Sr Global Cybersecurity Analyst in New York at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Global Cybersecurity Analyst based in United States.
This role leads application security and vulnerability management across a global technology environment. You will serve as a key security partner for applications, SaaS platforms, cloud workloads, and third-party software. The position combines hands-on security assessment with risk prioritization, remediation leadership, and cybersecurity program improvement. You will work closely with development, infrastructure, business application, and technology teams to strengthen security throughout the software lifecycle. The role also provides an opportunity to shape security practices around emerging AI and machine learning technologies. This is a collaborative, analytical position for a cybersecurity professional who can translate complex technical risks into practical business recommendations.
- Lead security reviews and intake for new and updated applications, SaaS platforms, and third-party software, including data classification, architecture, integrations, access models, and vendor security posture.
- Own the vulnerability management lifecycle across endpoints, servers, cloud workloads, and applications, from discovery and validation through risk-based prioritization, remediation tracking, exception management, and reporting.
- Conduct application security assessments, including secure code reviews, software composition and dependency analysis, secure configuration reviews, and web application vulnerability scanning.
- Partner with development, infrastructure, and business application teams to establish remediation timelines, drive findings to closure, and manage documented exceptions and risk acceptances.
- Administer and maintain vulnerability management and application security platforms, including Microsoft Defender, Rapid7 InsightVM, or comparable tools.
- Maintain application inventories and develop metrics and reporting on vulnerability exposure, remediation performance, and application risk for technical and business leadership.
- Support secure software development lifecycle practices, including security requirements, threat modeling, and security sign-off before production deployment.
- Assess AI and machine learning tools and features, considering data handling, data residency, subprocessors, prompt injection, and alignment with established AI security standards.
- Provide technical security support to employees, respond to security-related requests, and assist with troubleshooting and resolution.
- Maintain security procedures, standards, system documentation, operational runbooks, and other cybersecurity program materials.
- Contribute to security awareness and training initiatives, cybersecurity projects, compliance activities, audits, and broader security program improvements.
- Communicate technical security findings and recommendations clearly to both technical and non-technical stakeholders.
Requirements:
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- 5+ years of progressive cybersecurity experience, including application security, vulnerability management, and third-party software or SaaS security assessments.
- CompTIA Security+ certification or an equivalent cybersecurity certification is required.
- Experience with application security assessment, secure code review, threat modeling, and secure architecture and configuration review.
- Strong knowledge of vulnerability management practices, including CVSS, EPSS, known exploited vulnerability data, remediation tracking, and exception management.
- Familiarity with security standards and frameworks such as OWASP Top 10, OWASP ASVS, CIS Benchmarks, and NIST secure development guidance.
- Experience with vulnerability management and application security tooling such as Microsoft Defender, Rapid7 InsightVM, or comparable platforms.
- Understanding of modern software development and deployment practices, including source control, CI/CD pipelines, APIs, containers, cloud-hosted applications, and SaaS environments.
- Knowledge of AI and machine learning security concepts, including model and data handling risks, prompt injection, and third-party AI service and subprocessor risks.
- Experience evaluating third-party and SaaS security, including data classification, privacy considerations, and vendor security posture.
- Strong analytical, troubleshooting, problem-solving, planning, and prioritization skills, with the ability to manage multiple complex projects and deadlines.
- Excellent written and verbal communication skills, with the ability to translate technical vulnerabilities into clear business-oriented recommendations.
- Ability to work independently while collaborating effectively with cross-functional teams in a fast-paced environment.
- Preferred certifications include CSSLP, GWAPT, OSCP, or relevant Microsoft security certifications.
- Valid driver’s license and ability to meet applicable motor vehicle record requirements.
- Ability to occasionally travel and perform the physical requirements of a computer-based office role, including prolonged sitting and occasionally lifting or carrying up to 15 pounds.
- Must be available to work onsite four days per week and remotely one day per week, and live within reasonable commuting distance of Westfield, Indiana.
Benefits:
- Medical, dental, and vision coverage.
- 401(k) plan with company match, eligible beginning the first of the month following the date of hire.
- Generous vacation time and paid holidays.
- Volunteer Time Off.
- Paid parental leave.
- Tuition reimbursement.
- Health club reimbursement.
- Company-paid short- and long-term disability insurance.
- Company-paid life insurance, with optional supplemental life insurance.
- Health Savings Account (HSA) with company contribution.
- Flexible Spending Account (FSA).