Information Security Manager
$3,400 per monthNYS Office Information Technology Services
Duties Description
ITS provides operational support to state agencies on a 24x7x365 basis; some positions may be required to provide this critical service at any time.
Job Overview
Under the direction of the Executive Director of Security Shared Services (S3) within the Chief Information Security Office/Security Shared Services section, this position will assist with the oversight of the Security Shared Services Bureau. The position will supervise four or more Senior Information Security Officers SG-29 who lead teams supporting the security needs of multiple ITS dedicated agency/sector teams. The position will oversee the Incident Response Program and aid in the oversight of the NYS Cyber Risk Remediation Program (CRRP) and the development of products offered by the Chief Information Security Office (CISO). The incumbent will act as a member of the Chief Information Security Office Executive Leadership Team and participate in shaping and implementing the strategic vision for cybersecurity within NYS.
The position requires an incumbent to act with a great deal of independence in alignment with agency and upper-level management strategic direction. The incumbent must be able to communicate orally and in writing with various individuals and groups including executive management, business users and other IT staff. The incumbent must communicate with clarity to subordinate staff regarding work priorities and performance. The incumbent will work with ITS Dedicated Support Teams and upper-level agency management to resolve technically complex and politically sensitive issues under pressure. The incumbent will have strong customer service skills and focus on developing relationships with key stakeholders. Availability during off‑shift hours is required to ensure appropriate response to security incidents or other critical matters that may impact sensitive information, critical systems, ITS, NYS agencies, or other partners (such as local governments).
Duties Include, But Are Not Limited To
- Assist with the direction of the Security Shared Services Bureau in developing, deploying, and maintaining processes and procedures in alignment with NYS State and agency information security policies and standards. Monitor compliance and take appropriate action as needed.
- Oversee the continued development of the ITS Cyber Incident Response Program, which includes continuously improving procedures and ensuring 24x7x365 rotating coverage schedules for IR responders.
- Enhance the Secure Software Development Lifecycle (SSDLC) process in response to shifting cyber landscape and the requirements of ITS, agencies, and NYS.
- Foster and develop relationships with key stakeholders, such as the Dedicated Commissioners of Technology (DCTs).
- Provide off‑hours leadership in response to cyber threats, incidents, and events on a rotating basis.
- Serve as information security expert and evaluate systems and contracts for alignment with agency and state information security policies.
- Provide advisement and expertise in the development of NYS security policies and standards.
- Assist with development and implementation of the Security Shared Services Bureau’s program and associated products.
- Perform administrative and strategic functions to assist the CISO Executive Leadership team in managing the operations of the Chief Information Security Office.
- Monitor and maintain awareness of information security industry trends, tools, and techniques.
- Perform the full range of supervisory responsibilities.
Qualifications
Minimum Qualifications
- Non‑competitive: Nine (9) years of information technology, cybersecurity, or information assurance experience, including three (3) years at the supervisory level or one (1) year at the managerial level.
- A bachelor's or higher‑level degree in any field, supplemented by 15 semester credit hours in computer science or related field, substitutes for three years of required experience; any bachelor’s substitutes for two years of required experience.
- Associate degree with 15 semester credit hours in computer science or related field may substitute for one year of required experience. Candidates in a bachelor’s degree program with at least 15 semester credit hours in computer science or related field may substitute such credits for one year of required experience.
- A master’s degree or higher in computer science or related field substitutes for one year of required experience.
Preferred Qualifications
- Applicable Information Security certificate(s) such as CISSP, CISM, etc.
- Experience in one or more of the following areas: leading information security teams, applying and implementing network, system, or application security, security policy/standard/guideline development, implementation, or interpretation, conducting risk assessments and evaluating information technology systems for security controls (SSDLC), process development, improvement, and measurement, information security incident response, developing metrics and key performance indicators.
- Strong understanding of enterprise IT environments, including but not limited to system administration, application architecture, network architecture, operating systems, and associated security controls and solutions (e.g., WAF, firewalls).
- Strong understanding of the foundations of Information Security, such as the CIA triad, information classification, identity and access management, risk management, vulnerability management, secure architecture and engineering, network security, software development security.
- Excellent oral and written communication skills including the ability to clearly articulate information technology and information security concepts to a varied audience to facilitate wide understanding.
- Demonstrated critical thinking, problem solving, and analytical skills.
- Demonstrated excellence in customer service.
- Demonstrated skill in facilitating meetings, listening, and negotiating between multiple stakeholders to drive results.
Additional Comments
ITS will not offer permanent employment to any candidate unless the candidate provides documentation that they are authorized to accept work in the United States on a permanent basis. It is the policy of ITS not to hire F1 or H1 visa holders for permanent employment or to sponsor non‑immigrant aliens for temporary work authorization visas or for permanent residence.
Some positions may require fingerprinting.
