Posting DetailsPosition Information
Faculty/Professional Professional
Department Information Technology Exchange Center
Local Title External Security Services Information Security Officer
Budget Title Supervising Programmer/Analyst
Rank SL-5
Line Number 21116, 21176, 21180, 21203, 21216
Salary Range $77,346 -$143,611 Competitive based on experience.
FTE Full-Time
Bargaining Unit UUP
PRODiG+ Position No
Executive Position No
FLSA Exempt
Department Website https://www.itec.suny.edu
Brief Job Description ITEC's External Security Services Information Security Officer (ESISO) provides strategic cybersecurity leadership and advisory services to higher education institutions. The role focuses on assessing and implementing security strategies, policies, and frameworks aligned with the unique needs of universities and colleges, while helping manage cyber risk, regulatory compliance, and protection of academic, research, and administrative data. The ESISO serves as a trusted security advisor and advocate to campus and ITEC senior management, clearly communicating risks, priorities, and recommendations in business-relevant terms. The position requires a strong understanding of information security programs within complex U.S. organizations, including higher education, SUNY, and New York State government environments. With team leadership and security program management as core responsibilities, the role also carries a strong project management focus, coordinating deliverables with the Security Services Service Delivery Manager. The ESISO helps define, oversee, and contribute to approved campus security projects. The role also supports campuses during security incidents and advises on security-focused software, system requirements, compliance (e.g., GLBA, PCI, FERPA, HIPAA) and appropriate hardware and software configurations.
Please see
https://www.itec.suny.edu/itec-vacancies for more information.
The location for this position is in Buffalo, NY. An office location at a New York State or SUNY Institution may be possible.
Multiple selections may be made from this posting.
Required Qualifications - A bachelor's degree in a security, computing, programming, networking or related field, and progressive relevant professional work experience..
- Good presentation skills, interpersonal skills, written and communication skills.
- Demonstrated familiarity with compliance requirements (e.g., PCI, GLBA, FERPA) and NIST Cybersecurity Framework (CSF) or equivalents.
- Demonstrated familiarity with creating and implementing security policies, risk assessments and tabletop exercises.
- Demonstrated familiarity with Incident Response (IR) and creating IR Plans.
Preferred Qualifications - Master's degree in information security or assurance, such as MSIA, or Certifications related to Security Operations/Architecture/Engineering: ISC2: CISM, CISSP or SSCP.(CISSP-ISSAP or ISSEPa plus); relevant SANS GIAC series; or others, like PNPT, OSCP, CEH, CISA, or CySA+.
- Familiarity with Security Tools such as Zeek, Snort, Suricata, Nmap, Metasploit, Wireshark, OpenVAS, Autopsy, etc.
- Working or managerial experience in a large organization, especially higher education.
- Recent operational or administrative experience with EDR, SIEM, IDS/IPS Systems or Zero Trust Networks.
- Experience responding to or advising the response to a security breach, such as notification, chain of custody, guiding forensics, or compliance reporting.
- Experience in System Administration for Windows servers, vCenter/ESXi, Linux, Hypervisors, Networking Infrastructure a plus.
- Cloud provider experience and/or certifications with any of Azure, AWS, Google Cloud.
- Membership in REN-ISAC, MS-ISAC, or other industry ISAC.
Anticipated Date of Hire 12/01/2026
Priority Review DateApplication Deadline Date 09/20/2026
Open Until Filled No
Special Instructions to ApplicantContact PersonContact EmailContact FaxQuick Link for Direct Access to Posting https://jobs.buffalostate.edu/postings/8223