Job Title: \- Cyber Security Analyst
Location: New York, NY
Job Type: Contract
Work schedule: Normal business hours Monday-Friday 9am to 5pm Est, 35 hours/week (not including mandatory unpaid meal break after 6 hours of work).
Duration: 12 Months
Pay Rate: $50 per hour
Detailed job description
We are seeking an appropriately qualified vendor to provide cyber security analysts to work both in-person and, if needed, remotely. NYC agency anticipates that two (2) analysts will be needed at the time of contract registration, but the Agency may require, and the vendor would be expected to provide additional resources during the contract term. These analysts are needed for assistance with designing secure cloud infrastructure and managing standard cybersecurity review, response, and maintenance for the networks and software solutions currently being installed at the new Health facility currently undergoing construction in the Harlem neighborhood and at all NYC locations. The analysts will coordinate efforts with the agency and external construction teams, equipment vendors, and other specialists during hardware deployment and network setup. The analyst’s expertise in cloud security and risk management will help maintain network connectivity and security for newly installed IT solutions at locations and the new facility during, and after, construction, and allow lab operations to begin in accordance with agency timelines and standards.
Scope of Services:
The Contractor/cybersecurity analyst would perform a variety of services, both in-person at NYC locations and, if needed, remotely, including but not limited to:
• Identifying and mitigating complex IT technical threats to computer systems, networks, and data.
• Using technical IT tools and IT software to monitor, analyze, and defend against cyberattacks.
• Monitoring and analyzing network traffic, configuring firewalls, intrusion detection/prevention systems and conducting vulnerability assessments.
• Managing and protecting endpoints such as desktops, laptops, servers, and mobile devices from malware, ransomware, and other threats.
• Investigating security incidents, identifying root causes, and implementing corrective actions to prevent future occurrences.
• Utilizing SIEM tools to collect, correlate and analyze security event data for threat detection and responses.
• Monitoring and analyzing emerging threats, vulnerabilities, and attack vectors to proactively defend against cyber threats.
• Performing Penetration testing.
• Keeping abreast of the latest security, privacy, and regulatory concerns and best practices impacting third party risk management.
• Advising the agency on any changes requested by third parties to security and privacy provisions of agreements or contracts.
• Collaborating with IT project management and operational teams to design secure cloud infrastructure plans and services.
Performing analysis on the security of all cloud services, including but not limited to: AWS, Microsoft Azure, Google, etc.
• Providing subject matter expertise on cloud security, automation, and virtualization.
• Developing, documenting, and validating policies, processes, and procedures relating to a variety of cloud concepts and standards.
• Developing cloud security metrics to analyze risks and identify potential opportunities to reduce vulnerabilities.
• Collaborating with all parties and the city’s Cyber Command Center to obtain cloud solution dispositions and update agency inventory lists.
Experience and Organizational Capability:
The contractor/cybersecurity analyst would have the following credentials, organizational capability, and/or experience: