Vulnerability Analyst

2 months ago


New York, New York, United States Bloomberg Full time
Vulnerability Analyst - Data & Systems
New York, NY

Our Team:
The Threat and Vulnerability Management Team (TVM) is dedicated to making our systems and technologies as secure as possible. We protect Bloomberg.

We partner with internal technical departments to ensure the confidentiality, integrity, and availability of Bloomberg systems and the data we process.

We aim to ensure that our clients see us as a trusted partner.

We report to the Chief Information Security Office (CISO) who owns the technical aspects of this mission by ensuring Bloomberg products, systems, networks and commercial applications are built and maintained with security in mind.

We work on purpose. Come find yours.
What's the role?

We are seeking an IT Security Analyst for our TVM Data & Systems team to help ensure that our IT infrastructure and security processes are resilient against the latest threats.

You will be responsible for analyzing and assessing vulnerabilities across a wide range of technologies. You'll engage with various technology partners to validate and manage identified vulnerabilities through remediation.

You will work directly with other cross-department security engineering and incident response teams to set strategic direction for our enterprise Threat and Vulnerability Management program.

This is a team that drives company-wide initiatives to improve the effectiveness of Bloomberg's security posture. Analysts in this role must show exemplary judgment in making technical decisions to achieve business goals. You're expected to always demonstrate resilience and navigate difficult situations with composure and tact.

We'll trust you to:
Perform IT Security assessments and partner with other security or IT professionals to assess potential impact from vulnerabilities and determine appropriate mitigating controls
Build strong partnerships with technical teams to promote best practices for managing vulnerabilities, initiate and track remediation through to completion
Understand business requirements and work with business partners to define appropriate solutions; meeting both security mandates and business needs
Help standardize and automate work-flows, processes, procedures and reporting
Produce metrics and key performance indicators that demonstrate the effectiveness of the team's remediation efforts across the enterprise
Improve the design and usefulness of our IT Security management tools and solutions
Have excellent interpersonal and effective communications skills

You'll need to have:
3+ years of IT operations, systems management, or IT Security related experience
Hands-on expertise working with enterprise architectures
Understanding of Linux and Windows OS, system administration or software development
Knowledge of IT Operations, security, and system hardening best practices
Solid understanding of Public Cloud infrastructure concepts and terminologies
Experience analyzing vulnerability findings from IT and Security management tools
Understanding of industry standards such as CVE, CPE, CVSS & NIST
Ability to interpret complex data sets to make informed risk-based decisions
Strong organizational skills and can effectively manage complex tasks, projects, and agile framework

We'd love to see:
Solid understanding of Risk management frameworks and security tools
Ability to learn and implement technologies quickly
Programming experience developing utilities and tools with Python or shell scripting
Experience with DBMS, RDBMS and ETL methodologies.
Proficiency with systems configuration and automation technologies, such as Ansible
Knowledge of business intelligence reporting tools such as QlikSense.
Bachelor's degree in Computer Science, Engineering, or other related fields

Salary Range: 135, ,000 USD Annually + Benefits + Bonus

  • New York, New York, United States Assurant Full time

    Linux Systems Vulnerability AnalystAbout Assurant:Assurant, Inc. stands as a premier provider of business solutions tailored for the interconnected world. Our comprehensive lifestyle and housing services empower leading brands to enhance revenue, mitigate risks, and deliver exceptional customer experiences. We engage with over 300 million consumers globally,...


  • New York, New York, United States Assurant Full time

    Linux Systems Analyst - Vulnerability ManagementAbout Assurant:Assurant, Inc. stands as a prominent global provider of business services tailored for the interconnected world. Our solutions in lifestyle and housing empower leading brands to enhance revenue, mitigate risks, and deliver exceptional experiences to their clientele. We engage, connect, and...


  • New York, New York, United States Schonfeld Full time

    Senior Cybersecurity Analyst The RoleThe Schonfeld Cybersecurity Operations Team is looking for individuals who are excited by the idea of finding threats in ways no other defense mechanism can, eradicating threats, and building new intelligence to prevent future attacks from succeeding. This Cybersecurity Analyst will be responsible for improving the...


  • New York, New York, United States PGMTEK Inc. Full time

    Job Overview We are seeking an experienced Senior Cybersecurity Analyst to join our team at PGMTEK Inc. This role involves a long-term engagement focused on safeguarding our digital infrastructure.KEY RESPONSIBILITIES: Cybersecurity Expertise - 5-7 years of relevant experience. Formulate and execute a robust cybersecurity framework and policies to secure...


  • New York, New York, United States MORS Full time

    Position OverviewThe role of the Information Security Analyst Tier 1 at MORS focuses on executing fundamental threat detection and incident response tasks to uphold the organization's security integrity. Responsibilities include identifying and alleviating security vulnerabilities by scrutinizing security events and alerts, implementing incident response...


  • New York, New York, United States Berrysoft Consulting Full time

    NYS Department of Financial Services- 30 Months - One State Street Plaza, Second Floor, New York, NY % remoteShort description:The Security Analyst will directly support the New York State Department of Financial Services (DFS) Information Security Program, responsible for ensuring the confidentiality, integrity, and availability of information and...


