About the Role:As an information systems security compliance manager in the Corporate Information Security practice area, you will assist the deputy chief information security officer (CISO) in administering the overall strategy, design, and implementation of information security initiatives on a company-wide basis. This position will interface with staff and management across all levels of NYSTEC, as well as with external business partners, to ensure that NYSTEC's critical business functions and systems are secure and in accordance with best practices.
Serving as an information systems security compliance manager, your day-to-day role will include executing all information security functions for the company in keeping with a perspective to mitigate risk and to balance enhanced capacity and productivity.
Key Responsibilities- Lead and develop the information security team, establishing priorities and goals while supporting staff performance and professional development.
- Oversee NYSTEC's governance, risk, and compliance program, including security policies, standards, controls, risk management, and compliance processes
- Ensure compliance with applicable security frameworks and requirements, including Cybersecurity Maturity Model Certification (CMMC), HIPAA/HITRUST, and state and federal regulations.
- Interpret evolving regulatory, industry, and contractual requirements and translate them into appropriate security controls and practices.
- Advise the Deputy CISO and senior leadership on cybersecurity risk, security posture, emerging issues, and potential business impacts.
- Oversee security audits and assessments, including control effectiveness, findings, remediation activities, and ongoing compliance monitoring.
- Partner with business and technical leaders to integrate security and data protection requirements into technology, processes, and organizational initiatives.
- Provide leadership and oversight for enterprise security initiatives, including technical projects, security controls, and response to significant incidents and vulnerabilities
- This role follows a hybrid work model, with an expectation of working on-site two days per week.
About you:Required Qualifications- Knowledge of the organization's enterprise information technology (IT) goals and objectives.
- Knowledge of laws, policies, procedures, and governance frameworks relevant to organizational cybersecurity requirements.
- Proficiency with Windows operating environments, Microsoft Office applications, email, and internet-based tools.
- Experience in information security, including developing, documenting, and supporting the adoption of information security standards and procedures.
- Experience with security technologies and protocols, such as firewalls, intrusion detection systems, demilitarized zones (DMZs), Internet Protocol Security (IPSec), Domain Name System (DNS), Simple Mail Transfer Protocol (SMTP), and Hypertext Transfer Protocol (HTTP) proxies.
- Knowledge of security best practices across multiple platforms, such as Microsoft Windows, Microsoft 365, and Cisco Internetwork Operating System (IOS).
- Project management skills, including the ability to coordinate priorities and manage multiple tasks.
- Effective written and verbal communication, time-management, and organizational skills.
- Experience with governance, risk, and compliance (GRC) tools, such as Hyperproof or similar platforms, to document risks, security exceptions, security incidents, policies, standards, and control procedures.
Preferred/Desired Qualifications
- Certified information systems security professional (CISSP) or similar certification in information security preferred.
Education and Experience
- A bachelors degree in cybersecurity or a similar discipline and ten years of related experience in security management frameworks (e.g., National Institute of Standards and Technology [NIST], SysAdmin, Audit, and Network and Security [SANS]).
- An equivalent combination of advanced education, training, and experience will be considered.
The target base salary for this position is $129,085.00 to $167,062.00 per year. When determining compensation, we analyze and carefully consider several factors, including skill set, experience, location, and job-related qualifications.
Learn more about NYSTEC by visiting www.nystec.com.