Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Deputy Chief Information Security Officer (CISO) image - Rise Careers
Job details

Deputy Chief Information Security Officer (CISO)

Job Description

The Office of Technology and Innovation (OTI) leverages technology to drive opportunity, improve public safety, and help government run better across New York City. From delivering affordable broadband to protecting against cybersecurity threats and building digital government services, OTI is at the forefront of how the City delivers for New Yorkers in the 21st century. Watch our welcome video to see our work in action, follow us on social media @NYCOfficeofTech, and visit oti.nyc.gov to learn more.

At OTI, we offer great benefits, and the chance to work on projects that have a meaningful impact on millions of people. You'll have the opportunity to work with cutting-edge technology and collaborate with other passionate professionals who share your drive and commitment to making a difference through technology.

NYC Cyber Command is seeking a Deputy Chief Information Security Officer (CISO) who will lead in the implementation and management of information security controls that will increase the Agency s overall information security posture.

Under the direction of the CISO, the successful candidate will be responsible for the integration of information security controls and overall information security awareness across departments and units. The Deputy CISO directs the overall planning and execution of enterprise security systems, using operational and tactical expertise to direct security management reports, who oversee analysts, engineers and architects.

The Deputy CISO will be responsible for the compliance of IT systems, applications and networks with security policies and information protection strategies; develop, publish, and maintain Agency information security policies, standards, procedures, and guidelines; provide technical guidance and training to information "owners," agency IT teams, and design and implement programs for user awareness, and security compliance monitoring. The candidate will analyze potential security risks or breaches that have occurred and implement widely accepted and automated technologies to mitigate these risks/breaches and harden security systems for effective defense.

The Deputy CISO must have a strong technical background and fully understand threats, risk mitigation and technical controls to lead a team of security professionals through organizational objectives and defenses. The Deputy CISO assumes accountability for the daily tactical operations and overall strategic execution of the team under their leadership.

Responsibilities will include but are not limited to:
- Lead the design and development of protective and detective cybersecurity controls, configurations, and architectures with a strong focus on zero trust methodologies, cloud architectures,
IT/OT environments, and big data analytics;
- Implement robust, enterprise level security services across multiple city agencies in both OT and IT environments, such as identity and access management (IAM), email security, endpoint
detection and response (EDR), data loss prevention (DLP), etc;
- Oversee a team to perform security reviews, identify gaps in security architecture, and develop current and future state security architectures;
- Lead the telemetry onboarding program to ensure highly resilient and scalable data enablement for security operations, cyber threat intelligence, and incident response technologies and
teams;
- Manage the design, build, install, configure, and test dedicated cyber defense systems (hardware & software);
- Collaborate with both technical and non-technical teams to integrate security controls and procedures into workflows.
- Make recommendations to the Chief Information Officer on an information security roadmap based on risk analysis and assessments for current state and future state of information security
posture.
- Report regularly to senior management, keeping them abreast of the security landscape and the tactical controls and strategic plans to achieve success.
- Lead in developing communications for NYC Agency end users and stakeholders around cyber security issues.
- Ensure compliance with Citywide and agency security policies and standards;
- Design security solutions; conducts IT risk assessments and recommended mitigating solutions;
- Define, manage and monitor data security, confidentiality, integrity, and availability;
- Identify probable system exposures, compromises, problems, or design flaws and escalates issues to upper management to limit serious performance impact;

HOURS/SHIFT
Day - Due to the necessary technical management duties of this position in a 24/7 operation, candidate may be required to be on call and/or work various shifts such as weekends and/or evenings.

WORK LOCATION
Brooklyn, NY

TO APPLY
Please go to www.cityjobs/jobs/search and search for Job ID#695078

Only permanent employees in the title and those that are reachable on the civil service list are eligible to apply.

* Interested applicants with other civil service titles who meet the preferred requirements should also submit a resume for consideration

SUBMISSION OF A RESUME IS NOT A GUARANTEE THAT YOU WILL RECEIVE AN INTERVIEW
APPOINTMENTS ARE SUBJECT TO OVERSIGHT APPROVAL

Qualifications

1. A master's degree in computer science from an accredited college or university and three (3) years of progressively more responsible, full-time, satisfactory experience in Information Technology (IT) including applications development, systems development, data communications and networking, database administration, data processing, or user services. At least eighteen (18) months of this experience must have been in an administrative, managerial or executive capacity in the areas of applications development, systems development, data communications and networking, database administration, data processing or in the supervision of staff performing these duties; or

2. A baccalaureate degree from an accredited college or university and four (4) years of progressively more responsible, full-time, satisfactory experience as described in "1" above; or

3. A four-year high school diploma or its educational equivalent, and six (6) years of progressively more responsible, full-time, satisfactory experience as described in "1" above; or

4. A satisfactory combination of education and experience equivalent to "1", "2" or "3" above. However, all candidates must have at least a four-year high school diploma or its educational equivalent and must possess at least three (3) years of experience as described in "1" above, including the eighteen (18) months of administrative, managerial, executive or supervisory experience as described in "1" above.

In the absence of a baccalaureate degree, undergraduate credits may be substituted for a maximum of two (2) years of the required experience in IT on the basis of 30 semester credits for six (6) months of the required experience. Graduate credits in computer science may be substituted for a maximum of one (1) year of the required experience in IT on the basis of 30 graduate semester credits in computer science for one (1) year of the required IT experience. However, undergraduate and/or graduate credits may not be substituted for the eighteen (18) months of experience in an administrative, managerial, executive, or supervisory capacity as described in "1" above.

Additional Information

The City of New York is an inclusive equal opportunity employer committed to recruiting and retaining a diverse workforce and providing a work environment that is free from discrimination and harassment based upon any legally protected status or protected characteristic, including but not limited to an individual's sex, race, color, ethnicity, national origin, age, religion, disability, sexual orientation, veteran status, gender identity, or pregnancy.

Average salary estimate

$125000 / YEARLY (est.)
min
max
$100000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Deputy Chief Information Security Officer (CISO), City of New York

Are you ready to make a difference in New York City's cybersecurity landscape? At the Office of Technology and Innovation (OTI), we're on the lookout for a passionate Deputy Chief Information Security Officer (CISO) who wants to lead the charge in protecting our digital infrastructure. Join us in Brooklyn, NY, as you implement and manage vital information security controls that will bolster our agency's overall security posture. In this role, you’ll work closely with the Chief Information Security Officer to coordinate security awareness across departments while overseeing a talented team of analysts and engineers. Your expertise will drive the development of comprehensive security systems, focusing on cutting-edge methodologies like zero trust and advanced cloud architectures. You’ll ensure that our IT systems comply with established security policies, while delivering training and guidance to agency IT teams to promote a strong security culture. From conducting risk assessments to reporting vital information to senior management, every day will present unique challenges and opportunities. Plus, with the chance to work with innovative technologies in a supportive environment dedicated to improving public safety and government operations, this is more than just a job—it’s a chance to leave a lasting impact on millions of New Yorkers. If you’re excited about the idea of leading and enhancing cybersecurity defenses in one of the largest cities in the world, we can’t wait to see what you can bring to the OTI team!

Frequently Asked Questions (FAQs) for Deputy Chief Information Security Officer (CISO) Role at City of New York
What are the main responsibilities of a Deputy Chief Information Security Officer at OTI?

As a Deputy Chief Information Security Officer at the Office of Technology and Innovation (OTI), your main responsibilities will include implementing security controls, overseeing compliance with security policies, and leading a team that assesses and mitigates security risks. You will design and develop cybersecurity architectures and manage enterprise-level security services across multiple city agencies. The position also involves collaboration with various teams to integrate security practices into workflows and providing training to ensure staff awareness of cyber threats.

Join Rise to see the full answer
What qualifications do you need to become a Deputy Chief Information Security Officer at OTI?

To qualify for the Deputy Chief Information Security Officer position at OTI, you need a master's degree in computer science and three years of relevant experience or a bachelor's degree with four years of progressively responsible IT experience. Additionally, at least 18 months must have been spent in a managerial or executive capacity within IT. If you lack a baccalaureate degree, you can substitute education for experience—each 30 semester credits can equate to six months of required experience.

Join Rise to see the full answer
How does the role of Deputy CISO at OTI contribute to improving public safety?

The role of Deputy CISO at OTI is crucial for enhancing public safety as it ensures the protection of sensitive data and city operations against cyber threats. By implementing robust security measures and educating teams on best practices, you help maintain the integrity and confidentiality of city information systems, which is essential for the functioning of various public services that citizens rely on every day.