Some positions may require up to 25% travel and/or lifting up to 50 lbs. Some positions are pending Civil Service approval. Details of position(s) will be described further if you are selected for an interview.
If eligible, positions located in New York City will receive an additional $3,400 downstate adjustment location pay with regular annual salary. Positions located in the Mid‑Hudson will receive an additional $1,650 adjustment location pay.
Benefits of Working for NYS
Generous benefits package worth 65% of salary, including:
Holiday & Paid Time Off
- Thirteen (13) paid holidays annually
- Up to Thirteen (13) days of paid vacation leave annually
- Up to Five (5) days of paid personal leave annually
- Up to Thirteen (13) days of paid sick leave annually for PEF.
- Up to three (3) days of professional leave annually to participate in professional development.
Health Care Benefits
- Eligible employees and dependents can pick from a variety of affordable health insurance programs.
- Family dental and vision benefits at no additional cost.
Additional Benefits
- New York State Employees’ Retirement System (ERS) Membership.
- NYS Deferred Compensation.
- Access to NY 529 and NY ABLE College Savings Programs, as well as U.S. Savings Bonds.
- Public Service Loan Forgiveness (PSLF).
- And many more.
The Office of Information Technology Services is an equal opportunity employer, and we recognize that diversity in our workforce is critical to fulfilling our mission. We encourage all individuals with disabilities to apply.
#J-18808-Ljbffr$115k - $135k
...Position Overview The Privacy Manager is a member of the FUJIFILM Holdings America Corporation... ...current data mapping and inventory information, collaborating with Data Governance... ...requirements. Collaborate with information security team to ensure that security and privacy...SuggestedRemote workFlexible hours$145k - $205k
Edwards Lifesciences Belgium is seeking a leader for offensive cyber operations in Albany, NY. This role is pivotal in delivering unique threat insights essential for protecting the company’s innovative medical solutions. You'll oversee activities like penetration tests...Suggested- ...The Hispanic Alliance for Career Enhancement is seeking a Cyber Resiliency Manager to define and execute strategic directions within CVS Health's Cybersecurity team. This role focuses on managing procedures and improving internal controls, ensuring compliance with NIST...Suggested
- ...Administrative Services is seeking a highly skilled and proactive Information Security professional to join our team. In this role, you'll be... ...our information assets and technologies. You'll develop and manage security policies, assess organizational risks, guide third-...SuggestedFull timeFlexible hours
- ...Information Systems Security Officer (ISSO) Employment Type: Full-Time, Experienced Department: Information Technology CGS is seeking... ...includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the...SuggestedFull timeLocal areaRemote workFlexible hours
$87.7k - $164k
...Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider... ...and assessment on perceived security threats Maintain, manage, improve and update security incident process and protocol documentation...Summer holidayLocal areaFlexible hours$87.7k - $164k
...looking for a Cyber Triage and Forensics Incident Analyst to join their team in Albany, NY. This senior role involves responding to security incidents, conducting digital forensic analysis, and supporting remediation efforts. Candidates must have a Bachelor's or Master's...Flexible hours- ...Title: Elastic Security Engineer - SIEM Migration Location: Albany, NY Job Type: Contract to Hire Job Responsibilities: Lead and support a time-sensitive migration from Splunk to Elastic Security / SIEM Analyze existing Splunk use cases,...Full timeContract work
- ...is looking for an OT Firewall Engineer to design and maintain secure network perimeters for wind, solar, and battery storage facilities... .... Responsibilities include implementing security controls, managing Cisco and Check Point platforms, and responding to security events...Full timeRemote work
$144.9k - $265.8k
...Entra, Okta, Ping, Saviynt Design cloud security and IAM architectures for Azure, AWS,... ...authentication, authorization, identity management) Design and re‑engineer processes for centralized... .../expression, pregnancy, genetic information, national origin, protected veteran...Work experience placementSummer holidayFlexible hours$144.9k - $265.8k
...Entra, Okta, Ping, Saviynt Design cloud security and IAM architectures for Azure, AWS,... ..., authorization, identity management) Design and re-engineer processes for... ...California, please click here for additional information. EY focuses on high-ethical standards...Work experience placementSummer holidayFlexible hours$70k - $90k
...to play a key role in maintaining and strengthening NYeC’s information security and compliance posture within a healthcare data exchange environment... .... A minimum of 5 years in information security or risk management, with a focus on security operations highly preferred....Full timeWork at office1 day per week$109.64k - $145.27k
...mindset. About the Role As a principal consultant – security consultant in the Cybersecurity and Data Privacy Practice... ..., and communicating status upward and to client project managers. Share information proactively to make colleagues and clients more successful...Local areaVisa sponsorship$80k - $105k
...skilled Cybersecurity Analyst to join our security operations team. The ideal candidate... ...Endpoint Detection and Response (EDR), Managed Detection and Response (MDR), Managed Risk... ...s. Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related...Full timeTemporary workRemote workVisa sponsorship- Latham, The Pool Company, based in New York, is seeking a Cybersecurity Analyst to join their security operations team. This full-time hybrid role requires hands-on experience with EDR/MDR systems, incident response, and Zero Trust frameworks. Responsibilities include...Remote jobFull time
$80k - $105k
Latham Pool Products, Inc in New York is seeking a highly skilled Cybersecurity Analyst to strengthen our security operations team. The ideal candidate will engage in monitoring and analyzing security alerts, conducting incident investigations, and implementing Zero Trust...Remote jobFull time$60.41k - $75.51k
...Role: As an associate consultant - security and privacy advisor, you will... ...activities in support of significant health information technology (HIT) programs. Performing... ...response, disaster recovery, vulnerability management, and software development life cycle (...For contractorsLocal areaVisa sponsorship- ...network operations and performance. Key responsibilities include configuring network systems, ensuring ongoing upgrades and monitoring security. Ideal candidates should have 6-8 years of experience and a relevant degree, with a strong understanding of network technologies....
