Syracuse, New York
Security Analyst
- Posted: September 30, 2026
- Employment Type: Direct Hire
- Job Category: IT - Security
- Job Number:
Job Description
Please no 3rd parties or C2C.
Must be a US Permanent Resident or Citizen.
We are unable to sponsor currently.
Job Title: Security Analyst
Location: New York State – Hybrid; periodic travel to regional offices required
Job Type: Full-time, direct hire
Salary Range: $95,000 – $105,000 annually depending on experience
About the Role:
A professional services organization is seeking a Security Analyst to support its Information Technology team and enterprise information security program. This role is responsible for helping protect confidential client, employee, and business information across enterprise systems, cloud platforms, endpoints, networks, and third-party services.
The Security Analyst will collaborate with IT teams, business professionals, vendors, and organizational leadership to identify, investigate, and reduce cybersecurity risk while supporting secure and efficient business operations. The position includes security monitoring, incident response, vulnerability management, identity and access security, data protection, governance, and security awareness responsibilities.
Participation in a 24×7 on-call rotation is required.
Key Responsibilities:
- Monitor security alerts and telemetry across SIEM, XDR/EDR, IDS/IPS, email security, identity, cloud, network, and vulnerability management platforms.
- Investigate suspicious activity, correlate security indicators, validate severity and impact, and document findings.
- Escalate security events and incidents based on risk, business impact, available evidence, and established procedures.
- Support cybersecurity incident identification, containment, eradication, recovery, and documentation.
- Assist with incident response playbooks, tabletop exercises, post-incident reviews, and lessons-learned activities.
- Recommend improvements to security detection rules, automation, workflows, and processes to reduce alert noise and improve detection effectiveness.
- Support recurring vulnerability scanning, risk prioritization, remediation tracking, and security exception documentation.
- Partner with infrastructure and application teams to remediate vulnerabilities based on exploitability, business criticality, and confidentiality risk.
- Develop security metrics and status reporting covering remediation progress, vulnerability aging, recurring issues, and barriers to resolution.
- Assist with access reviews, privileged access monitoring, conditional access controls, MFA compliance, and joiner/mover/leaver control validation.
- Support data protection through security monitoring, policy enforcement, encryption, data loss prevention, and secure collaboration practices.
- Identify access-control and configuration gaps that could affect confidentiality, information-separation requirements, or client security expectations.
- Maintain security documentation, standard operating procedures, control evidence, exception records, and management reporting materials.
- Support security operations, vulnerability management, identity governance, security awareness, and cybersecurity reporting initiatives.
- Apply recognized cybersecurity frameworks and standards to align security practices with organizational risk requirements.
- Translate technical security findings into clear, practical risk information for IT leadership and non-technical stakeholders.
- Support cybersecurity awareness programs, phishing simulations, targeted employee guidance, and security education.
- Identify recurring user-related security risks and recommend appropriate technical controls, process improvements, or training.
- Participate in a 24×7 security on-call rotation and assist with incident response outside normal business hours when required.
- Travel periodically to regional offices as business and security needs require.
Qualifications:
Education
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field.
- Equivalent combinations of relevant education, training, and professional experience may be considered.
Experience
- Minimum of 2 years of experience in cybersecurity, information security, security operations, or a related IT role.
- Experience monitoring and investigating security alerts and supporting cybersecurity incident response activities.
- Experience with vulnerability identification, prioritization, remediation tracking, and reporting.
- Experience working in environments that handle confidential, regulated, or business-sensitive information is preferred.
- Experience supporting a professional services, financial services, legal, healthcare, or similarly security-conscious organization is a plus.
Technical Skills
- Working knowledge of SIEM, IDS/IPS, EDR/XDR, vulnerability scanning, identity security, email security, and related monitoring technologies.
- Understanding of security incident response processes, including identification, containment, eradication, recovery, and post-incident analysis.
- Knowledge of identity and access management concepts, including MFA, privileged access, conditional access, and access reviews.
- Familiarity with cloud security, endpoint security, network security, encryption, data loss prevention, and secure collaboration technologies.
- Familiarity with cybersecurity frameworks and standards, including NIST, ISO 27000-series standards, and COBIT.
- Working knowledge of applicable security, privacy, and regulatory requirements, including HIPAA, PCI DSS, SOX, DFARS, FISMA, and relevant financial-services cybersecurity requirements.
- Ability to analyze security telemetry, correlate indicators across multiple technologies, and distinguish legitimate activity from potentially malicious behavior.
- Ability to create and maintain technical documentation, incident records, security metrics, and management reporting.
Certifications
- Relevant cybersecurity certification is preferred, such as Security+, CySA+, GSEC, SSCP, or an equivalent industry-recognized credential.
- Additional security, cloud, networking, or vendor-specific certifications are a plus.
Soft Skills
- Strong analytical, investigative, and problem-solving skills.
- Clear written and verbal communication skills with the ability to document technical findings accurately.
- Ability to communicate cybersecurity risks and recommendations effectively to both technical and non-technical stakeholders.
- Strong organizational skills with the ability to manage multiple security priorities and follow established escalation procedures.
- Ability to collaborate effectively with IT teams, business professionals, vendors, and organizational leadership.
- Sound judgment when handling confidential, sensitive, or security-related information.
- Ability to participate reliably in a 24×7 on-call rotation and respond to time-sensitive security incidents.
Why Join Us?
This position provides the opportunity to contribute to a broad information security program within a professional services environment where protecting confidential information is a core business requirement. The Security Analyst will gain exposure to security operations, incident response, vulnerability management, identity security, data protection, governance, and security awareness while working closely with technical teams and organizational leadership.
The role offers opportunities to expand cybersecurity expertise, contribute to security program improvements, and take on increasing responsibility as the organization’s security capabilities continue to mature.
ISSI Technology Professionals celebrates diversity. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
We’re Here to Help
Getting to Know You
Let’s connect you with your next big opportunity. Your next career move starts here.
Helping You Succeed
Discover tools and tips to help you stand out. We’ve got your back every step of the way.