Under the direction of a Security Program Manager within the Chief Information Security Office (CISO)/Cyber Governance & Compliance/Access Review, the position will lead the Access Review section, which provides access review services to Enterprise ITS, ITS supported agencies, and other non-ITS supported Agencies. These services ensure that least privilege access is maintained across 50+ technologies through a collection and survey process in which managers validate the access required by their staff. The incumbent will supervise subordinate staff, leading two teams focused on operations and development of access review processes. The incumbent will act as a team member providing in-depth information security and technical expertise aligned with business needs of ITS and its client agencies to ensure Agency compliance with regulatory requirements and standards.
The position requires an incumbent to act with a great deal of independence in alignment with CISO and upper-level CISO management strategic direction. The position requires technical understanding in a broad range of areas to permit working directly with technical teams throughout ITS. Areas such as shared tool development, data normalization, active directory structure, and query language creation are just some of the expertise contained within the team. The position requires communicating orally and in writing with various individuals including management, users, and other IT staff. The incumbent will have to work with ITS teams and upper-level agency management to resolve compliance with the review standards to ensure completeness. The incumbent will also be required to demonstrate effective leadership skills and a strong understanding of project management.
The incumbent will be responsible for managing two Access Review units: Operations and Development. Operations oversees the delivery of access review services to ITS and our client agencies. The Development unit coordinates the technologies behind the reviews as well as the expansion of technologies and agencies able to be reviewed. The incumbent will be required to successfully manage technical and non-technical staff, work collaboratively with diverse groups, and establish ongoing relationships both internally and externally.
The position will be part of the CISO Incident Response program and may require availability during off-shift hours to ensure appropriate response to security incidents or other critical activities that may impact sensitive information, critical systems, NYS agencies, or ITS. Additional information on work schedule will be discussed at time of interview.
Specific duties include, but are not limited to:
Minimum Qualifications:
Additional Comments:
ITS will not offer permanent employment to any candidate unless the candidate provides documentation that they are authorized to accept work in the United States on a permanent basis. It is the policy of ITS not to hire F1 or H1 visa holders for permanent employment or to sponsor non-immigrant aliens for temporary work authorization visas or for permanent residence.
Some positions may require fingerprinting.
Some positions may require up to 25% travel and/or lifting up to 50 lbs. Some positions are pending Civil Service approval. Details of position(s) will be described further if you are selected for an interview.
If eligible, positions located in New York City will receive an additional $3,400 downstate adjustment location pay with regular annual salary. Positions located in the Mid-Hudson will receive an additional $1,650 adjustment location pay.
Benefits of Working for NYS Generous benefits package, worth 65% of salary, including: Holiday & Paid Time Off, Health Care Benefits, Additional Benefits. The Office of Information Technology Services is an equal opportunity employer, and we recognize that diversity in our workforce is critical to fulfilling our mission. We encourage all individuals with disabilities to apply.