NYU Langone Health · New York, NY

Salary
$97,590–$142,988from the description
Posted
Jun 28, 2026
Location
New York, NY
Last confirmed open
Jul 20, 2026

What this job asks for AI summary

A senior vulnerability management role within a hospital system's Penetration Testing and Vulnerability Management team. Day-to-day work centers on running and analyzing scans with Rapid7 InsightVM, coordinating remediation with infrastructure and application teams, supporting secure coding practices via Checkmarx, and administering the servers that underpin these tools. The role suits an experienced IT security professional with a background in healthcare or academic medical environments.

Senior level · 6+ years · New York-Newark-Jersey City, NY-NJ-PA · Bachelor's required · Full-time

Must have (5)
Rapid7 InsightVMCheckmarxIvantivulnerability scanningscripting
Nice to have (2)
penetration testingapplication security

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What gives you an edge
Checkmarx4%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
vulnerability scanning55%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $140,470 (middle half $107,810–$175,710). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (7)

The title 'Sr. II Security Analyst' is an internal leveling convention; it is treated here as a Senior-level role.

A Master's degree is explicitly stated as preferred, not required — the hard gate is a Bachelor's degree.

The 6-year minimum experience requirement is stated in the context of IT security policy, compliance, and GRC in healthcare/academic medical centers specifically, which is a meaningful domain constraint not fully captured by the years figure alone.

Scripting and macro writing are called out as job responsibilities with firm language ('as needed'), not under a preferred/nice-to-have section, so they are treated as required; no specific language is named.

Penetration testing and application security appear as team context and job responsibilities respectively, but the JD does not gate candidates on prior experience in these areas with firm language, so they are marked preferred.

Rapid7 InsightVM, Checkmarx, and Ivanti are all named explicitly in the responsibilities as tools the analyst will actively use and manage.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): threat intelligence analysis.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