Cybersecurity Senior Risk Analyst
RIT Solutions, Inc.
Title: Cybersecurity Senior Risk Analyst
Location: Hybrid: Work location (15 MTC, 16th Floor) & Remote Tuesdays & Fridays (3 days in office/2 days remote)
The Senior Risk Analysts will be expected to continue building an effective Citywide Cybersecurity risk program. These analysts will be responsible for improving our risk assessment process to make it more user-centric, interviewing and communicating with agencies when performing risk assessments, and driving creation of a third-party vendor register and monitoring process. Analysts will review and analyze technologies for inventorying third parties, collaborate with SMEs to collect third party intelligence and define actions based on it, and design steps for reviewing existing third parties in our portfolio.
Delays in onboarding practitioners with expertise in these areas will leave unaddressed gaps in our risk governance framework. As NYC's reliance on third party vendors continues to grow it is imperative for the City to have a vendor management practice, which does not only review vendors at the front end of the procurement process but actively manages risk throughout the vendor lifecycle. According to the 2025 Telecommunication Data Breach Investigations Report, 30% of breaches were linked to third party involvement (twice as many as in 2024). Maintaining our status quo can open up the City and agencies to lawsuits or audit findings (e.g. IRS, City Comptroller). If the City sustains a substantial cyber incident that results in loss of life or significant financial losses, it is not uncommon for individuals and organizations that are negatively impacted to file lawsuits against organizations that are responsible for defending/protecting critical information and critical services. The City would not be able to defend itself as having exercised due diligence in the protection of data and services without the existence of and proper functioning of a mature cyber risk program.
Not having a user-centric risk assessment process drains resources from City agencies and the Audit & Compliance team due to questions being misunderstood. This also causes inaccuracies in submitted information, which leads to risk being misevaluated and mismanaged. MANDATORY SKILLS/EXPERIENCE
Note: Candidates who do not have the mandatory skills will not be considered
• minimum of 4 years of experience in risk management or cybersecurity risk assessment or 4 years of experience evaluating and managing third parties in a cybersecurity team.
- One or more of the following certifications are:
- Certified Information Systems Auditor (CISA)
- Certified Information Systems Security Professional (CISSP)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Security Manager (CISM)
- CompTIA Security+
- CompTIA Network+
- CompTIA A+
- CompTIA CySA+
- Cisco Certified Network Associate - CCNA
- CEH: Certified Ethical Hacker
- GIAC Information Security Fundamentals (GISF)
- GIAC Security Essentials (GSEC)
- (ISC)2 Systems Security Certified Practitioner (SSCP)
- BS/BA degree in Cybersecurity, Risk Management, Information Systems, Computer Science, or a related field.
- Ability to work effectively in a team environment.
- Being highly organized, motivated and a self-directed professional.
- Knowledge of hardware, software, data, and network principles and systems related to Private and/or Public Sectors services.
- Understanding of commonly used computer operating systems, databases, network structures.
- Familiarity with cybersecurity framework(s) (NIST, SANS, PCI, ISO 27001/27002, or CIS)
- Investigative and analytical skills.
- Excellent oral and written communication skills;
- Knowledge of the current and evolving cyber threat landscape;
- Knowledge of laws, regulations, policies, and ethics related to cybersecurity and information privacy;
• Build new risk processes and implement risk frameworks to enable better monitoring and evaluation of risks across the City;
• Manage complex, cross-functional projects, pushing through ambiguity and challenges which may arise;
• Work with stakeholders across various divisions, soliciting input and working through feedback;
• Evaluate risk of third parties used by New York City agencies;
• Document and track remediation of risks in the Risk Register;
• Review and analyze various cybersecurity risk cases, justification, and exceptions documents submitted by agencies;
• ssist in the development of cybersecurity risk assessment procedures and testing methodologies based on established frameworks and guidelines;
• Initiating corrective actions to remediate vulnerabilities or weaknesses where necessary;
• Engage in communications with NYC Agencies;
• Handle special projects and initiatives as assigned.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Cybersecurity Senior Risk Analyst in New York, NY vacancy
- ...Cybersecurity Senior Risk Analyst 1 Labor Category - Analyst 2 Work Location: Hybrid: Work location (15 MTC, 16th Floor) & Remote Tuesdays & Fridays (3 days in office/2 days remote) Scheduled Work Hours: Normal business hours Monday-Friday 35 hours/week (not including...SeniorWork at officeRemote workMonday to Friday
- ...Cybersecurity Senior Risk Analyst Location: Hybrid: Work location (15 MTC, 16th Floor) & Remote Tuesdays & Fridays (3 days in office/2 days remote) Job Description The Senior Risk Analysts will be expected to continue building an effective Citywide Cybersecurity...SeniorWork at officeRemote work
- ...Senior Analyst, Cybersecurity Governance, Risk and Compliance, New York, NY The Senior Analyst, Cybersecurity Governance Risk & Compliance will administer the completion of compliance-related client requests to assess security policies and procedures. The Senior...SeniorWork experience placement
$90k - $160k
...IT RISK & CONTROL SENIOR ANALYST WHAT IS THE OPPORTUNITY? The IT Risk Senior Analyst is a subject-area specialist with specialized training, methods and analytic techniques to create recommendations and directions for cyber risk mitigation in a complex technical environment...SeniorRemote work$95.17k - $156.36k
...Senior Analyst – Cyber Risk & Control Monitoring Do you want to be part of a collaborative Cybersecurity Governance team? Are you a problem solver who enjoys diving into security risk, translating complex technical concepts for business partners, and driving meaningful...SeniorFull timeWork at officeVisa sponsorshipWork visaFlexible hours3 days per week$80.5k - $159.3k
...our industry.Job Description:Third Party Senior StaffJob Summary:The position will be... ...for leading the effort to identify key risks and information security gaps. Projects... ...Bachelor's DegreeInformation Technology and/or Cybersecurity background and/or experience, including...SeniorLocal areaWorldwide$85k - $140k
IT Audit, Risk and Cybersecurity - Senior Associate As CohnReznick grows, so do our career opportunities. As one of the nation’s top professional... ...Development Mentor and review work performed by Consultants and Analysts. Share knowledge and best practices related to IT audit,...SeniorFor contractorsWork at officeLocal areaFlexible hours3 days per week- A leading utility provider in Pennsylvania seeks a GRC Cybersecurity Senior Analyst to ensure compliance with regulatory obligations. This role involves... ...with various departments to implement governance and risk management processes. The ideal candidate has a Bachelor’s...Senior
- Capital One is seeking a Senior Associate - Cyber Risk & Analysis in New York City to join its Tech Audit team. This role will focus on cybersecurity risks and critical technology audits, allowing for personal and professional growth in a collaborative environment. The...Senior
$150k - $185k
...Actuary / Senior Actuary New York, New York, United States... ...help businesses tackle cyber risk head on. By combining industry... ...leading insurance with world-class cybersecurity technology, At-Bay offers end... ...of actuaries and actuarial analysts of diverse backgrounds and...Senior- ...Senior Catastrophe Risk Analyst If you're looking for the stability of a profitable, growing company with the entrepreneurial spirit of a startup, we're hiring. SageSure, a leader in catastrophe-exposed property insurance, is seeking a Senior Catastrophe Risk Analyst...Senior
$109.04k - $163.56k
...Sr Risk Analyst - KR07DE We're determined to make a difference and are proud to be an insurance company that goes well beyond coverages... ...the future. We are seeking a highly skilled and motivated Senior Catastrophe Risk Modeling Analyst to join our Reinsurance team...SeniorTemporary workWork at office3 days per week$90.6k - $150.44k
...Position Title Cloud/Cyber Risk Management Analyst Sr Location New York, NY 10018 Job Summary ***This is an Onsite role... ...LoD") mandate to identify, measure, monitor, and manage the Cybersecurity/Information Security ("Cyber") risk profile of the Bank,...SeniorLocal area$98.2k - $130.8k
...Overview Performs data and analytical services in support of optimizing risk adjusted revenue, maintaining compliance with CMS standards and modeling financial impacts of changes in risk adjustment data and methodologies. Collaborates regularly with internal departments...SeniorWork experience placementFlexible hours$117k - $145k
...About the role: We're looking for an experienced and impact driven professional to join our Global Risk team as a Senior Risk Analyst. In this role, you will take a leading part in shaping risk and commercial decision making across the AMER region. You will work...SeniorWork experience placementWork at officeRemote workHome office3 days per week$72.28k - $117.52k
...your recruiter who can provide you more specific details for this role. Line of Business: Risk Management Job Description: The Senior Group Risk Analyst provides a broad range of research, analysis, reporting, monitoring and/or operational process support...SeniorLocal areaWork from homeFlexible hours$105k - $120k
United Nations Federal Credit Union seeks a skilled contributor to enhance its Third-Party Risk Management (TPRM) program. The role involves assessing and mitigating risks, ensuring compliance with regulations, and collaborating with various internal teams to support procurement...SeniorWork at office- ...At Snaplii, risk management isn't a "brake" on growth-it's the "supercharger" that enables our 300% explosive expansion. We aren't looking for analysts who just read reports; we want strategists who can reverse-engineer fraud loops and command AI to automatically sever...SeniorWork experience placementWork at officeRelocationRelocation package
- ...Third-Party Risk Management Senior Analyst (MRA Remediation Support) - VP Level New York City, NY or Tampa, FL (Hybrid) 6-12 Months Contract Web Cam Interview $70-$75/Hr on W2 Third Party Risk is a global, first line team within the Markets Operational Risk & Control...SeniorContract work
- A financial services firm is looking for a First Line Risk Data Analyst/Manager to enhance risk reporting and analytical tools. The role involves creating executive dashboards, automating reporting processes, and ensuring compliance with risk management standards. Candidates...Senior
- ...Cybersecurity Risk Analyst We are seeking a Cybersecurity Risk Analyst to join our Information Security Risk team. This role focuses on assessing risks across applications (on-prem and cloud), infrastructure, and third-party vendors through a formalized risk assessment...
- ...given to candidates with prior experience in the Financial Services Industry. Position Summary: The Information Risk Analyst/Cybersecurity Risk Analyst will be responsible for developing risk assessment questionnaires, conducting risk assessments for applications...
- A global consulting firm is seeking an IT Risk & Vulnerability Analyst to ensure software security and compliance for strategic clients. The... ...reports. Candidates should have a Bachelor's degree in IT or Cybersecurity, with at least 3 years of experience in vulnerability...
$161.6k - $202k
...You'll join the Security team and work across four pillars: security certifications (HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and technical risk management. You won't be maintaining a stale compliance program - you'll...SeniorWork from homeFlexible hours$85k - $145k
...Market Risk Regulatory Initiatives Team Member RBC is seeking a highly motivated individual to contribute to key initiatives in the... ...role requires comfort working under pressure and presenting to senior management. What will you do? Monitor controls and issues...SeniorFlexible hours$87.8k - $160.9k
...opportunity The objective of our consulting risk services is to provide clients with a... ...IT and security teams to ensure that cybersecurity policies and procedures are up-to-date... ...present risk reports and dashboards to senior management and the board of directors....SeniorContract workSummer holidayWork at officeFlexible hours- ...Market Risk Senior Business Analyst This role will be part of the Market Risk Technology Team. This team is responsible for delivering market risk technology and software solutions for First and Second Line of Defense. Software solutions from this group include high...Senior
- Senior Governance, Risk, Compliance (GRC) Analyst job at Oura. New York, NY. At Oura, our mission is to empower every person to own their inner potential. With our award-winning Oura Ring and app, we help over 2.5 million people turn insights about sleep, activity, and...SeniorWork at officeLocal areaRemote workFlexible hours
- ...SMEs, and technology teams to enhance the organization’s data risk posture while supporting both U.S. and Japan-based stakeholders... ...within financial services Direct collaboration with cybersecurity, risk, audit, and business stakeholders across regions Opportunity...
$109.12k - $163.68k
...Market Risk Senior Analyst The Market Risk Senior Analyst is a seasoned professional role. Applies in-depth disciplinary knowledge, contributing to the development of new techniques and the improvement of processes and work-flow for the area or function. Integrates...SeniorFull timeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Senior Risk Analyst. Be the first to apply!
Related searches
- cyber security consultant New York, NY
- cyber security specialist New York, NY
- cybersecurity analyst remote New York, NY
- senior cybersecurity analyst New York, NY
- transaction risk analyst New York, NY
- operational risk consultant New York, NY
- governance risk & compliance analyst New York, NY
- it risk analyst New York, NY
- quantitative risk analyst New York, NY
- risk analyst intern New York, NY


