Governance, Risk, and Compliance Manager (Special Assistant, NS)

NYS Governor's Office of Employee Relations
Albany, NY, United States
about 1 month ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$127,507.0 - $160,911.0
Working hours
Regular working hours

Tech stack

Automation of Tests Cyber Security Information Security Management PCI Data Security Standards Information Technology Data Analytics CIS Benchmarks

Job description

Duties Description The New York State Department of Financial Services seeks to build an equitable, transparent, and resilient financial system that benefits individuals and supports business. Through engagement, data-driven regulation and policy, and operational excellence, the Department and its employees are responsible for empowering consumers and protecting them from financial harm; ensuring the health of the entities we regulate; driving economic growth in New York through responsible innovation; and preserving the stability of the global financial system.

The Department of Financial Services is seeking candidates for the position of Governance, Risk and Compliance Manager within Information Security. This position will report directly to the Deputy Superintendent for Information Security, and will be responsible for ensuring that NYS DFS operates within internal boundaries (governance), manages operational and security (risk), and complies with legal and regulatory requirements (compliance) for all information technology efforts. They will act as bridge between technical teams, the DFS legal department, and executive leadership to maintain a robust, secure, and legally compliant environment.

Duties include, but are not limited to, the following:

  • Develops and maintains policies: Drafts, reviews, and updates DFS information security, privacy, and operational policies to align with best practices and business goals;
  • Ensures internal controls are mapped effectively. Knowledge of frameworks (e.g., NIST CSF, ISO 27001, CIS Controls);
  • Conducts information security risk assessments across various units to identify vulnerabilities and potential threats;
  • Collaborates with IT, and other teams to develop, track, and implement risk mitigation plans;
  • Maintains and updates the DFS risk register to support leadership in addressing information security risk;
  • Stays up to date on global regulatory changes (e.g., HIPAA, PCI-DSS) and assesses their impact on DFS;
  • Performs continuous testing of information security internal controls to ensure they are operating effectively and remediate any gaps identified; and
  • Other duties as assigned.

Requirements

  • Minimum of seven (11) years of experience in risk management, internal control, compliance, information security or information technology fields, two years of which must have been at a managerial level. o Substitutions: An associates degree may substitute for two (2) years of experience; a bachelor’s degree may substitute for four (4) years of experience; a master’s degree may substitute for five (5) years of experience; a J.D. may substitute for six (6) years of experience; and a Ph.D. may substitute for seven (7) years of experience.

  • Experience in a leadership role is preferred. Employment history should demonstrate increasing levels of responsibility.
  • Knowledge of common information security management frameworks, such as NIST 800-53, CIS Controls.
  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate security and risk-related concepts to technical and nontechnical audiences.

Benefits & conditions

This is an appointment to a position in the exempt jurisdictional class. As such, the incumbent of this position would serve at the pleasure of the appointing authority.

Additional Comments Please note that a change in negotiating unit may affect your salary, insurance and other benefits.

Salary: $127,507 - $160,911 (salary commensurate with experience)

Appointment Status: This is an appointment to a position in the exempt jurisdictional class.

Appointment to this position is pending Governor Appointment’s Office and Division of Budget approval.

Some positions may require additional credentials or a background check to verify your identity.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on statejobsny.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

1:32 min

Structuring platforms for new services and data analytics

Nevelina Aleksandrova · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

1:10 min

Introduction to Microsoft Fabric and data agents

Dr. Alexander Wachtel Dr. Alexander Wachtel +1 · World Congress 2025

Videos

See all

Related articles

See all