Security Analyst

Barclay Damon

$95K — $105K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in cyber security, computer science, engineering, or related field required
  • 2+ years of experience in a cybersecurity or IT role
  • Familiarity with cybersecurity tools like SIEM, IDS/IPS, EDR, and vulnerability scanners
  • Proficient in information security frameworks such as ISO 27000, NIST, and COBIT
  • Knowledge of security standards including HIPAA, NIST, PCI, SOX, DFARS, FISMA, NYDFS
  • Strong analytical and problem-solving skills
  • Excellent verbal and written communication skills

Responsibilities

  • Monitor and respond to security events, documenting findings and escalating issues as necessary
  • Help improve the firm's security operations and awareness capabilities
  • Translate technical security issues for IT leadership and non-technical stakeholders
  • Triage alerts from various security platforms and document relevant findings
  • Assist in identification, containment, and recovery from cybersecurity incidents
  • Support vulnerability scanning and remediation processes
  • Helps manage access and protect sensitive firm and client information

Benefits

  • Hybrid work opportunity with flexible office locations
  • Supportive work environment emphasizing community and professional engagement
  • Opportunities for professional development and growth
  • Participation in a 24x7 on-call rotation
  • Travel may be required to regional offices
Full Job Description
Bond, Schoeneck & King, PLLC, a law firm of 300 attorneys in over 30 practice groups, is accepting applications for a full-time Security Analyst to support our Information Technology Department. This position supports and advances the Firm's information security program by protecting confidential client, attorney, and business information across firm systems, cloud platforms, endpoints, networks, and third-party services. The Security Analyst partners with IT, attorneys, administrative departments, vendors, and leadership to reduce cyber risk while enabling the efficient practice of law. This is a hybrid opportunity that can be based out of the following office locations:Buffalo, NY, Albany, NY, Syracuse, NY.

Position Responsibilities
  • Monitor, investigate, and respond to security events with sound judgment, clear documentation, and timely escalation
  • Help mature the Firm's security operations, vulnerability management, identity governance, awareness and reporting capabilities
  • Translate technical security issues into practical risk language for IT leadership and non-technical stakeholders

Security Monitoring and Detect
  • Monitor alerts and telemetry from SIEM, XDR/EDR, email security, identity, cloud, network, and vulnerability management platforms
  • Triage suspicious activity, validate severity, correlate indicators, and document findings in clear incident or case records
  • Recommend tuning, automation, and process improvements to reduce noise and improve detection quality

Incident Response and Investigation
  • Assist with identification, containment, eradication, recovery and post-incident documentation for cybersecurity incidents
  • Escalate material events promptly with evidence, impact assessment, business context, and recommended next steps
  • Contribute to playbooks, tabletop exercises, lessons learned, and continuous improvement of incident response procedures

Vulnerability and Exposure Management
  • Support recurring vulnerability scanning, risk prioritization, remediation tracking, and exception documentation
  • Partner with infrastructure, application teams to address vulnerabilities based on exploitability, business criticality, and client confidentiality risk
  • Prepare status updates and metrics that show remediation progress, aging risk, recurring issues, and barriers to closure

Identity, Access, and Data Protection
  • Assist with access reviews, privileged access monitoring, conditional access, MFA compliance, and joiner/mover/leaver control validation
  • Support protection of sensitive firm and client information through monitoring, policy enforcement, encryption, data loss prevention, and secure collaboration practices
  • Identify access or configuration gaps that could affect confidentiality, ethical wall obligations, or client expectations

Governance, Risk, and Compliance Support
  • Maintain security documentation, standard operating procedures, control evidence, expectation records, and management reporting materials
  • Use recognized security frameworks and standards to help align security practices with firm risk tolerance and professional services expectations

Security Awareness and Advisory Support
  • Support security awareness campaigns, phishing simulations, targeted guidance, and practical education for attorneys and staff
  • Support identifying recurring user behavior risks and recommend training, technical controls, or process refinements

Job Requirements
  • Bachelor's Degree in cyber security, computer science, engineering, or related field is required
  • Security Certifications such as Security+, CySA+, SSCP, CISSP Associate, AZ-500, SC-200, Sc-300, or similar credentials.
  • Experience: 2+ years of experience in a cybersecurity or IT role.
  • Technical Skills: Proficiency in using cybersecurity tools such as SIEM (Security Information and Event Management), IDS/IPS (Intrusion Detection System/Intrusion Prevention System), EDR (Endpoint Detection and Response), and vulnerability scanners.
  • Analytical Skills: Strong analytical and problem-solving skills. Ability to analyze complex data sets and identify patterns and anomalies.
  • Communication Skills: Excellent verbal and written communication skills. Ability to communicate technical information to non-technical stakeholders.
  • Attention to Detail: High level of attention to detail and accuracy. Ability to work under pressure and manage multiple tasks simultaneously.
  • Team Player: Ability to work effectively as part of a team and collaborate with colleagues from various departments.
  • Proficiency in information security frameworks, including ISO 27000, NIST, or COBIT.
  • Knowledge of security standards such as HIPAA, NIST, PCI, SOX, DFARS, FISMA, NYDFS, and others.
  • Participate in a 24x7 on call rotation.
  • Some travel may be required to Regional Offices


At Bond, exceptional work product and a collegial work environment are cornerstones of our success. We are committed to the communities in which we live and work. Bond has long recognized the value, both to its team and to our communities, of active participation in and support of charitable, governmental, professional and community-based organizations. This position's salary range is between $95,000 to $105,000, negotiable based on years' experience.

An offer of employment from Bond is contingent on:
  • Completion of a satisfactory conflicts check
  • Completion of a satisfactory background check
  • Completion of a satisfactory reference check


Similar Jobs

More Jobs at Barclay Damon

More Information Technology Jobs

Find similar Security Analyst jobs: