Chief Information Security Officer
DASNYAbout the role
Position Title: Chief Information Security Officer
Grade/Classification: 60 - Chief or Equivalent
Hiring Rate: $136,702 - Albany, NY Office
$141,756 (Includes location differential of $5,054) - NYC Office
Location: Albany, NY Office or NYC Office
FLSA Status: Exempt
Last Revised: July 2, 2024
Primary Purpose
The Chief Information Security Officer (ISO) is responsible for protecting and maintaining the confidentiality, integrity and availability of information and related infrastructure assets; managing the risk of security exposure or compromise; assuring a secure and stable information technology (IT) environment; identifying and responding to events involving information asset misuse, loss or unauthorized disclosure; monitoring systems for anomalies that might indicate compromise; increasing the awareness of information security within DASNY. The Chief, ISO has a senior advisory role in decisions affecting information security and assurance, and is responsible for the development, implementation, enhancement, monitoring and enforcement of DASNY and New York State information security policies and standards across the organization.
Essential Functions
Operations
- Conduct regular penetration testing and keep records of all test data and schedule of future testing.
- Maintain security of all electronic data, documents and records and regularly test vulnerabilities.
- Work with IS to plan, install, and maintain required security architecture, software, hardware, firmware, and appliances.
- Provide advice on security issues related to procurement of products and services.
- Review and approve all external network connections to DASNY’s network.
- Escalate security concerns to executive management, as necessary.
- Maintain records and controls for all IT security related matters including but not limited to pro-active investigations, risks, threats, actual security events, technology related assets, system life cycles, penetration testing, data vulnerability testing, and provides up to date time schedules of all reviews and follow-ups.
- Maintain records on system access to the DASNY technology environment with regard to access levels on all technology including but not limited to applications, equipment, and records.
- Maintain records on all DASNY technology assets and equipment including but not limited to: computer hardware and devices, computer monitors and peripherals, mobile phones/equipment/devices, construction technology devices and equipment, infrastructure hardware and devices, applications and software, cloud data storage, off-site physical data storage.
- Recommend, develop, enhance, monitor and update policies, standards, procedures, control processes, and education and awareness programs relating to IT security and risk management to verify appropriate safeguards are implemented; ensure appropriate information security awareness and educate all DASNY employees, and third-party individuals as required.
- Facilitate and ensure compliance with IT security policies, standards and processes, and federal and State laws and regulations affecting security controls and classification requirements of DASNY’s information.
- Ensure DASNY policies/practices align with the NYS Information Security Policy Standards established and issued by the Office of Information Technology Services.
- Coordinate with IS staff to ensure security measures are implemented in accordance with policy requirements.
- Participate in new hire on-boarding providing appropriate system credentials and training new hires on DASNY’s “need to know” information regarding its’ IT network, applications and security.
- Act as liaison between DASNY and external auditors.
- Coordinate DASNY’s technical efforts in response to information and system security compliance reviews or audits performed by external regulatory organizations or auditors.
- Develop or review contracts, service level agreements, memorandum of understanding language and other documents to verify that they meet information security needs and requirements and align with agency and State information security policies.
- Maintain guidelines for the development of secure application code using industry best practices.
Strategic
- Maintain current industry knowledge and build relationships with IT security related organizations on industry and government standards, information security market movement, and cu
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s