Security Researcher Jobs in New York
Security Researcher jobs in New York are among the most active in the country, concentrated in financial services, defense contracting, and enterprise technology, with openings at every level from junior analyst through principal researcher. Most hiring is centered in New York City, with additional activity in Albany and Buffalo, where institutions like JPMorgan Chase, IBM, and Booz Allen Hamilton maintain significant security operations. Penetration testing, vulnerability research, and threat intelligence are the specialties drawing the most consistent demand. Find a role that fits below and apply directly.
Find Security Researcher JobsOverview
Showing 5 of 8+ Security Researcher jobs











Position Highlights
- Serve as RIT’s lead resource for research security and sponsored research compliance, supporting federally funded and industry-sponsored research projects.
- Coordinate compliance efforts related to CMMC 2.0, FCI, CUI, HIPAA, NSPM-33, GDPR, and other research security and data protection requirements.
- Partner with principal investigators, sponsors, and campus stakeholders to assess compliance needs, develop project-specific security documentation, support audits and assessments, and ensure sponsored research activities meet regulatory and sponsor expectations.
- Help translate complex sponsor and regulatory requirements into practical processes, policies, training, and institutional controls that enable research success while maintaining compliance.
- Promote a culture of ethics, accountability, and compliance across the university's research enterprise.
This position is fully on campus and is not eligible for remote work. To receive full consideration, applicants must submit both a resume and cover letter with their application.
Sponsored Research Services, Office of the Vice President for Research
Sponsored Research Services (SRS) supports RIT’s research community by providing guidance and oversight throughout the sponsored research lifecycle. Working closely with faculty, research staff, and campus partners, SRS helps ensure that research activities meet sponsor requirements and applicable regulations while advancing the university’s research mission.
The Research Security and Compliance Specialist plays a key role in strengthening RIT’s research security and compliance framework. This position collaborates with stakeholders across the university, including the Information Security Office, Research Computing, Information & Technology Services, Institute Audit, and academic units, to support secure research practices, data protection, and regulatory compliance. Through partnership, education, and process development, the team helps researchers navigate evolving security requirements and successfully manage sponsored research projects.
Essential Duties & Responsibilities
- Oversees compliance component of RIT's CMMC program for sponsored research cybersecurity. Assists cross-functional team with policy creation, implementation, operations, program roadmap, requirements, tracking of compliance gaps, and preparation for self-assessment and third-party assessment. Provides final compliance sign-off on processes needed to comply with federal and sponsor standards and other information research security standards
- Ensures projects requiring protected research data are reviewed and supported before work begins. Assists with identifying cybersecurity and controlled-data obligations during proposal development, contract review, award set up, data use agreement review and project initiation.
- Provides gap analysis and creates individualized information research security control plans for projects as necessary. Provides compliance certifications to sponsors. Documents processes and records demonstrating RIT reviews, attestations, and required training occurred on every sponsored project
- Provides guidance, training, and consultation to research community, including developing and delivering training
- Advises research community on information research security regulations, changes, and compliance processes
- Other duties as assigned
Knowledge, Skills, & Abilities
- Knowledge of local, state, and federal laws and regulations that govern information research compliance standards
- Knowledge of federal cybersecurity and controlled-research-data requirements impacting sponsored research
- Understanding of network security, firewalls, encryption, cloud computing standards, and workstation security
- Skill in risk assessment and mitigation in the management of research compliance strategies
- Skill in effective communication and collaboration with internal and external stakeholders regarding complex or technical topics
- Skill in technical, legal, and compliance writing
- Ability to establish and maintain relationships with state and federal regulatory agencies
Minimum Education & Experience
- Master's degree in related field
- 5 years of relevant experience
- An equivalent combination of education and experience may be considered
Job Level Overview
Specialized Contributor Level 3 - A senior-level role requiring broad understanding of the profession or field of work. Independently leads diverse and often complex assignments, projects, or programs. May act as a mentor and guide less experienced staff.
FLSA Category
ExemptWork Location
On CampusCompensation
$72,500.00 - $116,000.00 AnnualApplication Materials
When you are ready to complete an application for this position please be prepared to submit the below requested information. This will be required to ensure your application is processed in a timely manner.
Cover Letter, Curriculum Vitae or ResumeCandidates must be eligible to work in the United States.
