Cybersecurity Senior Risk Analyst
RIT Solutions
Cybersecurity Senior Risk Analyst
Location: Hybrid: Work location (15 MTC, 16th Floor) & Remote Tuesdays & Fridays (3 days in office/2 days remote)
Job Description
The Senior Risk Analysts will be expected to continue building an effective Citywide Cybersecurity risk program. These analysts will be responsible for improving our risk assessment process to make it more user-centric, interviewing and communicating with agencies when performing risk assessments, and driving creation of a third-party vendor register and monitoring process. Analysts will review and analyze technologies for inventorying third parties, collaborate with SMEs to collect third party intelligence and define actions based on it, and design steps for reviewing existing third parties in our portfolio. Delays in onboarding practitioners with expertise in these areas will leave unaddressed gaps in our risk governance framework. As NYC's reliance on third party vendors continues to grow it is imperative for the City to have a vendor management practice, which does not only review vendors at the front end of the procurement process but actively manages risk throughout the vendor lifecycle. According to the 2025 Telecommunication Data Breach Investigations Report, 30% of breaches were linked to third party involvement (twice as many as in 2024). Maintaining our status quo can open up the City and agencies to lawsuits or audit findings (e.g. IRS, City Comptroller). If the City sustains a substantial cyber incident that results in loss of life or significant financial losses, it is not uncommon for individuals and organizations that are negatively impacted to file lawsuits against organizations that are responsible for defending/protecting critical information and critical services. The City would not be able to defend itself as having exercised due diligence in the protection of data and services without the existence of and proper functioning of a mature cyber risk program. Not having a user-centric risk assessment process drains resources from City agencies and the Audit & Compliance team due to questions being misunderstood. This also causes inaccuracies in submitted information, which leads to risk being misevaluated and mismanaged.
Mandatory Skills/Experience
Note: Candidates who do not have the mandatory skills will not be considered
· A minimum of 4 years of experience in risk management or cybersecurity risk assessment or 4 years of experience evaluating and managing third parties in a cybersecurity team.
- One or more of the following certifications are:
- Certified Information Systems Auditor (CISA)
- Certified Information Systems Security Professional (CISSP)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Security Manager (CISM)
- CompTIA Security+
- CompTIA Network+
- CompTIA A+
- CompTIA CySA+
- Cisco Certified Network Associate - CCNA
- CEH: Certified Ethical Hacker
- GIAC Information Security Fundamentals (GISF)
- GIAC Security Essentials (GSEC)
- (ISC)2 Systems Security Certified Practitioner (SSCP)
Desirable Skills
- BS/BA degree in Cybersecurity, Risk Management, Information Systems, Computer Science, or a related field.
- Ability to work effectively in a team environment.
- Being highly organized, motivated and a self-directed professional.
- Knowledge of hardware, software, data, and network principles and systems related to Private and/or Public Sectors services.
- Understanding of commonly used computer operating systems, databases, network structures.
- Familiarity with cybersecurity framework(s) (NIST, SANS, PCI, ISO 27001/27002, or CIS)
- Investigative and analytical skills.
- Excellent oral and written communication skills;
- Knowledge of the current and evolving cyber threat landscape;
- Knowledge of laws, regulations, policies, and ethics related to cybersecurity and information privacy;
Responsibilities:
· Build new risk processes and implement risk frameworks to enable better monitoring and evaluation of risks across the City; · Manage complex, cross-functional projects, pushing through ambiguity and challenges which may arise; · Work with stakeholders across various divisions, soliciting input and working through feedback; · Evaluate risk of third parties used by New York City agencies; · Document and track remediation of risks in the Risk Register; · Review and analyze various cybersecurity risk cases, justification, and exceptions documents submitted by agencies; · Assist in the development of cybersecurity risk assessment procedures and testing methodologies based on established frameworks and guidelines; · Initiating corrective actions to remediate vulnerabilities or weaknesses where necessary; · Engage in communications with NYC Agencies; · Handle special projects and initiatives as assigned.
