New York, NY

Salary
$121,792–$210,092from the description
Posted
Jul 20, 2026
Location
New York, NY
Last confirmed open
Jul 20, 2026

What this job asks for AI summary

A senior individual contributor role within an IT controls and compliance function at a large academic health system. The position centers on leading enterprise risk assessments across cloud, clinical, and research environments, evaluating security controls against frameworks such as HIPAA, HITRUST, PCI DSS, and NIST. It suits an experienced information security professional comfortable driving program maturity, mentoring peers, and engaging cross-functional stakeholders without direct management authority.

Senior level · 10+ years · New York-Newark-Jersey City, NY-NJ-PA · Full-time

Must have (10)
HIPAAHITRUSTPCI DSSFISMANIST Cybersecurity FrameworkISO/IEC 27001cloud securityenterprise risk assessmentidentity and access managementdata encryption

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 200 people in the New York-Newark-Jersey City, NY-NJ-PA area plausibly meet what this posting asks for (information security analysts). range 40–300

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
identity and access management45%cloud security42%NIST Cybersecurity Framework40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $143,559 (middle half $110,181–$179,574). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (6)

The title 'Lead IT Security Analyst' carries no standard seniority level word (Lead here is a functional descriptor, not a band like Senior/Staff), so the title states no level. The actual scope — 10+ years required, senior escalation point, enterprise program ownership, cross-functional influence — firmly supports Senior.

The minimum qualification states 'BA/BS degree or equivalent,' meaning equivalent experience is explicitly accepted in lieu of a degree; degree requirement is therefore None.

Several skills extracted (HIPAA, HITRUST, PCI DSS, FISMA, NIST CSF, ISO 27001, cloud security, enterprise risk assessment, IAM, data encryption) are drawn from the core responsibilities and minimum qualifications sections, which describe the role's primary day-to-day work. The JD does not separate these into a distinct preferred/nice-to-have section.

Cloud environments are described in terms of IaaS, PaaS, and SaaS assessment — no specific cloud vendor (AWS, Azure, GCP) is named, so no vendor-specific cloud skill is emitted.

'Advanced degree desirable' is explicitly framed as preferred, not required.

The salary range ($121,792.22–$210,091.64 annually) is provided to comply with New York State salary transparency law and does not include bonuses or differential pay.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