Demo

Cybersecurity Senior Risk Analyst

Stratford Solutions Inc.
Brooklyn, NY Full Time
POSTED ON 12/16/2025
AVAILABLE BEFORE 2/15/2026
Job Title: Cybersecurity Senior Risk AnalystLabor Category: Specialist 2Location: 15 MTC Brooklyn NY - Remote Tuesdays & Fridays (3 days in office/2 days remote) HybridJob Type: ContractWork schedule: Normal business hours Monday-Friday 35 hours/week (not including mandatory unpaid meal break after 6 hours of work.Duration: 24 MonthsPay Rate: $50 to $60 per hourJob Description /JustificationThe Senior Risk Analysts will be responsible for implementing tools and practices to enhance processes related to third-party risk management, risk assessment, and general cyber risk governance. The position requires a diverse background in governance, risk, and compliance; analysis; technology implementation; project management; and collaboration with diverse groups of stakeholders to strengthen the security posture of New York City agencies.The Senior Risk Analysts will be expected to continue building an effective Citywide Cybersecurity risk program. These analysts will be responsible for improving our risk assessment process to make it more user-centric, interviewing and communicating with agencies when performing risk assessments, and driving creation of a third-party vendor register and monitoring process. Analysts will review and analyze technologies for inventorying third parties, collaborate with SMEs to collect third party intelligence and define actions based on it, and design steps for reviewing existing third parties in our portfolio.Delays in onboarding practitioners with expertise in these areas will leave unaddressed gaps in our risk governance framework. As NYC's reliance on third party vendors continues to grow it is imperative for the City to have a vendor management practice, which does not only review vendors at the front end of the procurement process but actively manages risk throughout the vendor lifecycle. According to the 2025 Verizon Data Breach Investigations Report, 30% of breaches were linked to third party involvement (twice as many as in 2024). Maintaining our status quo can open up the City and agencies to lawsuits or audit findings (e.g. IRS, City Comptroller). If the City sustains a substantial cyber incident that results in loss of life or significant financial losses, it is not uncommon for individuals and organizations that are negatively impacted to file lawsuits against organizations that are responsible for defending/protecting critical information and critical services. The City would not be able to defend itself as having exercised due diligence in the protection of data and services without the existence of and proper functioning of a mature cyber risk program.Not having a user-centric risk assessment process drains resources from City agencies and the Audit & Compliance team due to questions being misunderstood. This also causes inaccuracies in submitted information, which leads to risk being misevaluated and mismanaged.SCOPE OF SERVICESTASKS:Build new risk processes and implement risk frameworks to enable better monitoring and evaluation of risks across the City;Manage complex, cross-functional projects, pushing through ambiguity and challenges which may arise;Work with stakeholders across various divisions, soliciting input and working through feedback;Evaluate risk of third parties used by New York City agencies;Document and track remediation of risks in the Risk Register.Review and analyze various cybersecurity risk cases, justification, and exceptions documents submitted by agencies;Assist in the development of cybersecurity risk assessment procedures and testing methodologies based on established frameworks and guidelines;Initiating corrective actions to remediate vulnerabilities or weaknesses where necessary;Engage in communications with NYC Agencies;Handle special projects and initiatives as assigned.MANDATORY SKILLS/EXPERIENCE Note: Candidates who do not have the mandatory skills will not be considered – MINIMUM OF 12 YEARS EXPERIENCE:A minimum of 4 years of experience in risk management or cybersecurity risk assessment or 4 years of experience evaluating and managing third parties in a cybersecurity team.DESIRABLE SKILLS/EXPERIENCE:BS/BA degree in Cybersecurity, Risk Management, Information Systems, Computer Science, or a related field.One or more of the following certifications are a plus:Certified Information Systems Auditor (CISA)Certified Information Systems Security Professional (CISSP)Certified in Risk and Information Systems Control (CRISC)Certified Information Security Manager (CISM)CompTIA Security CompTIA Network CompTIA A CompTIA CySA Cisco Certified Network Associate - CCNACEH: Certified Ethical HackerGIAC Information Security Fundamentals (GISF)GIAC Security Essentials (GSEC)(ISC)2 Systems Security Certified Practitioner (SSCP)Ability to work effectively in a team environment.Being highly organized, motivated and a self-directed professional.Knowledge of hardware, software, data, and network principles and systems related to Private and/or Public Sectors services.Understanding of commonly used computer operating systems, databases, network structures.Familiarity with cybersecurity framework(s) (NIST, SANS, PCI, ISO 27001/27002, or CIS)Investigative and analytical skills.Excellent oral and written communication skills;Knowledge of the current and evolving cyber threat landscape;Knowledge of laws, regulations, policies, and ethics related to cybersecurity and information privacy;

Salary : $50 - $60

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Cybersecurity Senior Risk Analyst?

Sign up to receive alerts about other jobs on the Cybersecurity Senior Risk Analyst career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$125,027 - $157,872
Income Estimation: 
$149,432 - $188,965
Income Estimation: 
$192,911 - $256,346
Income Estimation: 
$228,678 - $310,400
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Stratford Solutions Inc.

  • Stratford Solutions Inc. Manhattan, NY
  • Job Title: NG911 IT Security Project ManagerLabor Category: Specialist 3Location: 2 MetroTech Center, Brooklyn, NY 11201 (Onsite all 5 days)Job Type: Contr... more
  • 14 Days Ago

  • Stratford Solutions Inc. Manhattan, NY
  • Job Title: Administrative AssistantLocation: Onsite – 595 Court Street, Brooklyn, NY 11231Work Schedule: Monday–Friday, 8:00 AM – 4:00 PM (37.5 hours/week,... more
  • 6 Days Ago

  • Stratford Solutions Inc. Manhattan, NY
  • Job Title: Technical Project Manager for (Permit System) for DOT (Department of TransportationLabor Category: Project Manager 3Location: New York NY (Onsit... more
  • 7 Days Ago


Not the job you're looking for? Here are some other Cybersecurity Senior Risk Analyst jobs in the Brooklyn, NY area that may be a better fit.

  • Irongate Cybersecurity York, NY
  • IronGate Cybersecurity is in search of a highly skilled and experienced Senior Digital Forensics Analyst to enhance our Professional Services Team. This cr... more
  • 1 Month Ago

  • Ariel Partners Brooklyn, NY
  • Salary: $70JOB DESCRIPTIONAs New York City continues to advance our cybersecurity posture, it is essential that we have analysts dedicated to managing and ... more
  • 28 Days Ago

AI Assistant is available now!

Feel free to start your new journey!