Cyber Security Analyst, Level 2

City of New YorkNew York, NY
$104,334 - $125,000

About The Position

The Information Security Analyst supports day-to-day security operations by monitoring alerts, investigating potential threats, and helping protect systems, networks, and data. This role will support many functions of the Information Security Program which include, access provisioning, log analysis for fraud mitigation, security accreditations of new products and services, vulnerability reviews and follow up remediation of vulnerabilities associated to our new pension platform, reviews of indicators or compromise to be applied to NYCERS security controls for awareness, monitoring and incident response of our SIEM and security tools for suspicious activity, triage alerts and escalate incidents to senior analysts, support phishing analysis and malware investigations, support phishing simulations and user awareness campaigns, assist with security reports and dashboards, help update playbooks, policies, procedures, standards, and guidelines, participate in basic risk assessments, and promote security best practices, across the agency.

Requirements

  • Permanent in the Cyber Security Analyst Civil Service title or have a comparable Civil Service title.
  • Understanding of networking.
  • Familiarity with applications and operating systems.
  • Knowledge of cyber security concepts.
  • Willingness to manage, fine tune, and optimize security tools, such as SIEM, Endpoint Detection, Fraud mitigation tools, Intrusion Detection, etc. (training provided).
  • Detail oriented.
  • Good written and oral communications.
  • Comfortable interaction with agency colleagues.
  • Ability to follow procedures and ask questions.
  • A baccalaureate degree, from an accredited college including or supplemented by twenty-four (24) semester credits in cyber security, network security, computer science, computer programming, computer engineering, information technology, information science, information systems management, network administration, or a pertinent scientific, technical or related area; or
  • A four-year high school diploma or its equivalent approved by a State’s department of education or a recognized accrediting organization and three years of satisfactory experience in cyber security, network security, computer science, computer programming, computer engineering, information technology, information science, information systems management, network administration, or a pertinent scientific, technical or related area; or
  • Education and/or experience equivalent to the above.
  • College education may be substituted for up to two years of the required experience on the basis that sixty (60) semester credits from an accredited college is equated to one year of experience.
  • Twenty-four (24) credits from an accredited college or graduate school in cyber security, network security, computer science, computer programming, computer engineering, information technology, information science, information systems management, network administration, or a pertinent scientific, technical or related area; or a certificate of at least 625 hours in computer programming from an accredited technical school (post high school), may be substituted for one year of experience.

Nice To Haves

  • Possessing or willing to obtain a security certification (CompTIA Security+, Google Cybersecurity professional, CISSP, etc.).

Responsibilities

  • Monitor alerts, investigate potential threats, and help protect systems, networks, and data.
  • Support access provisioning.
  • Perform log analysis for fraud mitigation.
  • Conduct security accreditations of new products and services.
  • Perform vulnerability reviews and follow up remediation of vulnerabilities associated with the new pension platform.
  • Review indicators of compromise to be applied to NYCERS security controls for awareness.
  • Monitor SIEM and security tools for suspicious activity and respond to incidents.
  • Triage alerts and escalate incidents to senior analysts.
  • Support phishing analysis and malware investigations.
  • Support phishing simulations and user awareness campaigns.
  • Assist with security reports and dashboards.
  • Help update playbooks, policies, procedures, standards, and guidelines.
  • Participate in basic risk assessments.
  • Promote security best practices across the agency.
  • Lead the development, support, and testing of the comprehensive Business Continuity Plan (BCP).
  • Conduct regular Business Impact Analyses (BIA) to establish Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).
  • Maintain up-to-date recovery documentation.
  • Provide continuity training across business units.
  • Design and facilitate annual tabletop exercises simulating cyberattacks or system outages.
  • Document the results of tabletop exercises and track remediation actions.
  • Identify, analyze, and catalog security risks within the central corporate risk register.
  • Partner with various agency divisions and the head of Enterprise Risk Management to develop risk mitigation strategies.
  • Monitor key risk indicators (KRIs).
  • Prepare detailed risk profile reports and dashboards for senior leadership.

Benefits

  • Inclusive equal opportunity employer committed to recruiting and retaining a diverse workforce.
  • Work environment that is free from discrimination and harassment.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service