Cybersecurity Analyst SOC Levels
Listed on 2025-12-06
-
IT/Tech
Cybersecurity, Information Security
Location: New York
Job Title: Cybersecurity Analyst SOC Levels 3-5
Salary Range: Level 3: $95,929 - $127,050
Level 4: $102,760 - $139,755
Level 5: $114,537 - $153,731
Level 4 - 451
Level 5 – 551
DEPT/DIV: MTA Information Technology/ Office of ITCyber
Security Services
SUPERVISOR :
Cyber Security Officer, Monitoring
LOCATION: 2 Broadway, New York, NY 10004
HOURS: 12:00am – 8:30am (7.5hours/day)
8:00am – 4:30pm (7.5hours/day)
3:30pm – 12:00am (7.5hours/day)
This position is eligible for telework which is currently 2 days per week. New Hires are eligible to apply 30 days after their effective date of hire.
SummaryThe purpose of this position is to provide critical technical expertise in the detection, analysis and response to cybersecurity events. Cybersecurity Analyst will be responsible for early and accurate detection, prevention response, containment, and guidance to remediation of threats directed against the MTA on a 24/7 basis. The analysis is conducted through technology risk assessments, data analytics tools, business processes reviews and collaborate with security engineers, architects, developers, vendors, business units to constantly improve the overall security of the MTA.
The cybersecurity analyst will focus on specific domains and specialties within cybersecurity with a great degree of specialty to detect, protect and advise the organization proactively and reactively.
The Cybersecurity Analyst will be a member of the Cyber Security Operation Center “CSOC”. This role will conduct real-time 24/7 security monitoring and intrusion detection analysis using a Security Incident & Event Management system “SIEM” along with various technology and analytic tools, such as web and next generation firewalls, machine and human behavior learning tools, host-based security system, security event and incident monitoring systems, virtual, physical, and cloud platforms, user endpoint (laptop, desktop, mobile, and internet of things/IOT) systems, etc.
The Analyst will research emerging threats and vulnerabilities to aid in the identification and analysis of network incidents, and supports the creation or improvement of security controls, policies, standards, and guidance to address them.
- Ability to perform analysis and remediation actions on threats from various attack vectors such as: malware, viruses, ransomware, phishing, SQL Injection, compromised credentials, DDOS etc.
- Ability to provide incident response support
- Ability to mitigate actions to contain activity
- Ability to facility forensic analysis
- Researching emerging threats and vulnerabilities to aid in the identification of network incidents, and supports the creation of new architecture, policies, standards, and guidance to address them
- Provide incident response support, including mitigating actions to contain activity and facilitating forensics analysis when necessary
- Conducts security monitoring and intrusion detection analysis using various technology and analytic tools, such as web and next generation firewalls, machine and human behavior learning tools, host-based security system, security event and incident monitoring systems, virtual, physical, and cloud platforms, user endpoint (laptop, desktop, mobile, and internet of things/IOT) systems, etc.
- Correlates events and activities across systems to identify trends of unauthorized use
- Reviews alerts and data from sensors and documents formal, technical incident reports
- Tests new systems and manage cybersecurity risks and remediation through analysis
- Responds to computer security incidents according to the computer security incident response policy and procedures
- Provides technical guidance to first responders for handling information security incidents
- Provides timely and relevant updates to appropriate stakeholders and decision makers
- Communicates investigation findings to relevant business units to help improve the information security posture
- Validates and maintains incident response plans and processes to address potential threats
- Compiles and analyzes data for management reporting and metrics
- Monitors relevant information sources to stay up to date on current attacks and trends
- Analyzes potential impact…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).