Cybersecurity Lead Analyst

15 hours ago


New York, New York, United States Nuveen, a TIAA company Full time $120,000 - $180,000 per year

This is a Non-Employee Contingent Worker Role providing services for TIAA's family of companies and will be employed by TIAA's preferred 3rd Party Supplier. As a Non-Employee CW, perform a variety of moderately complex business planning, support, and project-related duties. Demonstrates an exceptional standard of quality and holds themselves accountable to achieving excellent results.

This role will sit onsite, likely in a hybrid capacity, at the location(s) listed in this posting.

The anticipated term of this engagement will be 13 months. This term could be extended based on company business needs.

CW-Cyber Security Analyst III
The Sr. Info Security Analyst drafts, communicates, implements, enforces and monitors the organization's security controls to protect technology assets from intentional or inadvertent modification, disclosure or destruction. Under limited supervision, this job works independently to manage and monitor the organization's IT systems and networks to ensure the security and safety of the organization's information.

Key Responsibilities And Duties

  • Ensures implementation of secure operating systems, networks and databases for the organization.
  • Performs complex risk assessments and executes tests of data processing system to ensure functioning of data processing activities and security measures.
  • Drafts plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure and to meet emergency data processing needs.
  • Encrypts data transmissions and erect firewalls to conceal confidential information as it is being transmitted and to keep out tainted digital transfers.
  • Facilitates risk audits and assessments and provides recommendations for application design to ensure operating effectiveness.
  • Monitors analysis of system access logs, ensuring only permitted individuals have access to company information.
  • Reviews violations of computer security procedures and discusses procedures with violators to ensure violations are not repeated.
  • Trains users and promotes security awareness to ensure system security and to improve server and network efficiency.

Educational Requirements

  • University (Degree) Preferred

Work Experience

  • 3 Years Required; 5 Years Preferred

Physical Requirements

  • Physical Requirements: Sedentary Work

Career Level
7IC

Leadership & Strategy

  • Lead the cybersecurity team, providing mentorship, guidance, and performance management.
  • Develop and execute the organization's cybersecurity strategy aligned with business goals.
  • Collaborate with IT leadership and stakeholders to assess risk and define security priorities.

Microsoft Security Operations

  • Administer and optimize Microsoft Defender for Endpoint, Identity, Cloud Apps, and Office 365.
  • Manage and monitor Microsoft Sentinel for threat detection, incident response, and log analytics.
  • Implement and maintain Microsoft Purview for data governance, compliance, and information protection.
  • Oversee Entra ID (Azure AD) identity and access management, including Conditional Access and Privileged Identity Management (PIM).
  • Conduct regular reviews of security configurations and policies across Microsoft 365 and Azure environments.
  • Conduct monthly Attack Simulations

Threat Management & Incident Response

  • Lead threat hunting and incident response activities using Microsoft XDR and SIEM tools.
  • Develop and maintain playbooks for automated response in Sentinel and Defender.
  • Coordinate with internal teams and external partners during security incidents and investigations.

Governance, Risk & Compliance

  • Ensure compliance with industry standards (e.g., NIST, GDPR, LGPD, DORA, other local data privacy laws).
  • Conduct risk assessments and vulnerability scans; manage remediation efforts.
  • Maintain documentation for security policies, procedures, and audit readiness.

Training & Awareness

  • Promote security awareness across the organization through training and communication.
  • Stay current with emerging threats, vulnerabilities, and Microsoft security innovations.

Start Date: 17-Nov-2025

End Date: 31-Dec-2026

Travel Required: No

Anticipated Posting End Date
Base Pay Range: $38.13/hr - $57.21/hr

Actual base salary may vary based upon, but not limited to, relevant experience, time in role, base salary of internal peers, prior performance, business sector, and geographic location.

_____________________________________________________________________________________________________

Equal Opportunity
We are an Equal Opportunity Employer. TIAA does not discriminate against any candidate or employee on the basis of age, race, color, national origin, sex, religion, veteran status, disability, sexual orientation, gender identity, or any other legally protected status.

Our full EEO & Non-Discrimination statement is on our careers home page, and you can read more about your rights and view government notices here.

Accessibility Support
TIAA offers support for those who need assistance with our online application process to provide an equal employment opportunity to all job seekers, including individuals with disabilities.

If You Are a U.S. Applicant And Desire a Reasonable Accommodation To Complete a Job Application Please Use One Of The Below Options To Contact Our Accessibility Support Team

Phone:

Email:

Drug and Smoking Policy
TIAA maintains a drug-free and smoke/free workplace.

Privacy Notices
For Applicants of TIAA, Nuveen and Affiliates residing in US (other than California), click here.

For Applicants of TIAA, Nuveen and Affiliates residing in California, please click here.

For Applicants of TIAA Global Capabilities, click here.

For Applicants of Nuveen residing in Europe and APAC, please click here.

,

Leadership & Strategy

  • Lead the cybersecurity team, providing mentorship, guidance, and performance management.
  • Develop and execute the organization's cybersecurity strategy aligned with business goals.
  • Collaborate with IT leadership and stakeholders to assess risk and define security priorities.

