Jobs and Careers
CI

Cybersecurity Senior Data Analyst, Bureau of Audit Services

City of New York
Long Island City, United Statesfull_timeVerifiedPosted 6 Nov 2025

About the role

Job Description

OPEN TO PERMANENT IN THE TITLE OF CYBER SECURITY**

The nation's leading public health agency, The New York City Department of Health and Mental Hygiene (DOHMH) is seeking a Cybersecurity Senior Data Analyst. This position will report to the to the Cyber Security IT Audit Manager in the Bureau of Audit Services, Office of the Chief Operating Officer. Audit Services plays a leading role in risk based assessments of the Department's operational efficiencies, control effectiveness and compliance with federal laws, such as the Health Insurance Portability and Accountability Act (HIPAA), Citywide policies, and New York City Comptroller's directives.

DUTIES WILL INCLUDE BUT NOT BE LIMITED TO:
Under the Supervision of the Bureau of Audit Services Management, the Cybersecurity Senior Data Analyst's responsibilities include but are not limited to:

- Plan and execute advisory, assessment and audit projects using information technology (IT) Governance, Risk and Compliance (GRC) best practices, methodologies and tools.
- Conduct research and analysis of the agency' systems, IT hardware and network infrastructure, programs, IT contracts and procurement, IT professional services, and compliance with the City's and Agency's policies and procedures and in comparison to federal and industry recommended standards, frameworks and controls.
- Assist in the development of cybersecurity audit plans, test plans, system analyses and IT system controls.
- Document and present IT advisory, assessment and audit reports including test results to all levels of management.
- Perform cybersecurity IT audits, security risk assessments, IT system integrity testing, IT controls reviews and integrated audits with fiscal auditors.
- Research, analyze and evaluate risks and controls relevant to cybersecurity and provide risk assessment and risk mitigation recommendations.
- Document project lessons learned and help identify risk management and performance improvement opportunities.
- Support Audit Management in conducting internal reviews of the Department's general IT system controls (e.g., access control, audit and accountability, configuration management, contingency planning, incident response and disaster recovery, physical and environmental protection, data center operations, supply chain risk management, etc.), and recommend controls to mitigate risks.
- Support the assessment of Department's compliance with federal requirements such as HIPAA Security and Privacy rules.
- Maintain ongoing and open communication with the Department's programs “ including the Division of Information Technology Office of Cybersecurity on general and application control issues and implementation of corrective actions.
- Prepare and maintain complete work paper documentation, memos, and letters.
- Act as the agency's representative during external audits/ reviews, and as a liaison between the Comptroller's Office, third party auditors/reviews and the division/bureau being audited.
- Seek self-improvement through education, certification, training, and staying abreast of current and emerging technologies; and; research and stay up-to-date on IT risk management and relevant audit concepts and methods.

Preferred Skills:
- A baccalaureate (BA/BS) degree from an accredited college or university in information technology, computer science, systems engineering, cybersecurity, accounting, business or a related area, including or supplemented by (i) 24 semester credits in computer science, or 24 semester credits in accounting and auditing or a closely related field and one (1) or more years of experience in information technology in information systems and cybersecurity audit, or cybersecurity risk, governance or compliance management, cybersecurity incident management, or cybersecurity operations.
- Highly motivated, self-directed and organized professional with the ability to plan and execute a project.
- Business analysis with a curious mindset and interest to learn new information. Excellent oral and written “ including word-based and graphic, communication skills.
- Ability to work independently when given specific instructions.
- Excellent interpersonal and relationship building skills.
- Ability to adapt to change quickly and follow directions, and capable of handling multiple projects at the same time and meet deadlines.
- Understanding of the CIA Triad and cyber security frameworks such as ISO 2700X, COBIT 5, and NIST CSF and 800-53.
- Related industry certifications or actively pursuing certifications such as Security+, CISSP, CISA, and/or CISM.
- Advanced knowledge of Microsoft Office Suite: Word, Excel, PowerPoint, Access, and Visio.
- ACL (Audit Command Language) or SQL (Structured Query Language) experience is a plus.
- Basic understanding of commonly used operation sy

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

City of New York

View company profile →