- ...Inc. is seeking a qualified Information Security Analyst to support annual information security program risk assessments and facilitate risk analysis activities... ...candidate will have 5-7 years of experience in cybersecurity, strong project management skills, and a Bachelor...Senior
- ...Responsibilities Support annual information security program risk assessments. Facilitate/Support interviews and evidence gathering... ..., and status updates. Requirements Experience in cybersecurity risk analysis Knowledge of information security standards and...SeniorLocal areaRemote work
- ...Cybersecurity Senior Risk Analyst 1 Labor Category - Analyst 2 Work Location: Hybrid: Work location (15 MTC, 16th Floor) & Remote Tuesdays & Fridays (3 days in office/2 days remote) Scheduled Work Hours: Normal business hours Monday-Friday 35 hours/week (not including...SeniorWork at officeRemote workMonday to Friday
- ...Senior Analyst, Cybersecurity Governance, Risk and Compliance, New York, NY The Senior Analyst, Cybersecurity Governance Risk & Compliance will administer the completion of compliance-related client requests to assess security policies and procedures. The Senior...SeniorWork experience placement
$90k - $160k
...IT RISK & CONTROL SENIOR ANALYST WHAT IS THE OPPORTUNITY? The IT Risk Senior Analyst is a subject-area specialist with specialized training, methods and analytic techniques to create recommendations and directions for cyber risk mitigation in a complex technical environment...SeniorRemote work- ...A dynamic consulting firm in the United States seeks a Senior Associate for its Cyber Security & Data Privacy (CSDP) group. This role involves leading client engagements to implement cybersecurity programs and managing daily compliance operations. Ideal candidates will...Senior
$87.8k - $160.9k
...opportunity The objective of our consulting risk services is to provide clients with a... ...IT and security teams to ensure that cybersecurity policies and procedures are up-to-date... ...present risk reports and dashboards to senior management and the board of directors....SeniorContract workSummer holidayWork at officeFlexible hours- ...Technology Operational Risk Officer Bring your expertise to JPMorgan Chase. As part of Risk Management and Compliance, you are... ...and strong understanding of modern software engineering, cloud, cybersecurity, and AI-enabled development to identify and assess technology...Senior
$150k - $185k
...Actuary / Senior Actuary New York, New York, United States... ...help businesses tackle cyber risk head on. By combining industry... ...leading insurance with world-class cybersecurity technology, At-Bay offers end... ...of actuaries and actuarial analysts of diverse backgrounds and...Senior- ...A leading healthcare provider is looking for a Senior Analyst to support risk management and internal audit initiatives. The role involves assessing enterprise risks, managing audit projects, and mentoring junior staff. The ideal candidate should have at least 3 years...SeniorFull time
- ...Senior Catastrophe Risk Analyst If you're looking for the stability of a profitable, growing company with the entrepreneurial spirit of a startup, we're hiring. SageSure, a leader in catastrophe-exposed property insurance, is seeking a Senior Catastrophe Risk Analyst...Senior
$109.04k - $163.56k
...Sr Risk Analyst - KR07DE We're determined to make a difference and are proud to be an insurance company that goes well beyond coverages... ...the future. We are seeking a highly skilled and motivated Senior Catastrophe Risk Modeling Analyst to join our Reinsurance team...SeniorTemporary workWork at office3 days per week$90.6k - $150.44k
...Position Title Cloud/Cyber Risk Management Analyst Sr Location New York, NY 10018 Job Summary ***This is an Onsite role... ...LoD") mandate to identify, measure, monitor, and manage the Cybersecurity/Information Security ("Cyber") risk profile of the Bank,...SeniorLocal area$98.2k - $130.8k
...Overview Performs data and analytical services in support of optimizing risk adjusted revenue, maintaining compliance with CMS standards and modeling financial impacts of changes in risk adjustment data and methodologies. Collaborates regularly with internal departments...SeniorWork experience placementFlexible hours- ...A leading financial institution is seeking a Model Risk Management Senior Analyst to oversee model risk and support validation efforts. This role includes creating and maintaining a model inventory, evaluating model performance, and ensuring compliance with regulations...Senior
$117k - $145k
...About the role: We're looking for an experienced and impact driven professional to join our Global Risk team as a Senior Risk Analyst. In this role, you will take a leading part in shaping risk and commercial decision making across the AMER region. You will work...SeniorWork experience placementWork at officeRemote workHome office3 days per week$72.28k - $117.52k