Microsoft Security Operations

  • Administer and optimize Microsoft Defender for Endpoint, Identity, Cloud Apps, and Office 365.
  • Manage and monitor Microsoft Sentinel for threat detection, incident response, and log analytics.
  • Implement and maintain Microsoft Purview for data governance, compliance, and information protection.
  • Oversee Entra ID (Azure AD) identity and access management, including Conditional Access and Privileged Identity Management (PIM).
  • Conduct regular reviews of security configurations and policies across Microsoft 365 and Azure environments.
  • Conduct monthly Attack Simulations

Threat Management & Incident Response

  • Lead threat hunting and incident response activities using Microsoft XDR and SIEM tools.
  • Develop and maintain playbooks for automated response in Sentinel and Defender.
  • Coordinate with internal teams and external partners during security incidents and investigations.

Governance, Risk & Compliance

  • Ensure compliance with industry standards (e.g., NIST, GDPR, LGPD, DORA, other local data privacy laws).
  • Conduct risk assessments and vulnerability scans; manage remediation efforts.
  • Maintain documentation for security policies, procedures, and audit readiness.

Training & Awareness

  • Promote security awareness across the organization through training and communication.
  • Stay current with emerging threats, vulnerabilities, and Microsoft security innovations.


  • New York, New York, United States Agency Cybersecurity Full time $20 - $25

    Location: On-Site in Flatiron, NYCPosition Type: Hourly, Full-Time Experience Level: Entry-levelCompensation: $20-25 per hourJob Summary:As a junior cybersecurity analyst at Agency, you will be crucial in bridging the gap between technology, our customers, and our internal business operations. You will work closely with multiple stakeholders to provide...


  • New York, New York, United States Jane Street Full time $800,000 - $1,000,000 per year

    About the PositionWe're looking to add a passionate Cybersecurity Analyst to our New York office to help protect Jane Street's employees, data, and infrastructure from the wilds of the internet. Our Cybersecurity Analysts are responsible for developing and using monitoring tools to guard the firm, as well as handling incident response and remediation when a...


  • New York, New York, United States Agency Cybersecurity Full time $60,000 - $80,000 per year

    *About Agency Cybersecurity:*Agency Cybersecurity is fast growing ventured back startup that provides best-in-class cybersecurity and compliance. Our software and services simplify complex compliance frameworks including SOC2, ISO 27001, HIPAA, and others, empowering businesses to scale securely and confidently. We're backed by top tier investors like Y...


  • New York, New York, United States S-RM Full time $120,000 - $180,000 per year

    SENIOR CYBERSECURITY ANALYST (SOC)US Region (Remote / Hybrid)WHO WE ARES-RM is a global intelligence and cyber security consultancy. Since 2005, we've helped some of the most demanding clients in the world solve some of their toughest information security challenges.We've been able to do this because of our outstanding people. We're committed to developing...


  • New York, New York, United States DestinationNova Full time $40,000 - $60,000 per year

    Company DescriptionDestinationNova is a social impact startup dedicated to fighting human trafficking through technology, education, and community empowerment. We create AI-powered solutions to protect vulnerable children, detect trafficking patterns, support survivors, and educate families, educators, and law enforcement. Our goal is to bridge the gap...


  • New York, New York, United States News Corp Full time $150,000 - $170,000 per year

    Equal Opportunity EmployerAll qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, or disability status. EEO/Disabled/VetsJob Description :*Job Title: Senior Cybersecurity AnalystLocation - NYCHybrid - 3 days in office*As a global media and information...


  • New York, New York, United States InterSources Inc Full time $80,000 - $120,000 per year

    Job Title: Cybersecurity Analyst – Incident Response & Digital ForensicsLocation:NYC, NYDuration:12 MonthsWork Type:OnsiteWorking Hours:37.5 Hours/WeekJob Description:Client is seeking ahighly skilled Cybersecurity Analystspecializing inIncident Response and Digital Forensicsto join theIT Threat Intelligenceteam within theCyber Security Operations Center...


  • New York, New York, United States Metropolitan Transportation Authority Full time $95,929 - $153,731 per year

    Job ID: 12375Business Unit: MTA HeadquartersLocation: New York, NY, United StatesRegular/Temporary: RegularDepartment: IT Cyber SecurityDate Posted: Nov 3, 2025DescriptionJob InformationJob Title: Cybersecurity Analyst Critical Assets & Incident Response CERT Levels 3-5Salary Range: Level 3: $95,929 - $127,050Level 4: $102,760 - $139,755Level 5: $114,537 -...


  • New York, New York, United States Revature Full time $140,000 - $170,000 per year

    About the Role:TheCybersecurity Operations Analyst – DLPis responsible for overseeing all aspects of Data Loss Prevention (DLP) within the organization. This role focuses exclusively on developing and maintaining DLP policies, tuning DLP systems for optimal performance, and continuously monitoring DLP activities to prevent and detect unauthorized data...


  • New York, New York, United States GenuineXs - Cybersecurity Experts Full time $120,000 - $200,000 per year

    Position OverviewAs the Senior Manager of Security Engineering and Operations, you will build and manage a team of direct, indirect, and outsourced resources for the delivery of enterprise security operations services. You will provide operational leadership in the delivery of security services and the ability to adjust priorities based on changing...