Lead Cybersecurity Threat Analyst

2 weeks ago


New York, New York, United States Consolidated Edison Company of New York, Inc. Full time
Overview


The Cybersecurity Red Team at Consolidated Edison is dedicated to executing real-world attack simulations and adversarial assessments to safeguard critical infrastructure across the nation. Our mission is to proactively uncover attack vectors that could compromise sensitive data or disrupt services.

Our activities encompass a wide range of operations, from standard penetration testing to intricate, tailored scenarios aimed at circumventing security measures, evading detection, and gaining unauthorized access to sensitive information.

This initiative is in its early stages, and all team members are encouraged to contribute to the evolution of the program and to devise innovative attack scenarios.

Our scope includes ConEd's cloud environments, publicly accessible services, internal IT and operational technology infrastructure, as well as customer-facing and internal applications.

Red Team members will analyze trends, scenarios, and the evolving threat landscape, collaborating with broader cybersecurity and infrastructure teams to address both immediate and ongoing needs.

Additionally, the team plays a vital role in providing guidance to blue team counterparts, enhancing the overall security posture and capabilities of the organization's cybersecurity program.

Core Responsibilities


As a senior technical resource, you will mentor team members and play a key role in the development of the ConEd Red Team Program.

Under the supervision of management and the lead analyst, you will competently conduct a variety of penetration testing, red team, and social engineering assessment activities that mirror real-world adversarial attacks.

Collaborate with key stakeholders to formulate assessment strategies.

Produce precise documentation that clearly explains findings, including technical walkthroughs, root causes, impacts, and remediation strategies.

Continuously enhance your skills to deliver advanced assessments.

Develop scripts and tools to automate repetitive tasks and improve efficiency.

Stay informed about tactics, techniques, and procedures (TTPs), global security incidents, industry trends, advisories, publications, and other relevant developments.

Effectively convey technical concepts to non-technical audiences.

Work with business owners to address findings and ensure successful implementation of changes.

Represent the department within the company and industry through research, presentations, publications, and training.

Assist in developing internal methodologies and improving processes for the team, including mentoring and knowledge transfer among team members.

Collaborate with blue teams to enhance detection and response capabilities.

Qualifications


Required Education/Experience:

High School Diploma/GED with a minimum of five (5) years in information security, including at least one (1) year in a red team or penetration testing role. Utility industry experience is preferred.

Alternatively, an Associate's Degree with a minimum of four (4) years in information security, including at least one (1) year in a red team or penetration testing role, is acceptable.

Or, a Bachelor's Degree with a minimum of three (3) years in information security, including at least one (1) year in a red team or penetration testing role, is also acceptable. Utility industry experience is preferred.

Preferred Education/Experience:


Bachelor's Degree in Information Technology, Computer Science, Mathematics, Engineering, or related fields.

Master's Degree in Information Technology, Computer Science, Mathematics, Engineering, or related fields.

Skills and Abilities


Strong written and verbal communication skills.

Ability to manage multiple projects to successful completion.

Capable of developing and delivering effective presentations.

Licenses and Certifications


Driver's License is required.

Certifications such as OSWP, OSCP, OSCE, OSEP, OSWE, OSED, OSEE, GPEN, GCIH, GPXN, GWAPT, GMOB, GAWN, GCPN, and similar are preferred.

Physical Demands


Must be able to push, pull, and lift up to 25 pounds.

Must be able to sit or stand to use a keyboard, mouse, and computer for the entire shift.

Equal Opportunity Employer:

Consolidated Edison is an equal opportunity employer, committed to recruiting, hiring, training, and promoting individuals in all job classifications without regard to race, color, creed, religion, sex, gender, age, national origin, marital status, sexual orientation, gender identity, gender expression, citizenship, eligible veteran status, disability, or any other status protected by law.



  • New York, New York, United States Crescens Full time

    Job Title: Cybersecurity Threat Modeling Integration Specialist Location: Remote Duration: 8 Months ContractOverview: The selected candidate will play a pivotal role in enhancing the security measures of Crescens by improving prevention, detection, response, and recovery strategies through various technical and operational methodologies. The objective is to...


  • New York, New York, United States Quanta Tech Systems LLC Full time

    Job OverviewCompany: Quanta Tech Systems LLCPosition: Cybersecurity Operations AnalystLocation: RemoteStatus: Full Time ContractorCompensation: Competitive, based on experienceRole SummaryQuanta Tech Systems LLC, a prominent technology firm, is in search of a proficient Cybersecurity Operations Analyst to enhance our cybersecurity division. This pivotal...


  • New York, New York, United States Citigroup Inc Full time

    Organization Overview:Citi, a premier global financial institution, serves approximately 200 million customer accounts across more than 160 countries and jurisdictions. We offer a diverse array of financial products and services, including consumer banking, corporate and investment banking, securities brokerage, transaction services, and wealth management.As...


  • New York, New York, United States ESTÉE LAUDER COMPANIES Full time

    About Estée Lauder CompaniesThe Estée Lauder Companies is a renowned leader in the prestige beauty industry, offering a wide range of high-quality beauty products that aim to enhance and celebrate individual beauty. With a strong focus on makeup, skin care, fragrance, and hair care, our diverse portfolio includes over 25 brands distributed in numerous...