Additional Details
In compliance with NYS's Pay Transparency Act, the salary range for this position is listed above. Rochester Institute of Technology considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, education/training, key skills, internal peer equity, as well as, market and organizational considerations when extending an offer. The hiring process for this position may require a criminal background check and/or motor vehicle records check. Any verbal or written offer made is contingent on satisfactory results, as determined by Human Resources. RIT provides equal opportunity to all qualified individuals and does not discriminate on the basis of race, color, creed, age, marital status, sex, gender, religion, sexual orientation, gender identity, gender expression, national origin, veteran status or disability in its hiring, admissions, educational programs and activities. RIT provides reasonable accommodations to applicants with disabilities under the Rehabilitation Act, the Americans with Disabilities Act, the New York Human Rights Law, or similar applicable law.
If you need reasonable accommodation for any part of the application and hiring process, please contact the Human Resources office at 585-475-2424 or email your request to careers@rit.edu . Determinations on requests for reasonable accommodation will be made on a case-by-case basis.
See All 8 Security Researcher Jobs in New York
Find roles in New York that match your experience and apply in just a few clicks.
Find Security Researcher JobsSecurity Researcher Jobs by City in New York
Where New York roles are concentrated, by current openings.
Security Researcher Job Market in New York
A snapshot from current New York openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Insurance
- Technology & Software
What New York Employers Look For
The qualifications that appear most often in security researcher jobs across New York.
- Bachelor's degree in computer science, cybersecurity, or a closely related technical field
- Hands-on experience with penetration testing tools such as Metasploit, Burp Suite, or Cobalt Strike
- Proficiency in at least one scripting or programming language, commonly Python, C, or Assembly
- Relevant certifications such as OSCP, CEH, or GPEN recognized by New York employers
- Experience identifying and documenting vulnerabilities in web applications, networks, or embedded systems
- Ability to obtain and maintain security clearance for defense or financial sector roles
Security Researcher Jobs in New York: Frequently Asked Questions
How do you become a security researcher in New York?
New York does not require a state-issued license to work as a security researcher. The standard path is a bachelor's degree in computer science or cybersecurity, followed by certifications like OSCP or GPEN that New York employers consistently recognize. Many researchers build their foundation through capture-the-flag competitions, bug bounty programs, or graduate programs at institutions like NYU Tandon or Columbia, then move into junior vulnerability research or security analyst roles.
How much do security researchers make in New York?
Security researchers in New York earn a median of about $134,660 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $83,110 for the lowest 10% to over $216,220 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire security researchers in New York?
Employers hiring security researchers in New York right now include CVS Health, JPMorganChase, and Cobalt, based on current listings on Migrate Mate as of August 2026. New York's concentration of major financial institutions and defense contractors means many of these roles sit within large internal security teams rather than smaller boutique firms.
Which New York cities have the most security researcher jobs?
The cities with the most security researcher openings in New York are New York, Albany, and Rochester. New York City dominates the distribution, driven by its dense cluster of financial institutions, media companies, and enterprise technology headquarters that maintain large internal security research functions, while Albany's government and defense presence anchors hiring further upstate.
Are there remote security researcher jobs in New York?
Yes, and more than most technical fields. About 33% of security researcher openings tied to New York are remote or hybrid as of August 2026, reflecting the largely code- and analysis-driven nature of the work. Roles focused on vulnerability research, malware analysis, and threat intelligence are the most likely to be fully remote, while positions requiring lab access or classified environments tend to remain on-site.
How can I get hired as a security researcher in New York with little or no experience?
The most realistic entry path is moving from a security operations center analyst or IT support role into research, which large New York employers like IBM and JPMorgan Chase often facilitate through internal rotations. NYU Tandon and Columbia both run security research labs where students build publishable work that substitutes for professional experience. A documented CVE disclosure or a strong portfolio of bug bounty findings carries significant weight with New York hiring managers evaluating candidates without a full-time research history.
Where can I find and apply to security researcher jobs in New York?
You can find and apply to security researcher jobs in New York on Migrate Mate, which lists current New York openings across industries. Search the listings, find roles that fit your experience and location, and apply directly to the employer from the listing page.
See All 8 Security Researcher Jobs in New York
Find roles in New York that match your experience and apply in just a few clicks.
Find Security Researcher Jobs