Source: New York State Jobs · Bespree is not the employer.
ITS provides operational support to state agencies on a 24x7x365 basis; some positions may be required to provide this critical service at any time.
Under the direction of a Deputy Chief Information Security Officer within the Chief Information Security Office (CISO) the incumbent will serve as the Director of the Cyber Risk Management (CRM) bureau, providing oversight of the Vulnerability Management, Threat Response, and Cyber Process Improvement & Metrics sections. The CRM Bureau is responsible for the oversight and operations of a variety of security tools and response functions to help ensure optimal cybersecurity protections, identification and remediation of vulnerabilities, and cyber risk reduction for ITS and its client agencies. The CRM bureau is also responsible for driving process improvement and developing metrics for the CISO division, as well as managing development and oversight of the Government Risk and Compliance (GRC) platform. The incumbent will provide direction and support for all activities and staff within the bureau, as well as subject matter expertise on vulnerability management and response, security program metrics, and process improvement. The incumbent will act as a member of the Chief Information Security Office Leadership Team, helping shape and implement the strategic vision for cyber security within NYS.
The position requires an incumbent to act with a great deal of independence in alignment with agency and upper-level management strategic direction. The position requires communicating orally and in writing with various individuals including management, users, vendors, and other IT staff. The incumbent must be able to communicate clearly with subordinate staff regarding work priorities and performance. The incumbent will have to work with various teams and stakeholders to resolve technically complex and politically sensitive issues under pressure.
The position requires availability during off-shift hours to ensure appropriate response to security incidents or other critical activities that may impact sensitive information, critical systems, NYS agencies, or ITS.
Specific duties include, but are not limited to:
Minimum Qualifications
Information Security Manager
Non-competitive: Nine years of information technology, cybersecurity, or information assurance experience*, including three years at the supervisory level or one year at the managerial level
Or
One year of state service as a Manager Information Technology Services 2 (Information Security)
*Substitutions: A bachelor's or higher-level degree in any field including or supplemented by 15 semester credit hours in computer science or related field substitutes for three years of required experience; any bachelor’s substitutes for two years of required experience. An associate degree with 15 semester credit hours in computer science or related field may substitute for one year of required experience. Candidates in a bachelor’s degree program with at least 15 semester credit hours in computer science or related field may substitute such credits for one year of required experience. A master’s degree or higher in computer science or related field substitutes for one year of required experience.
Preferred Qualifications
o Cyber Defense (e.g., GCIA, GCIH, GCED, GSOM, GSOC, GMON, GCDA)
o Cyber Threat Intelligence (e.g., GCTI, CTIA, CCIP, GOSI)
o Information Security Management (e.g., CISSP, CISM, CCISO)
o Leading and managing teams
o Technical writing
o Cyber risk management
o Identifying, assessing, prioritizing, and remediating security vulnerabilities
o Managing a vulnerability disclosure program
o Designing, implementing and configuring larger application platforms, such as an enterprise resource planning (ERP) solution
o Development and analysis of KPIs and metrics based on provided requirements
o Process development and continuous improvement
o Information security incident response
New York State agencies, departments, and public authorities provide services across healthcare, engineering, administration, public safety, the trades, and other areas.
Source: New York State Jobs · Bespree is not the employer.
ITS provides operational support to state agencies on a 24x7x365 basis; some positions may be required to provide this critical service at any time.
Under the direction of a Deputy Chief Information Security Officer within the Chief Information Security Office (CISO) the incumbent will serve as the Director of the Cyber Risk Management (CRM) bureau, providing oversight of the Vulnerability Management, Threat Response, and Cyber Process Improvement & Metrics sections. The CRM Bureau is responsible for the oversight and operations of a variety of security tools and response functions to help ensure optimal cybersecurity protections, identification and remediation of vulnerabilities, and cyber risk reduction for ITS and its client agencies. The CRM bureau is also responsible for driving process improvement and developing metrics for the CISO division, as well as managing development and oversight of the Government Risk and Compliance (GRC) platform. The incumbent will provide direction and support for all activities and staff within the bureau, as well as subject matter expertise on vulnerability management and response, security program metrics, and process improvement. The incumbent will act as a member of the Chief Information Security Office Leadership Team, helping shape and implement the strategic vision for cyber security within NYS.
The position requires an incumbent to act with a great deal of independence in alignment with agency and upper-level management strategic direction. The position requires communicating orally and in writing with various individuals including management, users, vendors, and other IT staff. The incumbent must be able to communicate clearly with subordinate staff regarding work priorities and performance. The incumbent will have to work with various teams and stakeholders to resolve technically complex and politically sensitive issues under pressure.
The position requires availability during off-shift hours to ensure appropriate response to security incidents or other critical activities that may impact sensitive information, critical systems, NYS agencies, or ITS.
Specific duties include, but are not limited to:
Minimum Qualifications
Information Security Manager
Non-competitive: Nine years of information technology, cybersecurity, or information assurance experience*, including three years at the supervisory level or one year at the managerial level
Or
One year of state service as a Manager Information Technology Services 2 (Information Security)
*Substitutions: A bachelor's or higher-level degree in any field including or supplemented by 15 semester credit hours in computer science or related field substitutes for three years of required experience; any bachelor’s substitutes for two years of required experience. An associate degree with 15 semester credit hours in computer science or related field may substitute for one year of required experience. Candidates in a bachelor’s degree program with at least 15 semester credit hours in computer science or related field may substitute such credits for one year of required experience. A master’s degree or higher in computer science or related field substitutes for one year of required experience.
Preferred Qualifications
o Cyber Defense (e.g., GCIA, GCIH, GCED, GSOM, GSOC, GMON, GCDA)
o Cyber Threat Intelligence (e.g., GCTI, CTIA, CCIP, GOSI)
o Information Security Management (e.g., CISSP, CISM, CCISO)
o Leading and managing teams
o Technical writing
o Cyber risk management
o Identifying, assessing, prioritizing, and remediating security vulnerabilities
o Managing a vulnerability disclosure program
o Designing, implementing and configuring larger application platforms, such as an enterprise resource planning (ERP) solution
o Development and analysis of KPIs and metrics based on provided requirements
o Process development and continuous improvement
o Information security incident response
New York State agencies, departments, and public authorities provide services across healthcare, engineering, administration, public safety, the trades, and other areas.