimately deploy to secure cloud-based system, to include configuration and use of defense and assessment tools specific to each environment type.
   This position is performed 100% onsite and cannot be performed remotely.

Qualifications:
   Education
o    Bachelor's Degree and minimum 6 years of prior relevant experience.
o    Graduate Degree and a minimum of 4 years of prior related experience.
o    In lieu of a degree, minimum of 10 years of prior related experience.
   Must have active TS/SCI Security Clearance.
   DoD 8140.03 IASAE Level 1 or 2 certification.

Preferred Additional Skills: 
   Perform Model Based System Engineering (UML, SysML, UAF).
   Configure/operate vulnerability analysis tools such Tenable NESSUS Security products.
   Develop dashboards, configure rules and operate/administer SEIM/audit reduction tools (e.g., Splunk).
   Active TS/SCI with poly is highly desired.

In compliance with pay transparency requirements, the salary range for this role in New York state is $92,500 - $171,500. This is not a guarantee of compensation or salary, as final offer amount may vary based on factors including but not limited to experience and geographic location. L3Harris also offers a variety of benefits, including health and disability insurance, 401(k) match, flexible spending accounts, EAP, education assistance, parental leave, paid time off, and company-paid holidays. The specific programs and options available to an employee may vary depending on date of hire, schedule type, and the applicability of collective bargaining agreements.Â