Demo

Security Analyst

NPAworldwide
Buffalo, NY Full Time
POSTED ON 4/22/2026
AVAILABLE BEFORE 5/21/2026
Job Description

You'll be responsible for executing a structured monthly security program, managing a robust security toolset, maintaining NYDFS Cybersecurity Regulation 500 (23 NYCRR 500) compliance, and serving as the organization's go-to resource for all things information security. If you're a hands-on security professional with audit experience, solid framework knowledge, and a methodical approach to risk and remediation, this role offers real ownership in a stable, respected organization.

What You'll Do

  • Execute a defined monthly security program including monitoring, alerting, vulnerability management, and follow-up on findings
  • Monitor networks and endpoints via SIEM and EDR tools; investigate anomalies and triage security events
  • Manage vendor vulnerability disclosures assess severity, develop remediation plans, and track resolution
  • Coordinate with internal stakeholders and external partners on annual NYDFS 500 audits and ongoing compliance activities
  • Conduct and oversee security assessments including penetration testing, phishing simulations (KnowBe4), vishing, and social engineering exercises; manage follow-up training for users who fail tests
  • Work with an external security partner (monthly rotating engagements external pen tests, internal attack simulations, and more) to maintain a layered security posture
  • Develop, maintain, and enforce security policies and procedures; cross-train IT staff to build organizational resilience
  • Prepare clear, standardized reports detailing threats, vulnerabilities, risks, and recommended mitigation steps
  • Respond to ad-hoc internal security support requests
  • Assist with company-wide system upgrades as needed

Security Tools & Technologies

You'll Work Within a Well-established, Multi-layered Security Stack, Including

  • Vulnerability Management: Tenable
  • Penetration Testing: Kali Linux, Acunetix / Invicti
  • Endpoint Detection & Response: Carbon Black Detect and Protect
  • Security Awareness & Phishing Simulation: KnowBe4 (managed internally)
  • External Security Partner: Hack at Cyber (monthly rotating engagements)
  • SIEM: Security Information and Event Management platform
  • Endpoint & Device Management: Microsoft Intune compliance policies
  • Firewall: Rule and policy management
  • OS Hardening: Operating system hardening tools and best practices
  • Anti-malware: Endpoint protection solutions

Qualifications

Qualifications

  • 5 years of hands-on information security experience; equivalent experience considered in lieu of a degree
  • Demonstrated experience with security audits, remediation tracking, and incident response candidates who have never been through a full audit cycle will not be considered
  • Working knowledge of security frameworks including CIS Controls, NIST, ISO 27001, or similar ability to apply framework knowledge to real-world decisions (e.g., evaluating proposed changes against NYDFS 500 requirements)
  • Hands-on experience with vulnerability management, SIEM monitoring, EDR tools, and penetration testing methodologies
  • Familiarity with NYDFS Cybersecurity Regulation 500 (23 NYCRR 500) is a strong plus; broader regulated industry compliance experience acceptable
  • Strong documentation skills; ability to write clear policies, procedures, and executive-ready reports
  • Comfortable communicating security risk to both technical teams and non-technical leadership
  • Strong organizational skills with the ability to manage a structured monthly program and respond to unplanned events

About The Role

Why is This a Great Opportunity:

Our client, an established and highly regarded industry leader in Western New York, is seeking an experienced Information Security Analyst to serve as the primary security professional within their IT organization. This is a newly created role the result of a long-tenured security leader stepping into an executive position meaning the program is mature, the tools are in place, and this person walks into a well-documented, well-resourced environment rather than starting from scratch.Outstanding Benefits!

  • Employees may be eligible for a hybrid telecommuting schedule upon successful completion of onboarding period.
    • Pension Plan !
    • Vert Generous Profit Sharing - annual payout
    • 401K with match
    • 4 weeks PTO to start
    • 5 days Sick time
    • 10 Holidays
    • Newly renovated work space including sit/stand desks

    Salary Type : Annual Salary

    Salary Min : $ 85000

    Salary Max : $ 115000

    Currency Type : USD

    Salary : $85,000 - $115,000

    If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
    Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

    What is the career path for a Security Analyst?

    Sign up to receive alerts about other jobs on the Security Analyst career path by checking the boxes next to the positions that interest you.
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Employees: Get a Salary Increase
    View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

    Job openings at NPAworldwide

    • NPAworldwide Manchester, NH
    • Job Description A growing healthcare organization is seeking a Healthcare IT Help Desk Specialist to support clinical and administrative staff with day-to-... more
    • 1 Day Ago

    • NPAworldwide Tulsa, OK
    • Job Description A growing healthcare organization is seeking a Healthcare IT Help Desk Specialist to support clinical and administrative staff with day-to-... more
    • 1 Day Ago

    • NPAworldwide Wichita, KS
    • Job Description CRNA - 27 Weeks Off in Kansas - AUTONOMY This CRNA-only opportunity offers a 27 weeks off per year in a supportive independent practice env... more
    • 1 Day Ago

    • NPAworldwide Wichita, KS
    • Why a Great Opportunity Direct Hire New Grads Welcoe Competitive Compensation, Based On Experience Excellent Full Benefits Package About The Area Williamsv... more
    • 1 Day Ago


    Not the job you're looking for? Here are some other Security Analyst jobs in the Buffalo, NY area that may be a better fit.

    • Erie and Niagara Insurance Association Williamsville, NY
    • About Us For more than 150 years, Erie and Niagara has been a policyholder-owned New York State regional insurance company. Providing property and casualty... more
    • 15 Days Ago

    • Sedara Buffalo, NY
    • Our primary mission at Sedara is to bring valuable security services and products to customers in order to better protect their environment, data, employee... more
    • 1 Month Ago

    AI Assistant is available now!

    Feel free to start your new journey!