Join Rise to see the full answer
What skills are essential for the Deputy Chief Information Security Officer position at OTI?

Essential skills for the Deputy Chief Information Security Officer position at the Office of Technology and Innovation include strong leadership abilities, a deep understanding of cybersecurity principles, risk assessment capabilities, experience with security frameworks such as zero trust, and effective communication skills for collaborating across departments. Technical expertise in system vulnerabilities, incident response, and compliance with data protection regulations is also critical.

Join Rise to see the full answer
What type of work environment can someone expect as a Deputy CISO at OTI?

As a Deputy Chief Information Security Officer at OTI, you can expect a dynamic and collaborative work environment in Brooklyn, NY. You will work alongside a team of dedicated professionals who are passionate about leveraging technology to drive safety and innovation in city services. While you may sometimes need to be on call or work various shifts due to the nature of cybersecurity operations, the workplace prioritizes a supportive and engaging culture.

Join Rise to see the full answer
Common Interview Questions for Deputy Chief Information Security Officer (CISO)
Can you describe your experience with risk assessments in the role of Deputy CISO?

In your response, highlight specific situations where you have conducted risk assessments, detailing the methodologies used, how you identified vulnerabilities, and how your findings informed strategic decisions. Emphasize the importance of a proactive approach to risk management in protecting organizational data.

Join Rise to see the full answer
How have you implemented zero trust security measures in previous roles?

Discuss specific examples where you successfully designed and implemented zero trust architectures. Explain the challenges you faced, how you overcame them, and the impact this had on the organization's overall security posture.

Join Rise to see the full answer
What measures would you take to ensure compliance with security policies?

Outline your strategic approach to compliance, including the importance of training, regular audits, and developing clear security policies. Provide examples of how you've previously ensured adherence to such policies in IT environments.

Join Rise to see the full answer
How do you handle security breaches or incidents?

Share your process for responding to security incidents, including initial detection, assessment, communication with stakeholders, and corrective actions taken. Focus on your ability to learn from incidents to improve future security measures.

Join Rise to see the full answer
What experience do you have in leading cybersecurity teams?

Describe your leadership style and how you've guided teams towards achieving cybersecurity objectives. Highlight specific achievements, such as projects completed or improvements in team performance and security outcomes.

Join Rise to see the full answer
How would you communicate complex security concepts to non-technical stakeholders?

Explain your approach to making technical information accessible, emphasizing the use of relatable examples and clear language. Discuss any tools or methods you utilize to enhance comprehension among non-technical staff.

Join Rise to see the full answer
Can you provide an example of a security framework you have developed?

Discuss the security framework you’ve crafted, the stakeholders involved, and how it was implemented. Emphasize the framework's alignment with organizational goals and its effectiveness in protecting critical information assets.

Join Rise to see the full answer
What tools and technologies do you think are essential for a Deputy CISO?

Identify the critical tools you consider fundamental for cybersecurity operations, such as Security Information and Event Management (SIEM) systems, vulnerability assessment tools, and incident response platforms. Explain how these technologies can improve security posture.

Join Rise to see the full answer
How do you stay up to date on the latest cybersecurity threats?

Share your methods for staying informed, such as attending conferences, participating in webinars, reading industry publications, or being part of professional organizations. Highlight the importance of continuous learning in adapting to the evolving threat landscape.

Join Rise to see the full answer
What do you think is the biggest challenge facing cybersecurity today?

Reflect on current trends affecting the cybersecurity landscape, such as the rise of ransomware, supply chain attacks, or advanced persistent threats. Discuss how organizations can effectively address these challenges through strategic planning and resource allocation.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 2 days ago
Posted 13 days ago
Photo of the Rise User
Bertoni Solutions Remote 100% remote position, only available to candidates located in Latin America, Lima, Peru
Posted 14 days ago
Photo of the Rise User
Ardent Remote Washington, D.C. Metro - hybrid/remote
Posted 8 days ago
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)

Our Mission To work to eliminate ageism and ensure the dignity and quality-of-life of New York City’s diverse older adults, and for the support of their caregivers through service, advocacy, and education. Strategic Goals To foster independence...

1030 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
December 26, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!