Job Title: Cybersecurity Senior Risk Analyst
Labor Category: Specialist 2
Location: 15 MTC Brooklyn NY \- Remote Tuesdays & Fridays (3 days in office/2 days remote) Hybrid
Job Type: Contract
Work schedule: Normal business hours Monday-Friday 35 hours/week (not including mandatory unpaid meal break after 6 hours of work.
Duration: 24 Months
Pay Rate: $50 to $60 per hour
Job Description /Justification
The Senior Risk Analysts will be responsible for implementing tools and practices to enhance processes related to third-party risk management, risk assessment, and general cyber risk governance. The position requires a diverse background in governance, risk, and compliance; analysis; technology implementation; project management; and collaboration with diverse groups of stakeholders to strengthen the security posture of New York City agencies.
The Senior Risk Analysts will be expected to continue building an effective Citywide Cybersecurity risk program. These analysts will be responsible for improving our risk assessment process to make it more user-centric, interviewing and communicating with agencies when performing risk assessments, and driving creation of a third-party vendor register and monitoring process. Analysts will review and analyze technologies for inventorying third parties, collaborate with SMEs to collect third party intelligence and define actions based on it, and design steps for reviewing existing third parties in our portfolio.
Delays in onboarding practitioners with expertise in these areas will leave unaddressed gaps in our risk governance framework. As NYC’s reliance on third party vendors continues to grow it is imperative for the City to have a vendor management practice, which does not only review vendors at the front end of the procurement process but actively manages risk throughout the vendor lifecycle. According to the 2025 Verizon Data Breach Investigations Report, 30% of breaches were linked to third party involvement (twice as many as in 2024). Maintaining our status quo can open up the City and agencies to lawsuits or audit findings (e.g. IRS, City Comptroller). If the City sustains a substantial cyber incident that results in loss of life or significant financial losses, it is not uncommon for individuals and organizations that are negatively impacted to file lawsuits against organizations that are responsible for defending/protecting critical information and critical services. The City would not be able to defend itself as having exercised due diligence in the protection of data and services without the existence of and proper functioning of a mature cyber risk program.
Not having a user-centric risk assessment process drains resources from City agencies and the Audit & Compliance team due to questions being misunderstood. This also causes inaccuracies in submitted information, which leads to risk being misevaluated and mismanaged.
SCOPE OF SERVICES
TASKS:
MANDATORY SKILLS/EXPERIENCE Note: Candidates who do not have the mandatory skills will not be considered – MINIMUM OF 12 YEARS EXPERIENCE:
DESIRABLE SKILLS/EXPERIENCE: