New York's cybersecurity market is large enough to support hundreds of specialized firms, yet concentrated enough that a generic jobs list can hide the differences that matter. NYCEDC describes New York City as a global cyber center with a 60,000-person cybersecurity workforce and more than 300 dedicated cyber companies (NYCEDC). A separate 2026 directory counts 329 cybersecurity companies based in New York, with a median company size of 11–50 employees (RevenueBase's New York cybersecurity directory).
That makes a company roundup more useful than a page of open roles for candidates targeting startup-focused security careers. The core question isn't only who is hiring. It's which environment matches your technical domain, preferred customer exposure, delivery model, and tolerance for ambiguity.
The seven companies below represent distinct environments, including platform product companies, specialized security providers, research-led consulting, and incident-response services. Read each profile by identifying the security problem, mapping it to relevant role families, checking the company's official careers or contact channels for evidence of current hiring, and tailoring your application to its domain. Hiring managers can use the same lens to understand competing employers and sharpen how they position a role.
Underdog.io is also relevant for candidates seeking vetted startup and high-growth opportunities. Its single application and human-powered matching can support a broader search, but it shouldn't replace verification of each company's current openings.
SecurityScorecard is a strong fit for people who want to work where cybersecurity meets third-party risk, security ratings, and executive decision-making. Its platform evaluates external security posture through A–F ratings, issue-level evidence, workflows, and remediation guidance. That creates a product environment centered less on one internal network and more on how organizations assess vendors, suppliers, and downstream exposure.
The platform also supports continuous third-party risk management, portfolio monitoring, supply-chain incident mapping, and executive-friendly reporting. TITAN AI and AI Agents add portfolio analysis and investigation capabilities, while a free starting tier lets an organization view and improve its own score before moving into deeper paid functionality (SecurityScorecard).

Candidates should look for role families in security engineering, threat intelligence, data engineering, product management, customer success, solutions architecture, and risk consulting. The strongest applications will connect a specific capability to the company's operating model. Examples include building reliable external attack-surface measurements, explaining security findings to procurement leaders, designing vendor remediation workflows, or improving the signal quality of automated ratings.
The product's usability is a real advantage. Ratings are easy to share with vendors and boards, and the free plan gives organizations a low-friction way to understand their own posture. The trade-off is that ratings can produce false positives, so customers often need to validate findings with vendors. Portfolio analytics and administrative features also sit behind paid tiers.
Practical rule: A candidate who can explain both the technical evidence and the business consequence will usually be more persuasive here than someone who only lists scanning tools.
Hiring managers should make the role's relationship to product, data, and customer workflows explicit. A security engineer may need to reason about evidence quality, while a customer-facing hire may need to manage disagreement over a rating without weakening trust.
BlueVoyant occupies a broader operating model than a pure software platform. The New York City-headquartered provider combines Managed Detection and Response, third-party risk management, digital risk protection, and professional services. For customers, that creates a single-partner option for 24/7 detection and response alongside supply-chain monitoring, brand protection, and takedown work (BlueVoyant).
Its MDR service covers endpoint, network, and cloud environments, while integrated TPRM and Digital Risk Protection modules address risks outside the traditional security perimeter. The company also operates with a global SOC and office footprint, with New York City serving as its corporate headquarters.

This is a useful target for candidates who want exposure to security operations, detection engineering, incident response, threat intelligence, digital investigations, customer delivery, or security consulting. The strongest fit depends on whether you prefer building product capabilities or delivering security outcomes through repeatable playbooks and service teams.
BlueVoyant's advantage is the breadth of its offer. A customer doesn't necessarily need separate partners for MDR, supply-chain risk, and digital risk. Its takedown and brand-protection experience can also matter to organizations dealing with impersonation, malicious domains, or exposed digital assets.
The trade-off is operational complexity. Pricing isn't publicly listed and depends on the customer's technology stack and service volume. Customers may also need alignment with supported EDR and SIEM tools, so candidates should understand integration work rather than treating MDR as an isolated SOC function.
Questions to ask during an interview:
Hiring managers should describe the actual service boundaries. A vague “full-spectrum” description won't tell candidates whether they'll spend most of their time tuning detections, handling incidents, supporting customers, or building platform integrations.
Claroty is built for a problem that general-purpose IT security products don't fully solve, visibility and control across cyber-physical systems. With a New York address, the company focuses on OT, IoT, and healthcare IoMT through its xDome platform and related modules. Its customers can use asset discovery, risk reduction, threat detection, policy recommendations, and secure remote access for environments where uptime and safety carry unusual weight (Claroty).
The platform uses deep packet inspection and light-active techniques to improve visibility without treating industrial or medical environments like ordinary office networks. Claroty also has a healthcare specialization connected to the Medigate heritage, while Team82 contributes ongoing vulnerability research and public technical analysis.
Candidates should consider Claroty if they want role families connected to OT security, network analysis, vulnerability research, healthcare security, embedded systems, detection engineering, product security, or solutions engineering. Experience with industrial protocols, medical devices, network telemetry, or safety-sensitive environments can be more relevant than broad familiarity with enterprise IT tools.
The company isn't a replacement for a general IT security stack. Its value comes from purpose-built visibility into environments where teams may not be able to install conventional agents or freely scan systems. That specialization creates a practical trade-off. Deployments can require coordination with network owners, biomedical engineering teams, plant operators, and other stakeholders who prioritize availability over rapid security changes.
A strong candidate question: “How does this team validate security controls without disrupting clinical, manufacturing, or operational workflows?”
Hiring managers should explain the customer environment candidates will support. A role involving hospitals will demand a different vocabulary and risk model from one serving manufacturing or critical infrastructure. Clarify whether the hire will work on packet inspection, asset modeling, research, customer deployment, or cross-functional product decisions.
Team82's research output can also serve as an application signal. Candidates shouldn't merely mention the group. They should read a relevant vulnerability analysis, explain the technical issue in their own words, and connect it to detection, remediation, or product design.
BigID makes sense for candidates who want cybersecurity work centered on data discovery, privacy, access governance, and AI risk. The New York-based enterprise platform combines Data Security Posture Management with DLP, access governance, privacy capabilities, and emerging AI Security Posture Management. It addresses organizations whose exposure comes from sensitive data sprawl, regulatory obligations, cloud complexity, and the way teams use data in AI systems (BigID).
The platform integrates with cloud environments, data lakes, enterprise security systems, and on-premises data sources. That breadth creates opportunities for engineers and product teams working across connectors, classification, policy enforcement, identity, privacy workflows, and security program transparency.

BigID's broad data-security scope is both its appeal and its challenge. The full product value often depends on cooperation among security, data, privacy, legal, compliance, and infrastructure teams. Candidates who enjoy translating between those groups may find a better fit than people seeking narrowly isolated security engineering work.
Relevant role families may include data security engineering, cloud security, privacy engineering, identity and access management, data governance, product management, solutions architecture, and customer implementation. Application materials should show a concrete understanding of data movement and control. Discuss how you'd identify sensitive data, handle overprivileged access, prioritize remediation, or make an AI data-use policy enforceable.
Candidates exploring confidential startup opportunities can also use Underdog.io's guide to confidential job searches for engineers, particularly when they want to explore options without making a broad public job-board search.
Hiring managers should state which part of the data estate the role will touch and how success will be evaluated. “AI security” can mean model governance, data lineage, access controls, prompt-related risk, or product development. Candidates need enough technical context to determine whether the work matches their experience.
Pricing and architecture sizing will depend on data-estate complexity, so customer-facing candidates should be prepared to discuss deployment scope rather than promise a simple universal rollout.
Trail of Bits is the clearest choice on this list for candidates who want research-grade software assurance rather than managed security operations. Founded in New York, the boutique security research and consulting firm works across application security, cloud security, supply-chain security, cryptography, formal methods, AI and machine-learning security, and smart-contract or blockchain audits (Trail of Bits).
Its public research corpus and open-source tools, including Slither and Echidna, give applicants something concrete to study before applying. The firm is particularly relevant to engineers who enjoy code-level reasoning, protocol analysis, adversarial testing, and writing findings that developers can act on.

Relevant role families include security research, application security consulting, cryptography, formal verification, smart-contract auditing, AI security, software engineering, and technical writing. A résumé that says “performed penetration testing” won't communicate much. A better application identifies a public tool, audit, or research topic and explains a technical insight, limitation, or possible extension.
Candidates can also review Underdog.io's guide to hiring software engineers for a useful perspective on presenting engineering depth during a selective process. The important point is not polished generality. It's evidence that you can reason carefully about code, architecture, protocols, and failure modes.
Trail of Bits offers strong fit for high-assurance systems, including cryptographic, zero-knowledge, AI, and blockchain work. The trade-off is that it isn't an MDR provider or a continuous managed-services operation. Engagements can involve premium consulting rates and longer lead times than mass-market consultancies, which means candidates should be comfortable with deep project work and hiring managers should explain delivery expectations clearly.
Application test: Pick one public research output and write a short technical note that identifies the problem, the exploitation or failure mode, and the engineering decision it should change.
Hiring managers should avoid screening primarily for tool familiarity. Ask candidates to analyze unfamiliar code or explain a security boundary. That approach better reflects the firm's research-led environment.
Kroll fits candidates who want incident response, digital forensics, threat hunting, cyber-risk assessments, and post-incident resilience rather than a single product engineering track. The New York-headquartered provider offers incident response retainers with defined response times and service credits, forensic investigation, notification support, threat hunting, and guidance on combining MDR with retainer strategies (Kroll Cyber).
The work is services-led, so customers rely on Kroll's specialists during investigations and recovery rather than operating a Kroll platform continuously. Candidates can build experience in evidence handling, executive communication, and recovery planning. Hiring managers should look for people who remain precise under pressure and can explain technical findings to clients.
Kroll describes retainer tiers and documented service-level commitments, including two-to-six-hour contact windows. Treat that detail as part of the service design, not as a promise about every role or investigation.
Likely role families include DFIR, malware analysis, threat hunting, incident coordination, cyber-risk consulting, e-discovery, client advisory, and resilience planning. Applications should show practical judgment around chain of custody, investigative scope, containment decisions, and communicating uncertainty during a live event.
The trade-off is intensity and variability. Urgent customer needs can change schedules quickly, and retainer or investigation costs may be material for smaller customers. Candidates seeking predictable internal security operations or a product-development rhythm should test that fit early.
Hiring managers should explain on-call expectations, travel or customer-site requirements, escalation ownership, and the boundary between investigation and remediation. Candidates should ask how teams preserve analytical quality when response speed matters.
For a broader assessment of a company's operational readiness, review this startup due diligence checklist. Candidates comparing Kroll with MDR providers should focus on delivery model and learning goals. Kroll is called when an organization needs experienced investigators and response leadership, which creates different work from continuously operating a detection platform.
Axonius focuses on a foundational security problem, knowing what exists across a fragmented technology estate and acting on the gaps. The New York City-headquartered company provides cyber asset intelligence, Cyber Asset Attack Surface Management, SaaS and application management, and exposure management through a connector-based platform (Axonius).
The platform normalizes telemetry from many tools to create an inventory of assets, identify coverage gaps, and trigger automated enforcement or remediation workflows. Its scope extends beyond core CAASM into SaaS and cloud asset visibility, which makes it relevant to organizations where ownership, configuration, and security coverage are spread across teams.
The likely role families include backend engineering, data engineering, integrations, cloud security, product management, solutions engineering, customer success, and security research. Candidates should understand that connector quality and accurate data mapping are central to the product. A strong application can show experience integrating APIs, reconciling conflicting asset records, designing normalization logic, or turning inventory data into an enforceable workflow.
The platform can deliver strong time-to-value in heterogeneous environments because it connects information already distributed across security and IT tools. Its trade-off is commercial and technical. Per-asset pricing can grow with large fleets, and inaccurate or incomplete source data can weaken the quality of the resulting inventory.
Hiring-manager prompt: Show candidates one example of a coverage gap and explain which system supplied the evidence, which team owned remediation, and how the workflow closed the loop.
That level of detail helps candidates distinguish an integration-heavy role from a pure product-security position. It also helps hiring managers attract people who understand the operational problem instead of only repeating CAASM terminology.
Candidates should review the official careers page and product material before applying, then tailor their outreach around one asset-visibility challenge. Hiring managers should state whether the role emphasizes connector development, data quality, workflow automation, or customer deployment.
| Solution | Implementation complexity | Resource requirements | Expected outcomes | Ideal use cases | Key advantages |
|---|---|---|---|---|---|
| SecurityScorecard | Low–Medium (SaaS; quick start; advanced analytics need setup) | Low to moderate (minimal integration; paid tiers for portfolio features) | Continuous A–F cybersecurity ratings, vendor monitoring, remediation guidance | Vendor risk management, executive reporting, self‑score cleanup | Widely adopted, shareable ratings; free self‑score tier |
| BlueVoyant | Medium–High (SOC integration; 24/7 operations) | High (EDR/SIEM alignment; ongoing operational costs) | 24/7 MDR, integrated TPRM and digital risk protection, response capability | Organizations wanting single vendor for MDR plus supply‑chain/brand protection | End‑to‑end MDR + DRP; mature playbooks and takedown experience |
| Claroty | High (OT network access; specialized deployments) | Moderate–High (coordination with OT/biomed teams; specialized sensors) | Deep OT/IoT/IoMT asset visibility, threat detection, secure remote access | Critical infrastructure, manufacturing, and healthcare OT environments | Purpose‑built OT tooling; strong vulnerability research (Team82) |
| BigID | Medium–High (many connectors; cross‑team alignment required) | High (access to data sources; sizing depends on data estate) | Sensitive data discovery, DSPM/DLP controls, privacy and AI governance support | Organizations with sensitive data sprawl, regulatory or AI/model data risks | Broad integrations across cloud/data sources; leader in DSPM/privacy |
| Trail of Bits | High (deep technical audits; custom engagements) | High (expert consultants; longer lead times; premium rates) | Research‑grade code and cryptography audits, AI/ML and blockchain assurance, tooling | High‑assurance systems (crypto, ZK, AI models, security‑critical code) | Top‑tier technical talent; open‑source tools and transparent research outputs |
| Kroll (Cyber Risk) | Low–Medium to engage (retainer setup); High during investigations | Variable (retainer fees; investigation costs scale with scope) | Rapid incident response, DFIR, threat hunting, documented SLAs | Organizations needing an on‑call IR partner and large investigation experience | Proven IR experience; clear retainer tiers and SLAs |
| Axonius | Low–Medium (connector setup; SaaS deployment) | Moderate (connector configuration; per‑asset pricing can scale) | Unified asset inventory, exposure/gap detection, automated remediation workflows | Heterogeneous estates seeking visibility and enforcement across assets | Extensive connector ecosystem; rapid time‑to‑value for visibility |
There isn't a universal winner among these companies. The right target depends on the kind of security work you want to perform and the kind of customer problem you want to own.
Start by ranking the shortlist across four dimensions:
Then build the application around one capability from the relevant profile. For SecurityScorecard, that might be external-risk measurement or vendor remediation. For Claroty, it could be industrial network analysis. For Trail of Bits, use a research output or code-level security example. For Kroll, describe an investigation or response decision. For Axonius, demonstrate integration and asset-data reasoning.
Check every company's official website for current openings and use official contact channels when a role isn't obvious. The company profiles and market signals are research prompts, not proof of an active vacancy. New York's market is broad and competitive, and NYCEDC describes the city's cybersecurity growth since 2017 as faster than the nation's, alongside its deep workforce and company base (NYCEDC). That combination can create opportunity, but it also means experienced candidates need sharper positioning.
Hiring managers should apply the same discipline in reverse. Clarify the security mission, name the technical environment, explain how the role works with adjacent teams, and make startup-stage expectations explicit. A candidate deciding between product security, incident response, and consulting needs to know how often priorities change, who owns decisions, how customer-facing the job is, and what “senior” means in practice.
The broader market context reinforces why this level of precision matters. New York has concentrated demand from finance, healthcare, technology, and other regulated sectors, while state risk data shows sustained cyber exposure. The New York State Comptroller reported that cyberattack complaints rose 53% from 2016 to 2022, with estimated 2022 losses exceeding $775 million, and identified Healthcare and Public Health plus Financial Services among the most attacked critical-infrastructure sectors (New York State Comptroller report). Those conditions support demand, but they don't guarantee that every role offers the same technical depth, compensation, autonomy, or growth path.
Candidates seeking curated access to startup and high-growth technology employers can also consider Underdog.io. Its human-powered matching and single application can broaden a targeted search, while company-specific verification and role fit should remain central.
Underdog.io offers candidates a single application for access to curated startup and high-growth technology opportunities, including roles in New York and remote markets. If you're comparing cybersecurity companies in New York and want a more focused route to relevant employers, visit Underdog.io and explore the matching process.
