Overview

Security Analyst Jobs in New York City Metropolitan Area at DRUM Associates

Title: Security Analyst

Company: DRUM Associates

Location: New York City Metropolitan Area

Our client is one of the world's largest publisher and distributor of children's books and a leader in educational technology, dedicated to helping schools, districts, and families expand access to literacy and learning. The Security Analyst monitors, investigates, and helps defend the organization's systems, networks, and data against security threats. This role will support the team's Security Architect by picking up overflow work, including day-to-day alert triage, incident response, vulnerability management, and compliance activities. The Security Analyst collaborates with IT and engineering teams to identify risks, remediate issues, and strengthen the organization's overall security posture. The position requires strong analytical skills, attention to detail, and effective communication to escalate threats appropriately and keep stakeholders informed.

Responsibilities

  • Security Monitoring: Monitor security tools (Wiz, Snyk, SonarQube) to detect, triage, and investigate alerts and suspicious activity.
  • Incident Response: Support the investigation and containment of security incidents including assessing zero-day and incident impact and cross-referencing affected applications, documenting findings and escalating as needed.
  • Vulnerability Management: Assist in scanning, identifying, and tracking vulnerabilities, and coordinate remediation with relevant teams.
  • Threat Analysis: Research emerging threats, indicators of compromise, and attack techniques to improve detection and defense.
  • Access & Identity Support: Assist with user access reviews, provisioning requests, and enforcement of least-privilege principles.
  • Compliance & Controls: Support the SOC 2 audit and adherence to security policies and regulatory requirements.
  • Documentation: Maintain accurate records of incidents, investigations, runbooks, and security procedures, including SOC-type activity paperwork.

Required Experience:

  • 0–4 years of experience in a security, IT, development, or systems administration role.
  • Tech background or a tech-related degree is acceptable for this entry-level role.
  • Ability to recognize and describe common attack vectors like phishing, malware, privilege escalation, and data exfiltration, and the defensive controls that mitigate each.
  • Familiarity with common security tools (like Wiz, Snyk, and SonarQube).
  • Understanding of networking fundamentals and operating systems (Windows, Linux).
  • Understanding of programming fundamentals. Familiarity with Java or Python preferred.
  • Ability to triage alerts, analyze logs, and identify anomalous or malicious behavior.
  • Strong written and verbal communication skills, critical for reporting and escalation.
  • Attention to detail and strong analytical and problem-solving skills.
  • Ability to work collaboratively and adapt to changing priorities.
  • Leverages AI tools to support alert triage, log analysis, and other core security tasks.
  • Hands-on experience in security monitoring or incident response.
  • Experience with vulnerability management in a production environment.
  • Scripting or automation experience (Python, Bash).
  • Nice-to-have: Experience with Wiz, Snyk, or SonarQube.
  • A plus: sysadmin experience, some programming background, or AWS exposure.
Upload your CV/resume or any other relevant file. Max. file size: 800 MB.