CybersecurityJobs.io
← Back to all jobs

Job Description

The Cyber Security Analyst supports incident response, threat detection, vulnerability management, governance, risk and compliance, and security operations across DCAS infrastructure, applications, networks, and cloud environments, reporting to the CISO.

Responsibilities

  • Collaborate with the Agency CISO to ensure cybersecurity related change management and CI/CD practices meet NIST separation of duties requirements.
  • Support cyber awareness training, security onboarding and readiness assurance, and cloud-based application knowledge transfer for the agency.
  • Lead and coordinate cybersecurity incident response, digital forensics, malware analysis, threat hunting, containment, eradication, recovery, and post incident activities.
  • Monitor and analyze security events, alerts, logs, and threat intelligence using SIEM, endpoint protection, cloud security tools, and monitoring platforms.
  • Conduct vulnerability assessments, risk analyses, remediation tracking, validation testing, and reporting across infrastructure, applications, cloud environments, and endpoints.
  • Perform cybersecurity audits, control assessments, risk reviews, and compliance evaluations aligned with NIST CSF, NIST SP 800-53, CIS Controls, Zero Trust principles, and Citywide policies.
  • Develop and maintain cybersecurity policies, standards, procedures, playbooks, incident response plans, and operational documentation.
  • Support Identity and Access Management operations, including SSO, MFA, RBAC, access reviews, provisioning, deprovisioning, and privileged access governance.
  • Analyze cybersecurity metrics, trends, vulnerabilities, incidents, and operational performance indicators; produce executive level reports and recommendations.
  • Collaborate with internal technology teams, application owners, vendors, City agencies, and external partners to improve cybersecurity capabilities and remediation outcomes.
  • Assist with cloud security reviews, application security assessments, secure application onboarding, and software security initiatives.
  • Provide technical leadership, mentoring, and guidance to junior cybersecurity staff and cross functional stakeholders.
  • Assist with audit readiness, evidence collection, regulatory compliance activities, and cybersecurity governance initiatives.
  • Research emerging threats, technologies, attack techniques, and industry best practices to strengthen defensive capabilities.

Requirements

  • Baccalaureate degree in computer science, engineering or a related field plus four years of satisfactory full-time experience related to datacenter engineering and operations, cloud engineering and operations, or complex IT infrastructure engineering.
  • Baccalaureate degree in computer science, engineering or a related field plus eight years of satisfactory full-time experience related to datacenter engineering and operations, cloud engineering and operations, or complex IT infrastructure engineering.
  • Education and/or experience that is equivalent to either of the above options.

Technologies

  • Qualys
  • Wiz
  • Rapid7
  • Veracode
  • HCL AppScan
  • Snyk
  • CrowdStrike
  • Microsoft Defender
  • SolarWinds SEM
  • ServiceNow
  • Jira
  • GitHub Enterprise Copilot Security
  • GitHub Copilot
  • BitSight
  • Security Scorecard
  • Shodan
  • Microsoft Entra ID (Azure AD)
  • SAML 2.0
  • OAuth 2.0
  • OpenID Connect
  • Conditional Access
  • MFA
  • RBAC

Similar Jobs