Director of Cyber Risk Management/Information Security Manager - 20001NYC

StateJobsNY$125K — $150K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 9 years of experience in IT, cybersecurity, or information assurance, including 3 years in a supervisory role, or 1 year in a managerial role.
  • Bachelor's degree with relevant coursework can substitute for required experience.
  • Certifications in Cyber Defense, Threat Intelligence, or Information Security Management preferred.
  • Strong understanding of information security principles, including the CIA triad and risk management.
  • Excellent oral and written communication skills with the ability to convey complex concepts clearly.

Responsibilities

  • Lead and direct activities within the Cyber Risk Management bureau.
  • Develop strategic plans for bureau operations and improvement.
  • Oversee threat and vulnerability response processes to reduce cyber risks.
  • Manage the GRC Platform and related documentation.
  • Implement the CISO Metrics Program with reporting and dashboards.
  • Establish a vulnerability disclosure program to triage findings from security researchers.
  • Provide subject matter expertise and leadership across all teams within CRM.

Benefits

  • Generous benefits package equivalent to 65% of salary
  • Thirteen paid holidays and up to 13 days of paid vacation annually
  • Health insurance options with family dental and vision benefits at no cost
  • Membership in the New York State Employees' Retirement System
  • Access to Public Service Loan Forgiveness and college savings programs.
Full Job Description
Duties Description ITS provides operational support to state agencies on a 24x7x365 basis; some positions may be required to provide this critical service at any time.

Under the direction of a Deputy Chief Information Security Officer within the Chief Information Security Office (CISO) the incumbent will serve as the Director of the Cyber Risk Management (CRM) bureau, providing oversight of the Vulnerability Management, Threat Response, and Cyber Process Improvement & Metrics sections. The CRM Bureau is responsible for the oversight and operations of a variety of security tools and response functions to help ensure optimal cybersecurity protections, identification and remediation of vulnerabilities, and cyber risk reduction for ITS and its client agencies. The CRM bureau is also responsible for driving process improvement and developing metrics for the CISO division, as well as managing development and oversight of the Government Risk and Compliance (GRC) platform. The incumbent will provide direction and support for all activities and staff within the bureau, as well as subject matter expertise on vulnerability management and response, security program metrics, and process improvement. The incumbent will act as a member of the Chief Information Security Office Leadership Team, helping shape and implement the strategic vision for cyber security within NYS.

The position requires an incumbent to act with a great deal of independence in alignment with agency and upper-level management strategic direction. The position requires communicating orally and in writing with various individuals including management, users, vendors, and other IT staff. The incumbent must be able to communicate clearly with subordinate staff regarding work priorities and performance. The incumbent will have to work with various teams and stakeholders to resolve technically complex and politically sensitive issues under pressure.

The position requires availability during off-shift hours to ensure appropriate response to security incidents or other critical activities that may impact sensitive information, critical systems, NYS agencies, or ITS.

Specific duties include, but are not limited to:
• Lead and direct all the activities within the Cyber Risk Management (CRM) bureau across multiple managers.
• Responsible for the overall vision and direction of the CRM bureau, including the development of strategic plans to revise and improve upon the bureau's work, drafting staffing plans, and the maintenance and development of charters, product catalogues, RACI charts, and other documentation.
• Oversee the development and maturation of the threat and vulnerability response process, helping CISO to reduce cyber risk by efficiently prioritizing and responding to significant vulnerabilities and emerging cyber threats.
• Oversee the team responsible for the GRC Platform and the CISO SharePoint site, including development, configurations, development, and maintenance through formalized tracking and release management.
• Oversee the development and maturation of the CISO Metrics Program, including collecting and displaying various data points for stakeholders through reports and dashboards.
• Oversee the creation of a vulnerability disclosure program to receive and triage vulnerabilities identified by security researchers.
• Provide guidance on cyber risk management best practices and strategies for risk identification and remediation to support the development and improvement of the agency's GRC platform.
• Provide leadership, guidance, and subject matter expertise across all teams within CRM.
• Serve as an information security expert and ensure technology contracts adhere to NYS Security Policies and standards and align with the strategic direction of ITS and CISO.
• Monitor and remain aware of information security industry trends, tools, and techniques.
• Ensure that all communications, processes, and teams within CRM are done in consideration of the operational concerns and workloads of peer teams throughout CISO and ITS, and that staff maintain the collaborative attitude and open communications required to successfully carry out the mission of CISO and ITS.
• Evaluate high-impact initiatives, monitor ongoing progress, and execute corrective strategies as needed
• Mentor and supervise staff in the proper performance of their duties.
• Perform additional duties as required.

Minimum Qualifications Minimum Qualifications
Information Security Manager
Non-competitive: Nine years of information technology, cybersecurity, or information assurance experience*, including three years at the supervisory level or one year at the managerial level
Or
One year of state service as a Manager Information Technology Services 2 (Information Security)

*Substitutions: A bachelor's or higher-level degree in any field including or supplemented by 15 semester credit hours in computer science or related field substitutes for three years of required experience; any bachelor's substitutes for two years of required experience. An associate degree with 15 semester credit hours in computer science or related field may substitute for one year of required experience. Candidates in a bachelor's degree program with at least 15 semester credit hours in computer science or related field may substitute such credits for one year of required experience. A master's degree or higher in computer science or related field substitutes for one year of required experience.

