> Markdown version of [/jobs/ext/466835-information-security-manager-11249](https://www.wearedevelopers.com/jobs/ext/466835-information-security-manager-11249). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Manager - 11249 - **Company:** State of New York - **Location:** Latham, NY, United States - **Salary:** $127,507.0 - $160,911.0 - **Contract:** Temporary contract - **Skills:** Amazon S3, Applications Architecture, Cyber Security, Identity and Access Management, Information Systems Security Architecture Professional, Network Security, Network Architecture, Software Engineering, Software Vulnerability Management, Information Security Management System, Data Classification, Information Technology - **Published:** June 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f2d0fc7d77864bbd ## About the Role Do you have experience in Writing skills?, Do you have a Master's degree?, The minimum qualifications required for this vacancy. Minimum Qualifications Information Security ManagerNon-competitive: Nine years of information technology, cybersecurity, or information assurance experience*, including three years at the supervisory level or one year at the managerial level.*Substitutions: A bachelor's or higher-level degree in any field including or supplemented by 15 semester credit hours in computer science or related field substitutes for three years of required experience; any bachelor's substitutes for two years of required experience.An associate degree with 15 semester credit hours in computer science or related field may substitute for one year of required experience. Candidates in a bachelor's degree program with at least 15 semester credit hours in computer science or related field may substitute such credits for one year of required experience.A master's degree or higher in computer science or related field substitutes for one year of required experience.Preferred qualifications: * Applicable Information Security certificate(s) such as CISSP, CISM, etc.* Experience in one or more of the following areas: o Leading information security teamso Applying and implementing network, system, or application securityo Security policy/standard/guideline development, implementation, or interpretationo Conducting risk assessments and evaluating information technology systems for security controls (SSDLC)o Process development, improvement, and measuremento Information security incident responseo Developing metrics and key performance indicators* Strong understanding of enterprise IT environments, including but not limited to system administration, application architecture, network architecture, operating systems, and associated security controls and solutions (e.g., WAF, firewalls)* Strong understanding of the foundations of Information Security, such as the CIA triad, information classification, identity and access management, risk management, vulnerability management, secure architecture and engineering, network security, software development security, etc.* Excellent oral and written communication skills including the ability to clearly articulate information technology and information security concepts to a varied audience to facilitate wide understanding* Demonstrated critical thinking, problem solving and analytical skills* Demonstrated excellence in customer service* Demonstrated skill in facilitating meetings, listening, and negotiating between multiple stakeholders to drive results ## Description The duties that the incumbent of the vacancy will be expected to perform. Duties Description ITS provides operational support to state agencies on a 24x7x365 basis; some positions may be required to provide this critical service at any time.Under the direction of the Executive Director of Security Shared Services (S3), within the Chief Information Security Office/Security Shared Services section, this position will assist with the oversight of the Security Shared Services Bureau. The position will supervise four or more Senior Information Security Officers SG-29 which lead teams supporting the security needs of multiple ITS dedicated agency/sector teams. The position will oversee the Incident Response Program. The position will assist with oversight of the NYS Cyber Risk Remediation Program (CRRP) and the development of products offered by the Chief Information Security Office (CISO). The incumbent will act as a member of the Chief Information Security Office Executive Leadership Team and participate in shaping and implementing the strategic vision for cybersecurity within NYS. The position requires an incumbent to act with a great deal of independence in alignment with agency and upper-level management strategic direction. The position requires communicating orally and in writing with various individuals and groups including, but not limited to, executive management, business users and other IT staff. The incumbent must be able to communicate with clarity to subordinate staff regarding work priorities and performance. The incumbent will have to work with ITS Dedicated Support Teams and upper-level agency management to resolve technically complex and politically sensitive issues under pressure. The incumbent will have strong customer service skills and will focus on developing relationships with key stakeholders.The position requires availability during off-shift hours to ensure appropriate response to security incidents or other critical matters that may impact sensitive information, critical systems, ITS, NYS agencies, or other partners (such as local governments).Duties include, but are not limited to: * Assist with the direction of the Security Shared Services Bureau in developing, deploying, and maintaining processes and procedures in alignment with NYS State and agency information security policies and standards. Monitor compliance and take appropriate action as needed.* Oversee the continued development of the ITS Cyber Incident Response Program which includes continuously improving procedures and ensuring 24x7x365 rotating coverage schedules for IR responders.* Enhance the Secure Software Development Lifecycle (SSDLC) process in response to shifting cyber landscape and the requirements of ITS, agencies, and NYS.* Foster and develop relationships with key stakeholders, such as the Dedicated Commissioners of Technology (DCTs).* Provide off-hours leadership in response to cyber treats, incidents, and events on a rotating basis.* Serve as information security expert and evaluate systems and contracts for alignment with agency and State information security policies.* Provide advisement and expertise in the development of NYS security policies and standards.* Assist with development and implementation of the Security Shared Services Bureau's program and associated products.* Perform administrative and strategic functions to assist the CISO Executive Leadership team in managing the operations of the Chief Information Security Office.* Monitor and maintain awareness of information security industry trends, tools, and techniques.* Perform the full range of supervisory responsibilities. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [WeAreDevelopers LIVE - CSS is DOOMed](https://www.wearedevelopers.com/videos/1838-wearedevelopers-live-css-is-doomed) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Blockchains: One Size doesn't Fit All](https://www.wearedevelopers.com/videos/409-blockchains-one-size-doesn-t-fit-all) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)