Manager Information Technology Services 2

Street One Commerce Plaza
Albany, NY, United States
3 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$118,425.0 - $145,039.0
Working hours
Regular working hours

Tech stack

Cyber Security Information Systems Computer Networks Data Security Web Browsers Information Sciences Information Security Management Internet Security Network Forensics Information Technology CIS Benchmarks Vulnerability Analysis

Job description

The Department of Financial Services is seeking candidates for the position of Manager Information Technology Services 2 (Information Security) within Information Security. Duties include, but are not limited to, the following:

  • Directs and manages implementation of information security and compliance programs;
  • Provides direction and guidance to teams with responsibility for developing, deploying, and maintaining information security architecture;
  • Directs the development, interpretation, review, and communication of information security policies, procedures, and standards;
  • Coordinates the implementation of information security procedures, risk reviews, and remediation activity, monitors information security compliance, recommends improvements to monitor access to information assets and ensure security safeguards are maintained;
  • Manages and resolves security threats to agency information systems and information security incident response;
  • Directs development and implementation of information security risk analysis and management processes; coordinates vulnerability scanning and analysis to help determine risk and remediation priorities; manages development and maintenance of enterprise risk registers, which includes reporting and tracking remediation efforts;
  • Directs the characterization and analysis of network traffic to identify anomalies and potential threats to network resources; determines events that require investigation and response;
  • Implements and improves information security incident response plans and reports;
  • Develops and implements plans and procedures to ensure business critical services are recovered in disaster efforts;
  • Directs investigation of alleged information security violations; coordinates collection, seizure, handling, and analysis of digital evidence; responds to requests for information from investigators;
  • May testify in proceedings regarding analytical processes and findings; Serves as an information security expert and evaluates systems and contracts for alignment with State policies and standards;
  • Reviews contract, service level agreement, memorandum of understanding language, and other documents to verify needs, requirements, and alignment with State policies and standards;
  • Provides information security expertise and recommendations to agency executives on a broad range of information security matters;
  • Researches laws and regulations that could affect the security controls and classification of information assets;
  • Monitors information security trends, tools, and techniques to maintain awareness and evaluate the applicability of the latest information security techniques and tools to agencies’ security programs;
  • Develops a multilayered and adaptive approach to counter information security threat environments; represents the agency at internal and external information security meetings;
  • Manages staff and resources dedicated to information security programs;
  • Collects metrics to measure the efficiency and effectiveness of information security programs;
  • Performs the full range of supervisory responsibilities; and
  • Other duties as assigned.

Requirements

  • Bachelor’s degree in Information Security, Computer Science, Management of Information Systems, or a related field required. Master’s degree and professional certifications, such as CISSP, preferred.
  • Minimum of seven (7) years of experience in a combination of risk management, information security and information technology fields. Experience in a leadership role is preferred. Employment history should demonstrate increasing levels of responsibility.
  • Knowledge and understanding of common information security management frameworks, such as NIST 800-53, CIS Controls.
  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate security and risk-related concepts to technical and non-technical audiences. Technical experience in the fields of cybersecurity, information security, information technology and/or cybersecurity intelligence.
  • Proven track record and experience in developing information security policies and procedures, as well as successfully executing programs that meet the objectives of excellence in a dynamic environment.
  • Familiarity with cybersecurity regulations, including the DFS Cybersecurity Regulation (23 NYCRR Part 500).
  • Strong analytical skills and ability to write clearly on complex issues.

Appointment Method:

Candidates must meet the minimum qualifications listed below in order to be eligible for appointment.

Non-Competitive: Eight years of information technology, cybersecurity, or information assurance experience*, including two years at the supervisory level.

  • Substitutions: A bachelor’s degree or higher in any field including or supplemented by 15 semester credit hours in computer science or related field substitutes for three years of required experience; any bachelor’s degree substitutes for two years of required experience.

An associates degree with 15 semester credit hours in computer science or related field may substitute for one year of required experience. Candidates in a bachelor’s degree program with at least 15 semester credit hours in computer science or related field may substitute such credits for one year of required experience.

A master’s degree or higher in computer science or related field substitutes for one year of required experience., Analysis Skills, Business Services, Business Support, CISSP - Certified Information Systems Security Professional, Communication Skills, Communications Security (COMSEC), Computer Forensics, Computer Science, Computer Security, Contract Review, Economic Growth, Financial Services, Financial Systems, Frequently Asked Questions (FAQ), Global Financial Markets, High Tech Industry, Human Resources Management, Incident Response, Information Architecture, Information Assets, Information Science, Information Technology & Information Systems, Information/Data Security (InfoSec), Internet Security, Interpersonal Skills, Leadership, Legal Research, Maintain Compliance, Management of Information Systems/Technology (MIS), Metrics, Network Performance/Analysis, Network Traffic Analysis, People Management, Policy Development, Presentation/Verbal Skills, Procedure Development, Procedure Implementation, Regulations, Request for Information (RFI), Resource Management, Risk, Risk Analysis, Risk Management, Security Analysis, Security Architecture, Security Attacks, Security Compliance, Security Monitoring, Service Level Agreement (SLA), Team Player, U.S. National Institute of Standards and Technology (NIST), Vulnerability Scanners, Web Browsers, Willing to Travel, Writing Skills

Benefits & conditions

Additional Comments Please note that a change in negotiating unit may affect your salary, insurance and other benefits.

Salary: The starting salary for this position is $118,425 with periodic increases up to $145,039

Positions located within the New York City metropolitan area, as well as Suffolk, Nassau, Rockland, and Westchester Counties, are also eligible to receive an additional $4,000 annual downstate adjustment.

Appointment Status: Temporary

Appointment to this position is pending Governor Appointment’s Office and Division of Budget approval.

Some positions may require additional credentials or a background check to verify your identity.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:21 min

Running custom language parsers in web browser environments

Irina Artemeva · World Congress 2023

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

1:46 min

Connecting hardware prototypes to the web browser

George Cave · World Congress 2023

Videos

See all

Related articles

See all