...with your recruiter who can provide you more specific details for this role. Line of Business: Risk Management Job Description: The Senior Group Risk Analyst provides a broad range of research, analysis, reporting, monitoring and/or operational process...SeniorLocal areaWork from homeFlexible hours$100k - $120k
...Description Develop and implement third-party risk management frameworks to ensure... ...Prepare detailed reports and presentations for senior management on risk assessment findings.... ...Senior Third Party Risk Management Analyst should have: A strong understanding of...SeniorPermanent employmentLocal areaFlexible hours$105k - $120k
...maturation of the Credit Union’s Third-Party Risk Management (TPRM) program, ensuring... ...location. What you'll do • Regardless of seniority or role, uphold UNFCU’s mission, core values... ...as a designated alternate to the TPRM analyst in the vendor management review and sign...SeniorContract workWork at officeLocal area- ...At Snaplii, risk management isn't a "brake" on growth-it's the "supercharger" that enables our 300% explosive expansion. We aren't looking for analysts who just read reports; we want strategists who can reverse-engineer fraud loops and command AI to automatically sever...SeniorWork experience placementWork at officeRelocationRelocation package
- ...Third-Party Risk Management Senior Analyst (MRA Remediation Support) - VP Level New York City, NY or Tampa, FL (Hybrid) 6-12 Months Contract Web Cam Interview $70-$75/Hr on W2 Third Party Risk is a global, first line team within the Markets Operational Risk & Control...SeniorContract work
$110k - $130k
...SUMMARY Model risk management (MRM) refers to the overseeing of risk defined by potential adverse consequences from decisions based... ...the potential of model error or wrongful model usage. The MRM Senior Analyst will support the SVP MRM Officer in the implementation and...SeniorTemporary workFlexible hours- ...Framework Ventures is seeking a Senior Market Risk Analyst to oversee daily risk monitoring and market analysis of trading portfolios. The ideal candidate will have 4-6 years of experience in market risk or equities trading, particularly in commodities and ETFs. Responsibilities...Senior
- ...Global Green Growth Institute seeks a consultant for a Climate Risk and Vulnerability Assessment (CRVA) in the UAE. The role requires a postgraduate degree and 8–15 years of relevant experience in climate science, with a strong emphasis on stakeholder engagement and data...Senior
- ...Cybersecurity Risk Analyst We are seeking a Cybersecurity Risk Analyst to join our Information Security Risk team. This role focuses on assessing risks across applications (on-prem and cloud), infrastructure, and third-party vendors through a formalized risk assessment...
- ...given to candidates with prior experience in the Financial Services Industry. Position Summary: The Information Risk Analyst/Cybersecurity Risk Analyst will be responsible for developing risk assessment questionnaires, conducting risk assessments for applications...
- ...remote job provider is looking for a Cyber Risk Analyst to assist in day-to-day operations... ...Impact Analysis while developing skills in cybersecurity and risk governance. Responsibilities... ...documentation, and collaboration with senior analysts. It offers competitive salary,...Remote work
$161.6k - $202k
...You'll join the Security team and work across four pillars: security certifications (HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and technical risk management. You won't be maintaining a stale compliance program - you'll...SeniorWork from homeFlexible hours- ...A leading cybersecurity firm seeks an experienced L3 SOC Analyst to join their remote team. In this role, you'll own complex security incidents, analyze and respond to high-severity events, and optimize SOC processes. Strong technical expertise in SIEM platforms and incident...SeniorRemote work
- ...A cybersecurity consultancy is seeking a Cyber Risk & Compliance Analyst to enhance client trust and ensure compliance with cybersecurity controls. Responsibilities include reviewing RFPs and contracts, managing third-party risk questionnaires, and maintaining up-to-date...Full timeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Senior Risk Analyst. Be the first to apply!
- risk analyst Brooklyn, NY
- operational risk consultant Brooklyn, NY
- risk officer Brooklyn, NY
- risk consultant Brooklyn, NY
- senior platform engineer Brooklyn, NY
- senior procurement Brooklyn, NY
- senior director product management Brooklyn, NY
- senior manager customer operations Brooklyn, NY
- senior vmware engineer Brooklyn, NY
- senior performance engineer Brooklyn, NY