  • New York, New York, United States Allen Rose Group Full time

    Position Overview The Senior Cybersecurity Analyst will report directly to the Chief Risk Officer. This role is pivotal in overseeing adherence to our information security framework throughout the entire organization.Key Components of the Security Framework:firewall management, secure data transmission, advanced malware defense, data loss mitigation,...


  • New York, New York, United States Quanta Tech Systems LLC Full time

    Job OverviewCompany: Quanta Tech Systems LLCPosition: Cybersecurity Operations AnalystLocation: RemoteStatus: Full Time ContractorCompensation: Competitive, based on experienceRole SummaryQuanta Tech Systems LLC, a prominent technology firm, is in search of a proficient Cybersecurity Operations Analyst to enhance our cybersecurity division. This pivotal...


  • New York, New York, United States PRI Technology Full time

    Principal Cybersecurity AnalystLocation: New York, NY - Onsite work requiredEmployment Type: Full Time/Permanent (No third-party applications accepted, candidates must not require sponsorship). The Principal Cybersecurity Analyst plays a pivotal role in spearheading the deployment of the organization's cybersecurity measures. This position involves the...


  • New York, New York, United States Anetac, Inc. Full time

    Job OverviewPosition: Senior Cybersecurity AnalystLocation: Remote (United States and Canada)Department: Anetac LabsReporting To: Head of Global EngineeringCompensation: Competitive salary based on experience.About Anetac, Inc.: Anetac is committed to revolutionizing the management of identities and service accounts within the cybersecurity landscape. With a...


  • New York, New York, United States Goldman Sachs Full time

    VICE PRESIDENT: MARKET RISK ANALYSTWe are looking for a skilled professional to take on the role of Market Risk Manager with a focus on the Mortgages and Structured Products sector. The ideal candidate will possess a robust academic foundation in Finance, Mathematics, or a related field, along with 7-10 years of relevant experience in market risk...


  • New York, New York, United States Mhymatch Inc Full time

    About the Role: As an Information Security Analyst at Mhymatch Inc, you will play a crucial role in protecting our organization's digital assets and ensuring the integrity of our information systems. Location: Remote Company Overview: Mhymatch Inc is a leading firm in the realm of cybersecurity, dedicated to delivering innovative solutions that safeguard...


  • New York, New York, United States Providge Consulting Full time

    Job DescriptionJob Title: Senior Business Systems AnalystJob Type: Part-timeLocation: RemoteJob Summary:Providge Consulting is seeking a highly skilled Senior Business Systems Analyst to play a critical role in the modernization of our client's legacy applications. As a key member of our team, you will lead the comprehensive analysis, documentation, and...


  • New York, New York, United States Beacon Hill Inc Full time

    IT Compliance and Security AnalystContract OpportunityCompensation: $75/hour, W2Work Arrangement: Hybrid (4 days/week onsite)Key Responsibilities:Compliance Evaluation: Conduct thorough assessments across all IT security control domains to ensure adherence to both external obligations and internal policies.Assessment Management: Oversee the planning,...

  • Financial Analyst

    5 days ago


    New York, New York, United States Urban Pathways, Inc. Full time

    Job OverviewCompensation based on experience.Work Model: 4 days in-office, 1 day remote.Join Urban Pathways in our mission to illuminate the journey home for individuals in need.About Urban Pathways, Inc.Founded in 1975, Urban Pathways has dedicated itself to assisting New York City's most vulnerable populations, those experiencing homelessness or residing...


  • New York, New York, United States Stellar Full time

    Are you passionate about safeguarding innovative blockchain technology enterprises and promoting fair access to the global financial landscape? The Stellar Development Foundation (SDF) has been on a mission since 2014 to support the expansive growth of the Stellar blockchain network, an open-source platform that operates at a high scale today. With the...


  • New York, New York, United States Noor Staffing Group Full time

    Salary: $125,000-$145,000Work Arrangement: On-Site Monday-Thursday / Remote FridaysPlease note that candidates must reside in the local area as relocation is not an option for this position.The Cybersecurity Specialist plays a crucial role in safeguarding, managing, and overseeing the security of the organization's enterprise infrastructure and network...


  • New York, New York, United States Considine Search Full time

    OverviewThe Senior Risk and Compliance Analyst will be responsible for safeguarding the integrity, confidentiality, and availability of the organization's information through comprehensive risk evaluations, audits, control assessments, policy formulation, and compliance efforts. The ideal candidate will engage in various governance, risk, and compliance...


  • New York, New York, United States Considine Search Full time

    OverviewThe Senior Risk and Compliance Analyst at Considine Search is responsible for safeguarding the integrity, confidentiality, and availability of the organization's information through comprehensive risk evaluations, audits, control assessments, policy formulation, and compliance initiatives. The ideal candidate will engage in various governance, risk,...


  • New York, New York, United States Noor Staffing Group Full time

    This position is based in a dynamic environment focused on safeguarding information assets.Please be aware that sponsorship is not available for this role, and we are not considering contract-to-contract candidates.The key responsibilities of this position involve identifying and evaluating security vulnerabilities, working collaboratively with various...