Jobs · Engineering · New York

Information Security Manager - 20001NYC

HybridEngineeringFull-time

About the role

ITS provides operational support to state agencies on a 24x7x365 basis; some positions may be required to provide this critical service at any time. Under the direction of a Deputy Chief Information Security Officer within the Chief Information Security Office (CISO), the incumbent will serve as the Director of the Cyber Risk Management (CRM) bureau, providing oversight of the Vulnerability Management, Threat Response, and Cyber Process Improvement & Metrics sections. The CRM Bureau is responsible for the oversight and operations of a variety of security tools and response functions to help ensure optimal cybersecurity protections, identification and remediation of vulnerabilities, and cyber risk reduction for ITS and its client agencies. The CRM bureau is also responsible for driving process improvement and developing metrics for the CISO division, as well as managing development and oversight of the Government Risk and Compliance (GRC) platform.

Responsibilities

  • Lead and direct all activities within the Cyber Risk Management bureau across multiple managers.
  • Develop strategic plans to revise and improve the bureau’s work, draft staffing plans, and maintain and develop charters, product catalogues, RACI charts, and other documentation.
  • Oversee the development and maturation of the threat and vulnerability response process, helping CISO to reduce cyber risk by efficiently prioritizing and responding to significant vulnerabilities and emerging cyber threats.
  • Oversee the team responsible for the GRC Platform and the CISO SharePoint site, including development, configurations, maintenance through formalized tracking and release management.
  • Oversee the development and maturation of the CISO Metrics Program, including collecting and displaying various data points for stakeholders through reports and dashboards.
  • Oversee the creation of a vulnerability disclosure program to receive and triage vulnerabilities identified by security researchers.
  • Provide guidance on cyber risk management best practices and strategies for risk identification and remediation to support the development and improvement of the agency’s GRC platform.
  • Provide leadership, guidance, and subject matter expertise across all teams within CRM.
  • Serve as an information security expert and ensure technology contracts adhere to NYS Security Policies and standards and align with the strategic direction of ITS and CISO.
  • Monitor and remain aware of information security industry trends, tools, and techniques.
  • Ensure that all communications, processes, and teams within CRM are done in consideration of the operational concerns and workloads of peer teams throughout CISO and ITS, and that staff maintain the collaborative attitude and open communications required to successfully carry out the mission of CISO and ITS.
  • Evaluate high-impact initiatives, monitor ongoing progress, and execute corrective strategies as needed.
  • Mentor and supervise staff in the proper performance of their duties.

Minimum Qualifications

  • Information Security Manager Non-competitive: Nine years of information technology, cybersecurity, or information assurance experience*, including three years at the supervisory level or one year at the managerial level
  • Or One year of state service as a Manager Information Technology Services 2 (Information Security)

Substitutions:

  • A bachelor’s or higher-level degree in any field including or supplemented by 15 semester credit hours in computer science or related field substitutes for three years of required experience; any bachelor’s substitutes for two years of required experience.
  • An associate degree with 15 semester credit hours in computer science or related field may substitute for one year of required experience.
  • Candidates in a bachelor’s degree program with at least 15 semester credit hours in computer science or related field may substitute such credits for one year of required experience.
  • A master’s degree or higher in computer science or related field substitutes for one year of required experience.

Preferred Qualifications

  • Certifications in one or more of the following:
    • Cyber Defense (e.g., GCIA, GCIH, GCED, GSOM, GSOC, GMON, GCDA)
    • Cyber Threat Intelligence (e.g., GCTI, CTIA, CCIP, GOSI)
    • Information Security Management (e.g., CISSP, CISM, CCISO)
  • Experience in one or more of the following areas:
    • Leading and managing teams
    • Technical writing
    • Cyber risk management
    • Identifying, assessing, prioritizing, and remediating security vulnerabilities
    • Managing a vulnerability disclosure program
    • Designing, implementing and configuring larger application platforms, such as an enterprise resource planning (ERP) solution
    • Development and analysis of KPIs and metrics based on provided requirements
    • Process development and continuous improvement
    • Information security incident response
  • Strong understanding of the foundations of Information Security, such as the CIA triad, information classification, identity and access management, risk management, vulnerability management, secure architecture and engineering, network security, software development security, etc.
  • Excellent oral and written communication skills including the ability to clearly articulate information technology and information security concepts to a varied audience to facilitate wide understanding
  • Demonstrated critical thinking, problem solving and analytical skills
  • Strong capabilities in developing and maintaining positive relationships with shared services teams within CISO and other divisions as required
  • Demonstrated skill in facilitating meetings, listening, and negotiating between multiple stakeholders to drive results

Similar jobs