Lead IT Security Analyst
$121.79k - $210.09kNYU Langone Health
Lead IT Security Analyst
IT/Health IT/Informatics
New York, NY • Full-Time/Regular
NYU Langone Health is a fully integrated health system that consistently achieves the best patient outcomes through a rigorous focus on quality that has resulted in some of the lowest mortality rates in the nation. Vizient Inc. has ranked NYU Langone the No. 1 comprehensive academic medical center in the country for three years in a row, and U.S. News & World Report recently placed nine of its clinical specialties among the top five in the nation. NYU Langone offers a comprehensive range of medical services with one high standard of care across 6 inpatient locations, its Perlmutter Cancer Center, and over 320 outpatient locations in the New York area and Florida. With $14.2 billion in revenue this year, the system also includes two tuition-free medical schools, in Manhattan and on Long Island, and a vast research enterprise with over $1 billion in active awards from the National Institutes of Health.
Position Summary: We have an exciting opportunity to join our team as a Lead IT Security Analyst. This position reports to the IT Controls & Regulatory Compliance Manager and serves as a senior individual contributor and subject matter expert responsible for leading enterprise risk assessments and evaluating the security of modern technology environments, including cloud-based platforms. The IT Controls Lead drives the design, execution, and continuous improvement of the organizations risk assessment program to ensure compliance with regulatory and industry requirements, including HIPAA, HITRUST, PCI DSS, and FISMA. This role partners closely with IT, Security, Clinical, Research, and Compliance stakeholders to assess risk across enterprise systems, research technologies, and cloud infrastructure, and to ensure that security controls are appropriately designed and operating effectively.
Job Responsibilities
Enterprise Risk Assessment Leadership
- Lead the execution and maturation of the enterprise risk assessment program aligned to regulatory and industry frameworks
- Conduct and oversee complex risk assessments, including HIPAA and HITRUST-aligned evaluations
- Define and maintain risk assessment methodologies, scoring models, and standards
- Identify, analyze, and document risks, and develop actionable remediation strategies
Cloud Security & Technology Risk Evaluation
- Lead security assessments of cloud and hybrid environments (e.g., IaaS, PaaS, SaaS)
- Evaluate key control domains, including:
- Identity and access management
- Network architecture and segmentation
- Logging, monitoring, and detection capabilities
- Data protection and encryption
- Assess alignment to frameworks such as:
- HITRUST
- PCI
- NIST Cybersecurity Framework
- ISO/IEC 27001
- Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments
Research Technology & Clinical Risk Oversight
- Lead security and risk reviews of research technologies and data use cases, including systems handling sensitive or regulated data
- Partner with clinical and research stakeholders to evaluate emerging technologies and ensure appropriate risk controls are in place
- Provide guidance on secure design and data protection strategies
Cross-Functional Leadership & Escalation
- Serve as a senior escalation point for complex or high-risk assessments across:
- Enterprise systems
- Third-party/vendor solutions
- Cloud and research environments
- Provide subject matter expertise and mentorship to team members supporting assessments and compliance activities
- Influence decision-making across stakeholders without direct authority
Regulatory & Audit Support
- Support internal and external audit activities by providing subject matter expertise, documentation, and control validation
- Ensure risk assessments and control evaluations align with regulatory expectations and audit requirements
- Partner with the IT Controls Manager on audit responses and remediation planning
Program Improvement & Innovation
- Identify opportunities to enhance assessment processes, tooling, and automation
- Contribute to development of metrics, dashboards, and reporting to measure risk posture and program effectiveness
- Drive continuous improvement in how risk is identified, assessed, and managed across the enterprise
Minimum Qualifications: Typically requires 10 or more years of experience and BA/BS degree or equivalent
Preferred Qualifications: Advanced degree desirable
Qualified candidates must be able to effectively communicate with all levels of the organization. NYU Langone Health provides its staff with far more than just a place to work. Rather, we are an institution you can be proud of, an institution where you'll feel good about devoting your time and your talents.
At NYU Langone Health, we are committed to supporting our workforce and their loved ones with a comprehensive benefits and wellness package. Our offerings provide a robust support system for any stage of life, whether it's developing your career, starting a family, or saving for retirement. The support employees receive goes beyond a standard benefit offering, where employees have access to financial security benefits, a generous time-off program and employee resources groups for peer support. Additionally, all employees have access to our holistic employee wellness program, which focuses on seven key areas of well-being: physical, mental, nutritional, sleep, social, financial, and preventive care. The benefits and wellness package is designed to allow you to focus on what truly matters. Join us and experience the extensive resources and services designed to enhance your overall quality of life for you and your family. NYU Langone Health is an equal opportunity employer and committed to inclusion in all aspects of recruiting and employment. All qualified individuals are encouraged to apply and will receive consideration. We require applications to be completed online.
View Know Your Rights: Workplace discrimination is illegal.
NYU Langone Health provides a salary range to comply with the New York state Law on Salary Transparency in Job Advertisements. The salary range for the role is $121,792.22 - $210,091.64 Annually. Actual salaries depend on a variety of factors, including experience, specialty, education, and hospital need. The salary range or contractual rate listed does not include bonuses/incentive, differential pay or other forms of compensation or benefits.
To view the Pay Transparency Notice, please click here
- ...other scanning tools. Web application scanning and web application firewalls. Containers. CIS benchmarks, STIGs, or other security hardening standards. Additional Desirable Skills Or Experience SAML, Kerberos, OAuth, OIDC, LDAP. Powershell and...Suggested
- ...Role: IT Security Analyst Location: NYC, NY ( Hybrid Role ) Job Description The Security analyst is an integral part of the Client team. The Security Analyst is responsible for the day -to -day administration and maintenance of IT security systems...SuggestedFlexible hours
- ...Lead Security Analyst The Lead Security Analyst will report directly to the Chief Risk Officer. The individual will be responsible for monitoring... ...with minimal supervision, interact effectively with IT, Security, and Business leaders. Key Responsibilities:...SuggestedFull time
- ...Vice President, Securities & Derivatives Lead Analyst Working at Citi is far more than just a job. A career with us means joining a team of more than 230,000 dedicated people from around the globe. At Citi, you'll have the opportunity to grow your career, give back...Suggested
- ...Role: Senior Offensive Security Engineer/Senior Penetration Tester/Senior Security Analyst Location: New York-Onsite Duration: Fulltime... ...technology. Responsibilities : Plan, lead, and execute penetration testing engagements, simulating...SuggestedFull time
- A leading international banking institute in New York City seeks a Senior IT Information Security Operation Analyst. In this role, you will manage daily security operations, ensure compliance with regulations, and drive security initiatives. Applicants should have significant...
- ...Industries (FPI). Our depth of experience allows us to provide IT security support for a wide range of IT General Support Systems (GSS)... ...and regulations. Job Description Information System Security Analyst duties include: Perform Certification & Accreditation (C&A), System...Contract workWork experience placementWork at office
- ...Senior IT Information Security Operations Specialist Welcome to PGMTEK, Inc where we help candidates find the opportunities that best match... ...Senior IT Information Security Operations Specialist for a leading international banking institute in New York City. This role...Full time
- We are looking for an IT Security Analyst to help protect enterprise systems, data, and cloud environments from emerging threats. This role focuses on identifying risk, detecting abnormal behavior, responding to incidents, and continuously strengthening security controls...
$102.6k - $179.25k
...About the Role: As a Senior IT Security Analyst, you will engage in advanced cybersecurity tasks with a high level of autonomy. Your contributions... ...advanced threat detection and monitoring activities. • Lead detailed security audits and forensic investigations. •...Work at office$195k - $240k
...(TVM Cloud) Senior Cloud Security and Vulnerability Analyst Location New York Business Area Legal, Compliance, and Risk Ref #... ...Come find yours. What's The Role? We are seeking an IT Security Analyst to help ensure that our Public Cloud IT...Temporary workFor contractorsWork experience placementWork at office- ...Security Analyst The Security Analyst is responsible for managing third-party vulnerability data, executing scans using Sompo’s proprietary tools, and partnering with IT teams to prioritize remediation efforts. The role requires strong technical expertise in vulnerability...
