Security Analyst
Cybersecurity Tools
Edr And Xdr
Email Security
Identity and Access Management
Incident Response
Information Security
InfoSec
Intrusion Detection And Prevention
Risk Management
Security Compliance
Security Information And Event Management
Security Monitoring
Security Operations
Security Standards
Threat Detection
Vulnerability Management
Job Description
Bond, Schoeneck & King is hiring a full-time Security Analyst to support the Information Technology Department and strengthen the firm’s information security program. This hybrid role is based in Buffalo, Albany, or Syracuse, NY, with responsibilities spanning security monitoring, incident response, vulnerability and identity management, and governance and compliance support.
Key Responsibilities
- Monitor, investigate, and respond to security events using sound judgment, clear documentation, and timely escalation.
- Support maturation of security operations, including vulnerability management, identity governance, security awareness, and reporting capabilities.
- Convert technical security findings into practical risk language for IT leadership and non-technical stakeholders.
- Monitor alerts and telemetry from SIEM, XDR/EDR, email security, identity systems, cloud, network, and vulnerability management platforms.
- Triage suspicious activity by validating severity, correlating indicators, and documenting findings in incident or case records.
- Recommend tuning, automation, and process improvements to reduce alert noise and improve detection quality.
- Assist with identification, containment, eradication, recovery, and post-incident documentation for cybersecurity incidents.
- Escalate material events with evidence, impact assessment, business context, and recommended next steps.
- Contribute to playbooks, tabletop exercises, lessons learned, and continuous improvement of incident response procedures.
- Support recurring vulnerability scanning, risk prioritization, remediation tracking, and exception documentation.
- Work with infrastructure and application teams to address vulnerabilities based on exploitability, business criticality, and client confidentiality risk.
- Provide status updates and metrics covering remediation progress, aging risk, recurring issues, and barriers to closure.
- Support access reviews, privileged access monitoring, conditional access, MFA compliance, and joiner/mover/leaver control validation.
- Help protect sensitive firm and client information through monitoring, policy enforcement, encryption, data loss prevention, and secure collaboration practices.
- Identify access or configuration gaps that may impact confidentiality, ethical wall obligations, or client expectations.
- Maintain security documentation, standard operating procedures, control evidence, expectation records, and management reporting materials.
- Use recognized security frameworks and standards to align security practices with the firm’s risk tolerance and professional services expectations.
- Support security awareness campaigns, phishing simulations, targeted guidance, and practical education for attorneys and staff.
- Support identifying recurring user behavior risks and recommend training, technical controls, or process refinements.
Required Qualifications
- Bachelor’s Degree in cyber security, computer science, engineering, or related field (required).
- 2+ years of experience in a cybersecurity or IT role.
- Security certifications such as Security+, CySA+, SSCP, CISSP Associate, AZ-500, SC-200, SC-300, or similar credentials.
- Proficiency using cybersecurity tools including SIEM, IDS/IPS, EDR, and vulnerability scanners.
- Strong analytical and problem-solving skills, including the ability to analyze complex data and identify patterns and anomalies.
- Excellent verbal and written communication skills, with the ability to communicate technical information to non-technical stakeholders.
- High attention to detail and accuracy, including the ability to work under pressure and manage multiple tasks.
- Ability to work effectively as part of a team and collaborate across departments.
- Knowledge of information security frameworks including ISO 27000, NIST, or COBIT.
- Knowledge of security standards such as HIPAA, NIST, PCI, SOX, DFARS, FISMA, NYDFS, and others.
- Participation in a 24x7 on call rotation.
- Some travel may be required to Regional Offices.
Technology Stack
- SIEM (Security Information and Event Management)
- XDR/EDR
- Email security
- Identity systems
- Cloud and network platforms
- Vulnerability management platforms
- IDS/IPS (Intrusion Detection System/Intrusion Prevention System)
- Vulnerability scanners
- ISO 27000, NIST, COBIT
- HIPAA, PCI, SOX, DFARS, FISMA, NYDFS
Hybrid Location
- Buffalo, NY
- Albany, NY
- Syracuse, NY
Compensation
$95,000 - $105,000 per year, negotiable based on years’ experience.
Offer Contingencies
- Completion of a satisfactory conflicts check
- Completion of a satisfactory background check
- Completion of a satisfactory reference check