  • New York, New York, United States Jane Street Full time

    About the RoleWe're seeking an experienced cybersecurity professional to join our team at Jane Street as a Senior Incident Responder and Forensic Investigator. The ideal candidate will have a strong background in responding to and investigating complex cyber incidents, with a focus on threat hunting and digital forensics.Our cybersecurity team is a...


  • New York, New York, United States Jane Street Full time

    About the RoleWe're seeking an experienced cybersecurity professional to join our team at Jane Street as a Senior Incident Responder and Forensic Investigator. The ideal candidate will have a strong background in responding to and investigating complex cyber incidents, with a focus on threat hunting and digital forensics.Our cybersecurity team is a...


  • New York, New York, United States Cox Communications Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Analyst II to join our team at Cox Communications. As a key member of our security team, you will be responsible for evaluating, proposing, and implementing enterprise-class technology and processes to optimize security and mitigate threats as they emerge.Key ResponsibilitiesEvaluate and propose...


  • New York, New York, United States Anetac, Inc. Full time

    Job OverviewPosition: Senior Cybersecurity AnalystLocation: Remote (United States and Canada)Department: Anetac LabsReporting To: Head of Global EngineeringCompensation: Competitive salary based on experience.About Anetac, Inc.: Anetac is committed to revolutionizing the management of identities and service accounts within the cybersecurity landscape. With a...


  • New York, New York, United States ST2 ManTech Advanced Systems Intl Full time

    Job DescriptionSecure Our Nation, Ignite Your FutureAt ST2 ManTech Advanced Systems Intl, we are seeking a highly motivated and experienced Cybersecurity Engineer to join our team. As a Cybersecurity Engineer, you will play a critical role in supporting the U.S. Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA)...


  • New York, New York, United States SideRamp Full time

    Job OverviewAbout SideRampSideRamp is dedicated to facilitating part-time opportunities within the gig economy, providing a comprehensive platform that connects professionals with high-quality, flexible side gigs. Our mission is to link users to a variety of freelance and part-time roles, enhancing the experience from opportunity discovery to application...


  • New York, New York, United States SideRamp Full time

    Job OverviewAbout SideRampSideRamp is dedicated to connecting professionals with flexible part-time opportunities in the gig economy, providing a comprehensive platform that facilitates high-quality side gigs. Our mission is to link users with diverse freelance and part-time roles, simplifying the process of discovering and applying for these...


  • New York, New York, United States City of New York Full time

    Position OverviewThe Office of Technology and Innovation (OTI) is dedicated to harnessing technology to foster opportunities, enhance public safety, and improve governmental operations throughout New York City. OTI plays a pivotal role in delivering essential services such as affordable broadband, cybersecurity protection, and digital government solutions,...


  • New York, New York, United States FalconX Full time

    About the RoleFalconX is seeking a highly skilled and experienced Staff Security Lead to join our Red Team. As a key member of our cybersecurity team, you will play a critical role in enhancing our cybersecurity posture by leading sophisticated red team operations.Key ResponsibilitiesRed Team Operations: Plan, design, and conduct red team exercises that...


  • New York, New York, United States Lynx Technology Partners Inc Full time

    Position Overview We are seeking a skilled Cybersecurity Operations Analyst to join our dedicated team at Lynx Technology Partners. This role offers the flexibility of remote work, with the expectation of being onsite three days a week. It is essential for candidates to be local and able to commute to our office as necessary. Company Mission Lynx Technology...


  • New York, New York, United States Allen Rose Group Full time

    Position Overview The Senior Cybersecurity Analyst will report directly to the Chief Risk Officer. This role is pivotal in overseeing adherence to our information security framework throughout the entire organization.Key Components of the Security Framework:firewall management, secure data transmission, advanced malware defense, data loss mitigation,...


  • New York, New York, United States SideRamp Full time

    Job OverviewAbout SideRampSideRamp is dedicated to connecting professionals with flexible, part-time opportunities in the gig economy. Our platform streamlines the process of finding and applying for high-quality freelance work, ensuring that users can easily engage with various side gigs.Position SummaryAs a Mid-level Cybersecurity Analyst, you will play a...


  • New York, New York, United States Mitiga Full time

    Mitiga is in search of a seasoned Incident Response Analyst. We are looking for a subject matter expert in cyber incident response, threat detection, and forensic analysis, to contribute to our mission of delivering an innovative cybersecurity solution to the industry.In this position, you will engage in incident response investigations and threat detection...


  • New York, New York, United States Ascot Group Full time

    Job Overview This position offers a unique opportunity within Ascot Group, a leading organization in specialty risk underwriting. As a modern enterprise, Ascot operates through a network of interconnected global platforms, united by a shared mission: One Ascot. Our strength lies in our talented workforce, thriving in a collaborative, inclusive, and...


  • New York, New York, United States Tbwa ChiatDay Inc Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Engineer to join our team at Tbwa Chiat/Day Inc. As a Cybersecurity Engineer, you will play a critical role in ensuring the security and integrity of our systems and infrastructure.Key ResponsibilitiesConduct Security Assessments: Conduct thorough security assessments of our systems and...


  • New York, New York, United States PRI Technology Full time

    Principal Cybersecurity AnalystLocation: New York, NY - Onsite work requiredEmployment Type: Full Time/Permanent (No third-party applications accepted, candidates must not require sponsorship). The Principal Cybersecurity Analyst plays a pivotal role in spearheading the deployment of the organization's cybersecurity measures. This position involves the...