> Markdown version of [/jobs/ext/2284644-supervising-programmer-analyst](https://www.wearedevelopers.com/jobs/ext/2284644-supervising-programmer-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Supervising Programmer/Analyst - **Company:** BUFFALO STATE - **Location:** Buffalo, NY, United States - **Salary:** $77,346.0 - $143,611.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing, Cyber Security, System Configuration, Linux, VMware ESX Servers, Hypervisor, Intrusion Detection Systems, Information Systems Security Architecture Professional, Windows Servers, Nmap, Zero Trust Network Access, Security Information and Event Management, Software Requirements Analysis, Wireshark, Snort (Software), Computer Networking Systems, Google Cloud, Metasploit, Vcenter - **Published:** August 28, 2026 - **Apply:** http://hr.buffalostate.edu/sites/hr.buffalostate.edu/files/uploads/Documents/classified_applicants_recruitment_merge.pdf ## About the Role 1. A bachelor's degree in a security, computing, programming, networking or related field, and progressive relevant professional work experience.. 2. Good presentation skills, interpersonal skills, written and communication skills. 3. Demonstrated familiarity with compliance requirements (e.g., PCI, GLBA, FERPA) and NIST Cybersecurity Framework (CSF) or equivalents. 4. Demonstrated familiarity with creating and implementing security policies, risk assessments and tabletop exercises. 5. Demonstrated familiarity with Incident Response (IR) and creating IR Plans. Preferred Qualifications 1. Master's degree in information security or assurance, such as MSIA, or Certifications related to Security Operations/Architecture/Engineering: ISC2: CISM, CISSP or SSCP.(CISSP-ISSAP or ISSEPa plus); relevant SANS GIAC series; or others, like PNPT, OSCP, CEH, CISA, or CySA+. 2. Familiarity with Security Tools such as Zeek, Snort, Suricata, Nmap, Metasploit, Wireshark, OpenVAS, Autopsy, etc. 3. Working or managerial experience in a large organization, especially higher education. 4. Recent operational or administrative experience with EDR, SIEM, IDS/IPS Systems or Zero Trust Networks. 5. Experience responding to or advising the response to a security breach, such as notification, chain of custody, guiding forensics, or compliance reporting. 6. Experience in System Administration for Windows servers, vCenter/ESXi, Linux, Hypervisors, Networking Infrastructure a plus. 7. Cloud provider experience and/or certifications with any of Azure, AWS, Google Cloud. 8. Membership in REN-ISAC, MS-ISAC, or other industry ISAC. ## Description ITEC's External Security Services Information Security Officer (ESISO) provides strategic cybersecurity leadership and advisory services to higher education institutions. The role focuses on assessing and implementing security strategies, policies, and frameworks aligned with the unique needs of universities and colleges, while helping manage cyber risk, regulatory compliance, and protection of academic, research, and administrative data. The ESISO serves as a trusted security advisor and advocate to campus and ITEC senior management, clearly communicating risks, priorities, and recommendations in business-relevant terms. The position requires a strong understanding of information security programs within complex U.S. organizations, including higher education, SUNY, and New York State government environments. With team leadership and security program management as core responsibilities, the role also carries a strong project management focus, coordinating deliverables with the Security Services Service Delivery Manager. The ESISO helps define, oversee, and contribute to approved campus security projects. The role also supports campuses during security incidents and advises on security-focused software, system requirements, compliance (e.g., GLBA, PCI, FERPA, HIPAA) and appropriate hardware and software configurations., + Buffalo State website + Buffalo News + Buffalo Rocket + Challenger + Chronicle of Higher Education + HigherEdJobs + Panorama Hispano News + Employee Referral + Other 2. * All applicants are subject to a pre-employment background investigation. The college's Pre-Employment Background Screening Policy is available at http://hr.buffalostate.edu/pre-employment-background-screening. Prior to an offer of employment, an applicant will be required to sign an authorization release form, allowing Buffalo State to conduct a background investigation. Failure of an applicant to sign the authorization release form will disqualify an applicant from further consideration for appointment. + I agree to comply with the college's policy. + I do not agree to comply with the college's policy. (Note, this selection will disqualify you from further consideration for appointment.) 3. * Do you have a bachelor's degree in a security, computing, programming, networking or related field, and progressive relevant professional work experience? + Yes + No 4. * Do you have demonstrated familiarity with compliance requirements (e.g., PCI, GLBA, FERPA) and NIST Cybersecurity Framework (CSF) or equivalents? + Yes + No Documents Needed to Apply Required Documents 1. Resume / Curriculum Vitae 2. Cover Letter 3. Names and Contact Information for 3 Professional References Optional Documents ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)