Chief Information Security Officer
New York City Fire Department · Brooklyn, NY · 3 wk ago
On-siteInformation TechnologyFull-time
About the role
The Fire Department, City of New York (FDNY), seeks a full-time Chief Information Security Officer in the Bureau of Technology Development & Systems. The successful candidate will be responsible for developing and implementing an organization's information security strategy to protect data and systems from cyber threats.
Responsibilities
- Establish Security Strategy: Develop and maintain the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected.
- Identify, assess, and mitigate information security risks to ensure the confidentiality, integrity, and availability of data.
Requirements
Minimum qualifications:
- A baccalaureate degree from an accredited college in computer science, information systems, engineering, mathematics or related field and six years of satisfactory full-time experience related to enterprise architecture, solutions architecture, network architecture and/or IT infrastructure systems; or
- A baccalaureate degree from an accredited college and ten years of satisfactory full-time experience related to enterprise architecture, solutions architecture, network architecture and/or IT infrastructure systems; or
- Education and/or experience which is equivalent to the above.
Skills
- Minimum of 6 years’ experience managing information security programs, developing, and applying information security, risk management, and privacy practices in local, state, or federal government.
- Minimum of 6 years’ practical experience designing and implementing IT security solutions with a deep understanding of various security threats and preventative measures.
- Familiarity with cyber-security frameworks such as NIST, CIS Controls, PCI-DSS, HIPAA etc.
- Strong demonstrated knowledge of LAN/WAN, systems administration, active directory, PowerShell, group policy, virtualization, cloud and IT security technologies.
- Experience with systems access management, change management, security monitoring and intrusion detection, vulnerability management, endpoint security management, cloud security, data loss prevention, encryption, network security, disaster recovery, data management, physical security, vendor management.
- Experience with CrowdStrike, McAfee, Pulse Secure, Cisco, firewalls, Windows Server, Rapid7, MS Office 365, Endpoint Security and Enterprise Mobility in the cloud.
- IT certifications (1 or more) such as Security+, CISSP, CISA, CISM, CySA+, CRISC, C-CISO, SSCP, CASP, CEH, GIAC.