Full-Time

Cybersecurity Analyst Critical Assets & Incident Response CERT Levels 3

5

Posted on 12/18/2025

Metropolitan Transportation Authority

Metropolitan Transportation Authority

1,001-5,000 employees

Operates regional public transit network

Compensation Overview

$95.9k - $153.7k/yr

New York, NY, USA

Hybrid

Hybrid role; two days per week on-site/office required.

Category
IT & Security (1)
Required Skills
TCP/IP
PowerShell
Python
Operating Systems
Perl
Requirements
  • Bachelor’s Degree and minimum 1 year of relevant experience. An equivalent combination of education and experience may be considered in lieu of a degree.
  • Bachelor’s degree in Computer Science or related fields preferred.
  • CISSP or other advanced security-related certification preferred but not required.
  • Certifications in technology subdomains preferred but not required (i.e., Cloud, Applications, Infrastructure, Security Technology, etc.)
  • Requires prior experience with installing, maintaining, and troubleshooting technology systems.
  • Proven ability to troubleshoot and support technical issues using standardized procedures.
  • Proven ability to analyze a security risk assessment or conduct one with guidance
  • Understanding of Operating Systems and Hardware
  • Understanding of TCP/IP (OSI Layers 1– 4) and Internet and Intranet technologies required (OSI Layers 5-7).
  • Scripting or programming skills (PERL, Python, PowerShell, etc.) preferred as needed.
  • 1 year of experience in a specific (Cloud, Applications, Infrastructure, Security Technology, etc.) cybersecurity subdomain is preferred
Responsibilities
  • Researching emerging threats and vulnerabilities to aid in the identification of network incidents, and supports the creation of new architecture, policies, standards, and guidance to address them
  • Provide incident response support, including mitigating actions to contain activity and facilitating forensics analysis when necessary
  • Conducts security monitoring and intrusion detection analysis using various technology and analytic tools, such as web and next generation firewalls, machine and human behavior learning tools, host-based security system, security event and incident monitoring systems, virtual, physical, and cloud platforms, user endpoint (laptop, desktop, mobile, and internet of things/IOT) systems, etc.
  • Correlates events and activities across systems to identify trends of unauthorized use
  • Reviews alerts and data from sensors and documents formal, technical incident reports
  • Test new systems and manage cybersecurity risks and remediation through analysis
  • Responds to computer security incidents according to the computer security incident response policy and procedures
  • Provides technical guidance to first responders for handling information security incidents
  • Provides timely and relevant updates to appropriate stakeholders and decision makers
  • Communicates investigation findings to relevant business units to help improve the information security posture
  • Validates and maintains incident response plans and processes to address potential threats
  • Compiles and analyzes data for management reporting and metrics
  • Monitors relevant information sources to stay up to date on current attacks and trends
  • Analyzes the potential impact of new threats and communicates risks back to detection engineering functions
  • Performs root-cause analysis to document findings and participate in root-cause elimination activities as required
  • Works with data sets to identify patterns
  • Understands data automation and analysis techniques
  • Uses judgment to form conclusions that may challenge conventional wisdom
  • Hypothesizes new threats and indicators of compromise
  • Monitors threat intelligence feeds to identify a range of threats, including indicators of compromise and advanced persistent threats (APTs)
  • Identifies the tactics, techniques, and procedures (TTPs) of potential threats through the MITRE ATT&CK or similar frameworks
  • Participate in the creation of enterprise security documents (policies, standards, baselines, guidelines, and procedures) under the direction of the IT Security Manager, where appropriate.
  • Perform Contract management and supply management functions appropriate to reduce security risks
Desired Qualifications
  • Experience with configuring and troubleshooting PLC, RTU, or HMI in industrial environments.
  • Understanding and experience with various types of OT networking protocols, Modbus, Profibus, OPC, etc.
  • Develop/review specification for PTC systems.
  • Implement secure configurations and monitor Supervisory Control and Data Acquisition (SCADA) systems used in rail control.
  • Use purpose-built firewalls for protecting railway signaling and communication systems.
Metropolitan Transportation Authority

Metropolitan Transportation Authority

View

MTA runs North America’s largest public transit network, serving about 15.3 million people across New York City, Long Island, southeastern New York State, and Connecticut through six agencies: NYC Transit, MTA Bus, LIRR, Metro-North, Bridges and Tunnels, and Construction & Development. It moves roughly 2.6 billion trips each year using subways, buses, commuter rails, bridges and tunnels, and related facilities. It differentiates itself by operating multiple transit modes under one umbrella, providing integrated services across districts and modes with extensive infrastructure. Its goal is to provide safe, clean, efficient public transportation that serves as the region’s lifeline and mobility backbone while supporting staff with solid benefits.

Company Size

1,001-5,000

Company Stage

N/A

Total Funding

N/A

Headquarters

New York City, New York

Founded

1834

Simplify Jobs

Simplify's Take

What believers are saying

  • $68 billion 2025-2029 Capital Plan funds 2,390 new subway cars.
  • Congestion pricing revenues accelerate signal upgrades and accessibility.
  • Board approves 435 R211 cars and 44 LIRR locomotives in 2025.

What critics are saying

  • $51 billion plan underfunds subway signals, causing delays in 6-12 months.
  • Federal freeze withholds $3.5 billion over emissions in 12-18 months.
  • TWU lawsuit triggers strike, halting operations in 6-12 months.

What makes Metropolitan Transportation Authority unique

  • MTA serves 11 million daily passengers across 12 counties.
  • MTA manages seven toll bridges and two tunnels daily.
  • Janno Lieber leads modernization since January 2022 appointment.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options

Flexible Work Hours

Company News

Forbes
May 16th, 2025
Nj Transit Strike: What To Know As Work Stoppage Affects Thousands Of Commuters—And Could Impact Beyoncé Concertgoers

Topline. Rail engineers working for New Jersey Transit went on strike early Friday, suspending service for one of the busiest train systems in the country and impacting approximately a hundred thousand riders each day, marking the first major strike to affect the train system in four decades. People board a New Jersey Transit train in Manhattan on May 15 in New York City.Getty Images Key Facts

Government Technology
Oct 14th, 2020
Traffic AI Startup Brings Anthony Foxx, Stuart McKee Aboard

Hayden AI, founded last year, has pulled in two big names along with $5 million in investment money. The company plans to put cameras on vehicles like city buses and run the video through AI.

INACTIVE