$60 - $80 per hour
A rapidly growing consulting firm in Albany, NY, is hiring a Risk Manager to oversee operational and cybersecurity risk assessments. The ideal candidate should have a Bachelor's in Risk Management, 5+ years of relevant experience, and FEMA ICS certifications. This full-...Hourly payFull timeContract work$152.7k - $294k
...Development: Define and drive the development of long-term information security program strategies that support the firm’s business objectives... ...Leadership: Exceptional program leadership and stakeholder management skills. Proven ability to lead cross‑functional initiatives...Summer holidayFlexible hoursShift work$120k - $230k
...Solutions Engineer is a customer-facing security professional who provides consultative technical... ...communicate complex ideas and information to diverse audiences and can facilitate... ...between others. Detail-Oriented: Can manage complex tasks or projects, identifying errors...Work at officeRemote workWorldwideFlexible hours- ...seeks an experienced Network Engineer to enhance and maintain a large scale wired and wireless network. Responsibilities include managing infrastructure, optimizing performance, and providing technical guidance. Candidates should have a Bachelor's in a relevant field,...
$115k - $130k
...CHA Consulting, Inc. is seeking a Security Electronics Engineer IV to join our MEP Team in Albany, NY; Syracuse, NY; or Rochester, NY. This role involves the planning, design, and implementation of physical security systems for critical infrastructure. The ideal candidate...$94.15k - $150k
...Suitability/Public Trust Fully remote Information Technology Overview GovCIO is... ...operate next-generation firewall and web security proxy solutions, ensuring secure, high-availability... ...conducted via video with the hiring manager and/or team Camera must be on A...Full timeCurrently hiringRemote workFlexible hours- ...of our department. In this role, you are at the heart of our operations, responsible for maintaining organized files, compiling information, and ensuring its shared seamlessly. While the core of your work revolves around essential clerical tasks, you also have the chance...Full timeShift workNight shiftWeekend workAfternoon shift
$17.72 per hour
...direct supervision of the on-duty Shift Supervisor, or general supervision of facility command staff. Responsible for maintaining a secure detention facility and the safe custody of detainees. To join our team of outstanding professionals, apply today! Hourly rate is...Hourly payContract workShift work$40.33k - $91.77k
...Explore Career Opportunities as a Transportation Security Officer (TSO) with TSA TSA is hiring Transportation Security Officers across the United States. TSOs are the face of the agency, the people on the front lines who play an important role at TSA. TSOs are responsible...Full timePart timeRemote workRelocationShift workNight shift$17.72 per hour
...supervision of facility command staff. Responsible for maintaining a secure detention facility and the safe custody of detainees. To join... ...(AIP), an Akima company, is not just another federal management operations contractor. As an Alaska Native Corporation (ANC), our...Hourly payContract workFor contractorsRemote workShift work$71.2k - $158.2k
...Job Description The Senior Federal Information Systems Security Engineer (ISSE) serves as a technical integrator responsible for ensuring that... ...stakeholders to gather system connectivity details, generate and manage Ports, Protocols, and Services Management (PPSM)...Contract workTemporary workWork experience placementRelocationFlexible hours- ...construction of COLUMBIA Class submarines, financial and budget management, shipyard support of submarines, vendor support of submarines... ...recommendations, analyzing technical/programmatic information to ensure smooth operation of the department, field location,...Full timeContract workPart timeLocal areaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Manager. Be the first to apply!
- information security lead Albany, NY
- entry level information security analyst Albany, NY
- information security Albany, NY
- sr information security engineer Albany, NY
- senior information security analyst Albany, NY
- information technology security engineer Albany, NY
- information security compliance analyst Albany, NY
- data center security officer Albany, NY
- director information security Albany, NY
- information security analyst Albany, NY


