> Markdown version of [/jobs/ext/1812084-governance-risk-and-compliance-manager-special-assistant-ns](https://www.wearedevelopers.com/jobs/ext/1812084-governance-risk-and-compliance-manager-special-assistant-ns). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Governance, Risk, and Compliance Manager (Special Assistant, NS) - **Company:** NYS Governor's Office of Employee Relations - **Location:** Albany, NY, United States (Remote available) - **Experience:** Experienced - **Salary:** $127,507.0 - $160,911.0 - **Contract:** Temporary contract - **Skills:** Automation of Tests, Cyber Security, Information Security Management, PCI Data Security Standards, Information Technology, Data Analytics, CIS Benchmarks - **Published:** July 10, 2026 - **Apply:** https://statejobsny.com/public/vacancyDetailsView.cfm?id=219580 ## About the Role * Minimum of seven (11) years of experience in risk management, internal control, compliance, information security or information technology fields, two years of which must have been at a managerial level. o Substitutions: An associates degree may substitute for two (2) years of experience; a bachelor's degree may substitute for four (4) years of experience; a master's degree may substitute for five (5) years of experience; a J.D. may substitute for six (6) years of experience; and a Ph.D. may substitute for seven (7) years of experience. * Experience in a leadership role is preferred. Employment history should demonstrate increasing levels of responsibility. * Knowledge of common information security management frameworks, such as NIST 800-53, CIS Controls. * Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate security and risk-related concepts to technical and nontechnical audiences. ## Description Duties Description The New York State Department of Financial Services seeks to build an equitable, transparent, and resilient financial system that benefits individuals and supports business. Through engagement, data-driven regulation and policy, and operational excellence, the Department and its employees are responsible for empowering consumers and protecting them from financial harm; ensuring the health of the entities we regulate; driving economic growth in New York through responsible innovation; and preserving the stability of the global financial system. The Department of Financial Services is seeking candidates for the position of Governance, Risk and Compliance Manager within Information Security. This position will report directly to the Deputy Superintendent for Information Security, and will be responsible for ensuring that NYS DFS operates within internal boundaries (governance), manages operational and security (risk), and complies with legal and regulatory requirements (compliance) for all information technology efforts. They will act as bridge between technical teams, the DFS legal department, and executive leadership to maintain a robust, secure, and legally compliant environment. Duties include, but are not limited to, the following: * Develops and maintains policies: Drafts, reviews, and updates DFS information security, privacy, and operational policies to align with best practices and business goals; * Ensures internal controls are mapped effectively. Knowledge of frameworks (e.g., NIST CSF, ISO 27001, CIS Controls); * Conducts information security risk assessments across various units to identify vulnerabilities and potential threats; * Collaborates with IT, and other teams to develop, track, and implement risk mitigation plans; * Maintains and updates the DFS risk register to support leadership in addressing information security risk; * Stays up to date on global regulatory changes (e.g., HIPAA, PCI-DSS) and assesses their impact on DFS; * Performs continuous testing of information security internal controls to ensure they are operating effectively and remediate any gaps identified; and * Other duties as assigned. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud)