Director, Information Security
- Full-time
- Agency: DEPARTMENT OF BUILDINGS
- Job Category: Technology, Data & Innovation
- Salary Band: $150,000+
- Compensation: USD 75443 - USD 164451
Job Description
At the NYC Department of Buildings, we are responsible for ensuring the safe and lawful use of buildings and properties by enforcing the NYC Construction Codes, Energy Code and Zoning Resolution. We facilitate compliant development with integrity, efficiency, and professionalism. As an Agency, we are committed to remaining a premier municipal building organization, dedicated to enhancing the quality of life for all New Yorkers and making our city safer. As an employer, we are committed to improving our performance and developing procedures that are streamlined, understandable, and transparent. We are seeking a dynamic leader to serve as the Director, Information Security.
Director, Information Security will provide strategic and operational leadership for enterprise architecture, cloud platforms, and cybersecurity operations. Reporting to the Executive Director, Information Security, this role ensuring reliability, scalability, and security of mission-critical systems supporting DOB’s mission to serve New York City. Director, Information Security will work with all areas of DOB’s businesses to further enhance and architect a shared vision for “best in class" information security, enterprise architecture and compliance program that will assess appropriate technology platform risks and protect value in DOB’s core business.
Director, Information Security is a hands-on technical leadership role responsible for maintaining a robust security posture and reliable infrastructure operations across DOB’s technology platform. This role owns the security and operations of DOB’s entire enterprise architecture including, network routers and switches, server infrastructure, cloud solutions, on prem and public facing firewalls, endpoint vulnerability including modernization initiatives.
The Director, Information Security is responsible for strengthening and executing information security posture, strategy, policy, enforcement, risk mitigation and cybersecurity awareness. Responsibilities will also encompass security and Risk Management Framework (RMF) focused architecture and engineering of the enterprise, while defining security standards, developing and implementing security controls.
The successful candidate must possess skills to actively engage with internal agency technology teams and maintain strong working relationships with external technology partners such as OTI and NYC Cyber Command while streaming technology stack as well as a strong ability to effectively manage direct reports, resource allocation and prioritization, budgets, and key performance indicators. This position requires a seasoned leader with strong business acumen and detailed working knowledge of information security technologies, practices, policies, and their application to a business and act calmly and competently in high-pressure, high-stress situations.
Duties and Responsibilities include, but are not limited to, the following:
- Oversee and implement a sustainable, strategic and long-term information and cybersecurity roadmap that deliver world-class cyber protection for the agency.
- Strengthen DOB’s corporate security program in the areas of Vulnerability Management, Incident Management, Threat Management, and Security Awareness.
- Enhance existing Threat Management and Incident Management functions, including analysis, triage and escalation of security events, coordination and tracking of response activities.
- Manage IT infrastructure implementation and operations, including networks, servers, desktops, telecommunications, voice, security infrastructure
-Provide leadership and vision for the strategic development and management of computing information systems, network communications, telecommunications, voice services, applications, information security systems, and technology infrastructure that will support DOB staff and facilities.
- Manage an IT Incident Response Team, security incidents and events to protect agency assets, including intellectual property, regulated data.
- Manage all phases of Vulnerability Management including scanning, reporting, and remediation tracking.
- Oversee vulnerability remediation activities, coordinate with other stakeholders to plan and track remediation activities.
- Maintain standard operating procedures (SOP) and documentation of IT processes as needed to support business operations, architecture, security, disaster recovery, standards, and purchasing while establishing and enforcing IT policies, processes, portfolio management, standards, and methodologies.
- Authorize and oversee the deployment, monitoring, maintenance, development, and support of all hardware and software based on department data centers, telecommunications, and user end-point needs.
- Identify potential and emerging information security threats, vulnerabilities, and control techniques.
- Support agency leadership to review enterprise IT and cyber risks, assess capabilities, prioritize security and risk strategies and communicate risk intelligence in a way that drives business decision-making.
- Engage and coordinate cross-functional stakeholder participation in risk profiling, investigation, escalation and resolution.
- Provide leadership to individual contributors, build risk capabilities and build program oversight.
