Jump to main content.

The Official Careers Website of the City of New York

Search

DIRECTOR INCIDENT MANAGEMENT

  1. HRA/DEPT OF SOCIAL SERVICES
Posted on: 08/21/2023
  1. Full-time

Location

MANHATTAN

  1. Exam may be required

Department

DSS ACCOUNTABILITY OFFICE NM

$58,700.00 – $130,000.00

Job Description

This vacancy has now expired.

The Office of Data Security Management is responsible for the implementation and management of the Agency’s cyber security program. ODSM works closely with NYC Cyber Command and is tasked with continuously improving the Agency’s risk posture by ensuring appropriate security controls are in place to protect the confidentiality, integrity and availability of Agency information resources. The COVID-19 pandemic has accelerated the need to enhance DSS-HRA-DHS cyber security priorities as remote access and teleworking capabilities expanded exponentially.

The Office of Data Security Management is recruiting for (1) Computer Systems Manager NM-II to function as the Incident Management Director (IM) who will:

- Oversee the daily operations of the Emergency Operations & Incident Management unit. Plan and direct the activities of staff, verify, and approve work products, set annual goals, mentor, and identify training opportunities, and develop strong working relationships with relevant partners outside of ODSM in order to effectively advance the objectives of the unit.

- Develop BIA plan (Business Impact Analysis) for assessing Agency business processes, determining which areas are vulnerable, and the potential losses if those processes go down for a day, a few days, or a week.

- Develop a Disaster Recovery plan that focuses mainly on restoring Agency IT infrastructure and operations after a crisis in accordance with the New York City Cyber Command (NYC3) policies, governing laws and regulations, and industry best practices. Oversee the process to review and adjudicate requests for exceptions to policy.

- Assess problem management, root cause analysis, and postmortem reviews following incident occurrence. Conclude comprehensive data assessment, resolve incidences and determine prevention of future incidents.

- Conduct forensic investigations and collaborate with law enforcement and other regulatory bodies during and following an incident.

- Maintain abreast of trends and threats in the cybersecurity space; liaise with internal and external partners to continuously examine and revise policies as appropriate; perform ad-hoc projects as assigned by the Deputy CISO


Minimum Qualifications

1. A master's degree in computer science from an accredited college or university and three (3) years of progressively more responsible, full-time, satisfactory experience in Information Technology (IT) including applications development, systems development, data communications and networking, database administration, data processing, or user services. At least eighteen (18) months of this experience must have been in an administrative, managerial or executive capacity in the areas of applications development, systems development, data communications and networking, database administration, data processing or in the supervision of staff performing these duties; or

2. A baccalaureate degree from an accredited college or university and four (4) years of progressively more responsible, full-time, satisfactory experience as described in "1" above; or

3. A four-year high school diploma or its educational equivalent, and six (6) years of progressively more responsible, full-time, satisfactory experience as described in "1" above; or

4. A satisfactory combination of education and experience equivalent to "1", "2" or "3" above. However, all candidates must have at least a four-year high school diploma or its educational equivalent and must possess at least three (3) years of experience as described in "1" above, including the eighteen (18) months of administrative, managerial, executive or supervisory experience as described in "1" above.

In the absence of a baccalaureate degree, undergraduate credits may be substituted for a maximum of two (2) years of the required experience in IT on the basis of 30 semester credits for six (6) months of the required experience. Graduate credits in computer science may be substituted for a maximum of one (1) year of the required experience in IT on the basis of 30 graduate semester credits in computer science for one (1) year of the required IT experience. However, undergraduate and/or graduate credits may not be substituted for the eighteen (18) months of experience in an administrative, managerial, executive, or supervisory capacity as described in "1" above.


Preferred Skills

- Typically, 3+ years of relevant experience. - Deep understanding of Cloud-native authentication mechanisms. - Provides expert knowledge Identity Lifecycle Management. - Provides expert knowledge AWS services. - In-depth knowledge of scripting languages PowerShell, bash, python. - In-depth knowledge of SIEM technology tool Splunk. - knowledge of DNS and DHCP networking protocols. - In-depth knowledge of Windows server operating systems. - Stays abreast of industry trends and technologies. - Maintains root cause analysis skills for investigation of incidents impacting technology availability. - Reviews capacity utilization for trends and raises awareness across teams to address areas of excess and shortages. - Administers processes and procedures related to code management. - Engages various teams to evaluate and implement performance tuning recommendations. - Experience in project management and change control processes. - Strong written and oral communication skills. - In-depth knowledge of networking, complex network architecture, and information security technologies and methods. - Strong understanding of the cyber threat landscape, attack vectors, and risk mitigation as well as remediation methods. - Strong familiarity with information security management frameworks such as NIST, ISO or other widely recognized and adopted data security standards. - Knowledge of data privacy regulations and compliance requirements. - CISSP, CISA, CISM, CCFP, CEH, or other cybersecurity certifications. - Excellent written and verbal communication skills.
Residency Requirement

New York City Residency is not required for this position
Additional Information

The City of New York is an inclusive equal opportunity employer committed to recruiting and retaining a diverse workforce and providing a work environment that is free from discrimination and harassment based upon any legally protected status or protected characteristic, including but not limited to an individual's sex, race, color, ethnicity, national origin, age, religion, disability, sexual orientation, veteran status, gender identity, or pregnancy.

Job ID

490587

Title code

1005D

Civil service title

COMPUTER SYSTEMS MANAGER

Title classification

Competitive-1

Business title

DIRECTOR INCIDENT MANAGEMENT

  1. Experienced (non-manager)

Job level

00

Number of positions

1

Work location

155 West Broadway New York N Y

  1. Administration & Human Resources

DIRECTOR INCIDENT MANAGEMENT

Search