Cyber Security Analyst at City of New York
New York City, NY
—
Jul 28, 2026
New York City, NY
Jul 29, 2026
What this job asks for AI summary
This role at the NYC Department of Citywide Administrative Services sits within the IT team and reports to the agency CISO. Day-to-day work spans cybersecurity incident response, digital forensics, threat hunting, vulnerability management, SIEM-based monitoring, and GRC activities aligned to NIST and CIS frameworks. The position also supports cloud security reviews, IAM operations, policy development, and provides technical mentorship to junior security staff.
Senior level · 4+ years · New York-Newark-Jersey City, NY-NJ-PA · Bachelor's required · Full-time
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 35 people in the New York-Newark-Jersey City, NY-NJ-PA area plausibly meet what this posting asks for (information security analysts). range 8–55
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $143,559 (middle half $110,181–$179,574).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 29, 2026. It is a model, not a headcount.
Why we read it this way (6)
The title is 'IT Infrastructure Engineer' but the role's primary day-to-day work — incident response, digital forensics, threat hunting, SIEM monitoring, vulnerability management, and GRC — is squarely security analysis (15-1212). The infrastructure framing in the title and the civil-service job class code (95714) reflect NYC government classification conventions rather than the actual work performed; 15-1244 is noted as the runner-up given the title.
The minimum experience requirement is 4 years with a CS-related bachelor's degree, or 8 years with any bachelor's degree. The lower threshold (4 years) is used for the overall years minimum.
No compensation figures are stated in the posting.
All skills are drawn from the body of the job description's responsibilities section, which functions as the requirements block for this civil-service posting. No separate 'Preferred' or 'Nice to have' section exists.
The posting lists no specific named security products (e.g., Splunk, CrowdStrike, Tenable) — only capability categories such as SIEM and endpoint protection are named.
Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): malware analysis, NIST SP 800-53.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.