$45 - $50 per hour
...Primary Value: Executes day to day technical and administrative security tasks Core Responsibilities Perform log monitoring (firewalls... ...application dashboards (firewall, anti-malware, etc.) Support IT staff on initial response to alerts for malware incidents...Hourly payTemporary workWork at officeRemote work- ...Security Program Administrator The Security Program Administrator will be required to work with business owners and managers to acquire... ...through analysis of required project tasks and required IT security stance within the firm Knowledge & Skills. Strong...Work at officeLocal area
- ...Securities and Derivatives Intermediate Analyst Working at Citi is far more than just a job. A career with us means joining a team of more than 230,000 dedicated people from around the globe. At Citi, you'll have the opportunity to grow your career, give back to your...
$78.32k - $109.28k
...Securities and Derivatives Intermediate Analyst is an entry level position responsible for processing orders and transactions originating from trading desks and branch offices in coordination with the Operations - Transaction Services team. The overall objective of this...Full time- ...Securities & Derivatives Sr Analyst Hybrid Working at Citi is far more than just a job. A career with us means joining a team of more than 230,0... ..., partners and regulators, and play an integral part in leading an agenda at the forefront to optimise and streamline processes...Work experience placementWork at officeLocal areaFlexible hours
- ...Securities Valuation Analyst Start your journey at JPMorgan Chase, where you belong and your impact matters. Join a team that delivers independent... ...and market knowledge to identify growth areas and help lead projects in a collaborative environment where your contributions...Worldwide
- ...Securities & Derivatives Analyst Working at Citi is far more than just a job. A career with us means joining a team of more than 230,000 dedicated people from around the globe. At Citi, you'll have the opportunity to grow your career, give back to your community and...Casual workWork at officeWork from home
$90k - $110k
...across the capital stack, with a primary focus on Asset-Backed Securities (ABS). Covered sectors include autos, equipment, data centers... ...public and private markets. Act as a Securitized Products analyst with a primary focus on ABS, while maintaining the ability to...Flexible hours$85k - $95k
...following our governance standards to ensure AI is used ethically, securely, and transparently. If you join us, you're joining a culture... ...For: We are looking for a Securities Lending Operations Analyst who will be responsible for performing all daily operational processes...Contract workLocal areaFlexible hours- ...Role: Security Analyst Location: Hybrid Duration: 6+ months Details: -Provide post implementation support for new security technology. -Research emerging security products, services, protocols and standards, in support of security...
- ...Senior Security Analyst We are looking for a senior security analyst with 10+ years experience in cybersecurity to include leading or being part of an incident response team. Customer location: New York City (lower east side) Duration: 12 months Start date: End of...Day shift
- ...Summary: We are seeking an application security governance analyst to join and help establish and maintain effective governance practices within the application security vertical of Cybersecurity. The ideal candidate will have a strong background in application...
- ...Database Security Role Database security role offers an opportunity to work in a hybrid environment of applying Access Control and Database knowledge. All Production database systems security is managed by a dedicated team and resources working on this team are focused...
- ...Security Analyst Job Location: NYC, NY (Looking for local Candidate - MUST be able to onsite interview for this role in NYC) Job Type: 6+ Months Contract Qualifications: Bachelor's degree in computer science or a related discipline, or equivalent work experience...Contract workWork experience placementLocal area
$196.9k - $295.3k
...Security Analyst, Bridge Bridge is Stripe's fintech innovation hub focused on building a modern, stablecoin-powered cross-border... ...processes where it makes sense, and find custom approaches where it doesn't. Lead risk assessment, control design and testing for all...Full timeWork at officeLocal areaRemote workWork from homeRelocation- ...Provide a short description of the Position: An application security engineer ensures software security by identifying vulnerabilities, implementing protective measures, collaborating with development teams, monitoring for suspicious activities, and staying updated on...
- ...Oracle Database Security Analyst We are seeking an experienced Oracle Database Security Analyst to join our dedicated database security team in Jersey City, NJ. This position offers an excellent opportunity to work in a hybrid environment involving Access Control and...
- ...seeking a skilled Cybersecurity Engineer with expertise in endpoint security technologies to join our team. The ideal candidate will be... ...vulnerability scans and assessments. o Collaborate with IT and application teams to remediate identified vulnerabilities....H1bLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead IT Security Analyst. Be the first to apply!
- bond analyst New York, NY
- rate analyst New York, NY
- network security analyst New York, NY
- information security compliance analyst New York, NY
- security analyst intern New York, NY
- entry level information security analyst New York, NY
- security analyst remote New York, NY
- entry level security analyst New York, NY
- physical security analyst New York, NY
- security operations analyst New York, NY