Preferred Qualifications
• Certifications in one or more of the following:
o Cyber Defense (e.g., GCIA, GCIH, GCED, GSOM, GSOC, GMON, GCDA)
o Cyber Threat Intelligence (e.g., GCTI, CTIA, CCIP, GOSI)
o Information Security Management (e.g., CISSP, CISM, CCISO)
• Experience in one or more of the following areas:
o Leading and managing teams
o Technical writing
o Cyber risk management
o Identifying, assessing, prioritizing, and remediating security vulnerabilities
o Managing a vulnerability disclosure program
o Designing, implementing and configuring larger application platforms, such as an enterprise resource planning (ERP) solution
o Development and analysis of KPIs and metrics based on provided requirements
o Process development and continuous improvement
o Information security incident response
• Strong understanding of the foundations of Information Security, such as the CIA triad, information classification, identity and access management, risk management, vulnerability management, secure architecture and engineering, network security, software development security, etc.
• Excellent oral and written communication skills including the ability to clearly articulate information technology and information security concepts to a varied audience to facilitate wide understanding
• Demonstrated critical thinking, problem solving and analytical skills
• Strong capabilities in developing and maintaining positive relationships with shared services teams within CISO and other divisions as required.
• Demonstrated skill in facilitating meetings, listening, and negotiating between multiple stakeholders to drive results

Additional Comments ITS will not offer permanent employment to any candidate unless the candidate provides documentation that they are authorized to accept work in the United States on a permanent basis. It is the policy of ITS not to hire F1 or H1 visa holders for permanent employment or to sponsor non-immigrant aliens for temporary work authorization visas or for permanent residence.

Some positions may require fingerprinting.

Some positions may require up to 25% travel and/or lifting up to 50 lbs. Some positions are pending Civil Service approval. Details of position(s) will be described further if you are selected for an interview.

If eligible, positions located in New York City will receive an additional $4,000 downstate adjustment location pay with regular annual salary. Positions located in the Mid-Hudson will receive an additional $2,000 adjustment location pay.
to permanent non-competitive and the official probationary period will begin.

Benefits of Working for NYS Generous benefits package, worth 65% of salary, including:
Holiday & Paid Time Off
• Thirteen (13) paid holidays annually
• Up to Thirteen (13) days of paid vacation leave annually
• Up to Five (5) days of paid personal leave annually
• Up to Thirteen (13) days of paid sick leave annually for PEF.
• Up to three (3) days of professional leave annually to participate in professional development

Health Care Benefits
• Eligible employees and dependents can pick from a variety of affordable health insurance programs
• Family dental and vision benefits at no additional cost

Additional Benefits
• New York State Employees' Retirement System (ERS) Membership
• NYS Deferred Compensation
• Access to NY 529 and NY ABLE College Savings Programs, as well as U.S. Savings Bonds
• Public Service Loan Forgiveness (PSLF)
• And many more.

Name ITS Human Resources



Fax 518-402-4924

Email Address [email protected]

Address

Street 164 Columbia Turnpike

City Rensselaer

State NY

Zip Code 12144

Notes on Applying To apply for this position, please submit a cover letter and resume clearly indicating how you qualify. Ensure that you include the vacancy ID in the subject of your email for prompt routing. Your Social Security number may be required to confirm eligibility.

About StateJobsNY

StateJobsNY Careers

There has never been a better time to explore the diverse array of job opportunities at StateJobsNY—the premier hub for public sector employment in New York.

Work You’ll Do

Join StateJobsNY to engage in meaningful work that directly impacts the lives of millions. StateJobsNY offers a unique platform where innovation meets public service, providing a broad spectrum of career paths ranging from administrative roles to leadership positions in various state departments. Transform public service with your skills and dedication. At StateJobsNY, every position plays a crucial role in shaping the future of New York’s communities. Lead with professionalism and purpose. StateJobsNY positions you perfectly at the nexus of public needs and innovative solutions. Collaborate with a dedicated team of professionals who are committed to excellence in service and leadership. StateJobsNY fosters a culture of growth and learning, where every employee is encouraged to expand their horizons.

StateJobsNY Employment Advantages

The team is committed to building a supportive environment where careers flourish and talents are honed. StateJobsNY offers competitive benefits, comprehensive diversity training, and opportunities for professional development.

Do Innovative Work

Engage with a team that values creativity and forward-thinking. StateJobsNY is a place where your ideas can lead to substantial improvements in how public services are delivered.

Drive Change in Public Sector

Deliver solutions that make a real difference. With StateJobsNY, your efforts contribute directly to the development and implementation of policies that benefit the public.

Be Part of a Great Team

Join a workforce that is as diverse as the state itself. StateJobsNY is proud of its inclusive culture that embraces diversity and fosters an environment of respect and cooperation.

Future-Proof Your Career

With StateJobsNY, the path to personal and professional growth is clear. Embrace the chance to develop leadership skills and gain valuable experience that will serve you throughout your career.

Explore

Discover how StateJobsNY is leading the way in public sector innovation: - Implementing advanced digital solutions to enhance state services. - Pioneering initiatives that promote sustainable practices across all departments.

The StateJobsNY Difference

With a commitment to excellence and a focus on sustainable growth, StateJobsNY not only meets today’s challenges but also anticipates the needs of tomorrow. Professionals looking to make a tangible impact will find StateJobsNY an ideal place to grow and contribute.

Stay Connected

Join the Team

Search open positions that match your skills and interests. StateJobsNY seeks passionate, curious, and driven individuals ready to make a difference. SEARCH STATEJOBSNY JOBS

Keep Up to Date

Stay informed with career tips, insider perspectives, and industry-leading insights—all from the dedicated professionals at StateJobsNY.

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding opportunities that await at StateJobsNY.
Learn more about StateJobsNY

Similar Jobs

More Jobs at StateJobsNY

More Information Technology Jobs

Find similar Director of Cyber Risk Management/Information Security Manager - 20001NYC jobs: