Deputy Superintendent for Cybersecurity Intelligence (Director Financial Services Programs 3, NS)
About the role
The New York State Department of Financial Services seeks to build an equitable, transparent, and resilient financial system that benefits individuals and supports business. Through engagement, data-driven regulation and policy, and operational excellence, the Department and its employees are responsible for empowering consumers and protecting them from financial harm; ensuring the health of the entities we regulate; driving economic growth in New York through responsible innovation; and preserving the stability of the global financial system.
Under the direction of the agency’s Executive Deputy Superintendent for Cybersecurity, the Deputy Superintendent for Cybersecurity Intelligence will provide expertise and leadership in support of the Department’s mission to protect consumers and industry by leading the Division’s collection and analysis of cybersecurity threat, incident, supervisory, and risk intelligence.
Responsibilities
- Leads a team of Cybersecurity Intelligence Unit personnel.
- Conducts and oversees analysis of cyber threats and trends, and develops actionable recommendations for DFS-regulated entities to mitigate such threats and trends.
- Supports the development of alerts, advisories, and guidance for DFS-regulated entities.
- Develops and implements policies and procedures for the Intelligence Unit and the Cybersecurity Division.
- Engages with DFS-regulated entities, other governmental agencies, and private sector cybersecurity firms.
- Analyzes supervisory, examination, incident, and threat intelligence information to identify emerging risks, systematic vulnerabilities, concentration risks, and trends affecting DFS-regulated entities and the financial services sector.
- Reviews, analyzes, and makes recommendations informed by threat intelligence tools and sources.
- Develops intelligence reports and risk assessments to support supervisory priorities, examination planning, risk monitoring, resource allocation, and policy development.
- Monitors intelligence and supervisory data collected from regulated entities, intelligence tools, and open-source materials to assist with the development and implementation of the Department’s comprehensive strategy regarding risk monitoring.
- Identifies and assesses cyber independencies, concentration risks, and common points of failure across technologies, services providers, critical infrastructure and regulated entities.
- Coordinates intelligence sharing with federal and state regulatory partners, law enforcement, information sharing and analysis centers (ISAC’s) and industry stakeholders.
- Other duties as assigned.
Requirements
14 years of specialized experience leading or advising teams working on information technology (IT), cybersecurity, cyber threat analysis, and/or incident response, including 5 years in a managerial or supervisory capacity. Supervision must have included supervising staff performing professional work in the areas described above.
Substitutions: an associate’s degree may substitute for two years of specialized experience; a bachelor’s degree may substitute for four years of specialized experience; a master’s degree may substitute for five years of specialized experience; a J.D. may substitute for six years of specialized experience; and a Ph.D. may substitute for seven years of specialized experience.
Preferred Qualifications
Advanced degree(s) in information technology (IT), cybersecurity, public policy, risk management, and/or law.
Pay
Salary: $172,787 - $213,995 (salary commensurate with experience). Positions located within the New York City metropolitan area, as well as Suffolk, Nassau, Rockland, and Westchester Counties, are also eligible to receive an additional $4,000 annual downstate adjustment.
Appointment to this position is pending Governor Appointment’s Office and Division of Budget approval. This is an appointment to a position in the exempt jurisdictional class, serving at the pleasure of the appointing authority.