- Assess risk tolerance, implement and oversee appropriate security processes and foster a security-aware culture for the agency.
- Develop and manage information security and infrastructure budgets and monitor them for variances.
- Continuously identify and spearhead opportunities to improve the efficiency and effectiveness of the Information Security operations and processes.
- Coordination of maintenance and patching of Information Security Systems.
- Oversee security awareness activities including security awareness training and proactive phishing exercises.
- Participate in projects to evaluate, develop and implement technologies to support security operations.
- Maintain and publish metrics.
- Monitor/Review external threat environment, DAST and penetration scans and advise relevant stakeholders on the appropriate courses of action and liaise with external agencies, such as NYC Cyber Command, OTI and other advisory bodies as necessary, to ensure that the agency maintains a strong security posture.
- Provide subject matter expertise to executive management with a broad range of security standards and best practices.
- Assess applications through threat modeling, code review and security testing while providing guidance on effective countermeasures.
- Contribute to security architecture and assist in building and rolling out processes for secure code development and deployment.
- Propose solutions for secure application design, DevSecOps automation, tool optimization, application vulnerability management and strategies for risk reduction.
- Plan, review and approve change management processes for network and security modifications, including documenting changes, validating implementation steps, and supporting rollback planning
- Enhance the protection of agency critical applications through collaboration with constituents, analysts, and application developers to address security risks throughout the Software Development Life Cycle (SDLC).
- Review roadmaps, designs, and specifications with applications teams to assist craft application security features and improvements.
CIVIL SERVICE STATUS:
Only those who are permanent in the Computer Systems Manager civil service title, applicants who are reachable on the Computer Systems Manager open competitive list, and applicants as indicated below will be considered.
Candidates who are permanent in comparable civil service titles may be considered for title change under rule 6.1.9 of the Personnel Rules and Regulations of the City of New York.
REMOTE WORK
This position may be eligible for remote work up to 2 days per week, pursuant to the Remote Work Pilot Program.
To Apply:
Visit Jobs NYC (cityjobs.nyc.gov) to view and apply for available positions. Search by agency (Department of Buildings), keywords, or for the specific Job ID #.
NOTE: ONLY THOSE CANDIDATES UNDER CONSIDERATION WILL BE CONTACTED.
COMPUTER SYSTEMS MANAGER - 10050
Qualifications
1. A master's degree in computer science from an accredited college or university and three (3) years of progressively more responsible, full-time, satisfactory experience in Information Technology (IT) including applications development, systems development, data communications and networking, database administration, data processing, or user services. At least eighteen (18) months of this experience must have been in an administrative, managerial or executive capacity in the areas of applications development, systems development, data communications and networking, database administration, data processing or in the supervision of staff performing these duties; or
2. A baccalaureate degree from an accredited college or university and four (4) years of progressively more responsible, full-time, satisfactory experience as described in "1" above; or
3. A four-year high school diploma or its educational equivalent, and six (6) years of progressively more responsible, full-time, satisfactory experience as described in "1" above; or
4. A satisfactory combination of education and experience equivalent to "1", "2" or "3" above. However, all candidates must have at least a four-year high school diploma or its educational equivalent and must possess at least three (3) years of experience as described in "1" above, including the eighteen (18) months of administrative, managerial, executive or supervisory experience as described in "1" above.
In the absence of a baccalaureate degree, undergraduate credits may be substituted for a maximum of two (2) years of the required experience in IT on the basis of 30 semester credits for six (6) months of the required experience. Graduate credits in computer science may be substituted for a maximum of one (1) year of the required experience in IT on the basis of 30 graduate semester credits in computer science for one (1) year of the required IT experience. However, undergraduate and/or graduate credits may not be substituted for the eighteen (18) months of experience in an administrative, managerial, executive, or supervisory capacity as described in "1" above.
Additional Information
The City of New York is an inclusive equal opportunity employer committed to recruiting and retaining a diverse workforce and providing a work environment that is free from discrimination and harassment based upon any legally protected status or protected characteristic, including but not limited to an individual's sex, race, color, ethnicity, national origin, age, religion, disability, sexual orientation, veteran status, gender identity, or pregnancy.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply