Description Position at MTA Headquarters
JOB TITLE:
Cybersecurity Engineer Level 4
SALARY RANGE:
$105,843 - $143,948
DEPT/DIV:
Information Technology
SUPERVISOR:
CybSecOffMgr AccesMgmtIdentSec
LOCATION:
2 Broadway, New York, NY 10004
HOURS OF WORK:
9:00 am - 5:30 pm (7.5 hours/day) or as required
This position is eligible for teleworking, which is currently one day per week. New hires are eligible to apply 30 days after their effective date of hire.
Job Summary:
The purpose of this position is to provide technical expertise in managing and analyzing cybersecurity risks. Cybersecurity Engineer will be responsible for designing, building, and maintaining infrastructure and applications technology to support a secure cybersecurity posture. These include systems that support cybersecurity directly and/or the business operations for Information and Operational Technology disciplines. Secure building and configuration of systems (applications, infrastructure, wireless, carrier systems, cloud, operational technology, IOT, etc.) from the outset reduces risk to MTA. Specialized and focused skill sets in various technology domains assist with the overall risk reduction for the MTA. The configuration, hardening, guidance, response, and analysis of these systems aid in the reduction and containment of Cyber Security risk. Risk assessments, data analytics tools, operational process reviews, and collaboration with security engineers, architects, developers, vendors, and business units to constantly improve the overall security of the MTA.
Critical Skills: - Hands-on PAM platform engineering: privileged account vaulting, session management, credential rotation, and access request workflow configuration
- Experience with Privileged Identity Management (PIM) and Just-in-Time (JIT) access design and implementation, including approval workflows and time-bound elevation
- Tiered administration models (Tier 0-5): designing and enforcing privileged access controls, admin account separation, and secure administrative paths
- Knowledge of service account and non-human identity security: discovery, vaulting, rotation, and remediation coordination
- Strong experience with endpoint privilege management: least-privilege enforcement, elevation controls, and local admin removal
- Knowledge of operational support and troubleshooting of privileged access issues, including escalations and platform break/fix
Integration of PAM with directory, MFA, SSO, and ITSM platforms - Experience with infrastructure, OT, and application teams on remediation, while maintaining PAM ownership boundaries
Responsibilities:
- Researching emerging threats and vulnerabilities to aid in the identification of network incidents, and supporting the creation of new architecture, policies, standards, and guidance to address them
- Knowledge and practical implementation of secure system configuration and hardening standards
- Design, configure, and integrate secure solutions in the technology domains assigned
- Provide incident response support, including mitigating actions to contain activity and facilitating forensic analysis, system hardening, and recovery when necessary
- Provides installation, system configuration, hardening, and optimization for infrastructure, application, and security components and systems such as servers, workstations, mobile devices, directory services, operating systems, middleware, IOT, web and next-generation firewalls, machine and human behavior learning tools, host-based security system, security event and incident monitoring systems, virtual, physical, and cloud platforms.
- Identifies configuration gaps independently and/or with vendors to reduce cybersecurity risks
- Reviews alerts and data from sensors and documents formal, technical incident reports
- Performs other duties as assigned
- Complies with all policies and standards
- May be required to work hours outside regular work hours, as applicable
- Observes the work performed by contractors, as applicable
- Reviews invoices and approves them if the work has contractual standards, as applicable
- Addresses performance issues with the contractor when possible, as applicable
- Escalates issues to other parties when needed, as applicable
Qualifications:
- Bachelor's Degree in Arts/Sciences (BA/BS) and minimum 3 years of relevant experience required. An equivalent combination of education and experience may be considered in lieu of a degree.
- Bachelor's Degree in Arts/Sciences (BA/BS) in Computer Science or related fields preferred.
- Certified in Oracle Cloud Infrastructure. At least one certification in technology subdomains preferred upon hire but not required (ie., Cloud, Applications, Infrastructure, Security Technology, etc.)
- Current CISSP or other advanced security-related certification preferred upon hire but not required.
Knowledge, Skills, and Abilities:
- Proven ability to independently evaluate and resolve most problems within an area of infrastructure, applications within a security domain context.
- Proven ability to analyze and/or conduct a security risk assessment.
- Advanced understanding of TCP/IP (OSI Layers 1- 4) and Internet and Intranet technologies required (OSI Layers 5-7).
- Some scripting or programming skills (PERL, Python, PowerShell, etc.) preferred as needed.
Competencies:
Core Competency
Proficiency Level
Competency Definition
Communicates Effectively
Adept
Developing and delivering multi-mode communications that convey a clear understanding of the unique needs of different audiences
Values Diversity
Adept
Recognizing the value that different perspectives and cultures bring to an organization
Collaborates
Adept
Building partnerships and working collaboratively with others to meet shared objectives
Cultivates Innovation
Capable
Creating new and better ways for the organization to be successful
Customer Focus
Capable
Building strong customer relationships and delivering customer-centric solutions
Tech Savvy
Capable
Anticipating and adopting innovations in business-building digital and technology applications
Technical Skills
Capable
Specialized knowledge and expertise on tools, programs, domains, platforms, and products used for specific tasks
Other Information:
Pursuant to the New York State Public Officers Law & the MTA Code of Ethics, all employees who hold a policymaking position must file an Annual Statement of Financial Disclosure (FDS) with the NYS Commission on Ethics and Lobbying in Government (the "Commission").