About Cyber Command
New York City Cyber Command (NYC3) is committed to protecting City systems that provide vital services to New Yorkers from cyber threats, and helping residents become safer in their digital lives.
As the organization defending the largest municipality in the country, NYC3 is charged with directing citywide incident response, setting citywide cybersecurity policies and standards and working with city agencies to strengthen their cyber defenses.
“To lead and execute an innovative, intelligence-driven, risk-informed cyber defense and response strategy — with the support of key partners and allies — that enables the city government to properly function and provide services to New Yorkers.”
“New York City the most cyber-resilient city in the world”
About Security Sciences
Security Sciences provides highly functional, available, trusted solutions that prevent, detect, respond, and recover from cyber threats. Our Software Engineering team develops, constructs, tests, and maintains the software architecture necessary for big data analytics. Our Security Architecture team designs and implements highly defensible security infrastructure on behalf of NYC government agencies. Our Service Delivery team is responsible for providing NYC3 with IT infrastructure support and IT help desk services. Finally, our Cyber Programs team leads Security Sciences data protection and identity & access management (IAM) initiatives.
About the Position
The Associate IAM Security Engineer is responsible for the design and implementation of defensible security infrastructure on behalf of the New York City government. The candidate will be responsible for identifying security gaps across NYC government agencies and developing solutions to rectify those gaps. Furthermore, the Security Engineer will defend the City by reducing risks borne of password only identity architecture.
Responsibilities will include but are not limited to:
• Perform security reviews, identify gaps in security architecture, and develop a security risk management plan;
• Provide subject matter expertise on the deployment of Privileged Access Management (PAM) and Multifactor Authentication (MFA) solutions;
• Design, build, install, configure, and test dedicated cyber defense systems (hardware & software);
• Implement robust, enterprise Identity and Access Management (IAM) solutions across multiple city agencies;
• Operate and administer cyber defense applications and software;
• Collaborate with both technical and non-technical teams to integrate security controls and procedures into workflows;
• Automate controls and redundant processes whenever possible;
• Liaise with cybersecurity vendors to support procurement of cybersecurity solutions;
• Handle special projects and initiatives as assigned.
Minimum Qual Requirements
1. A baccalaureate degree, from an accredited college including or supplemented by twenty-four (24) semester credits in cyber security, network security, computer science, computer programming, computer engineering, information technology, information science, information systems management, network administration, or a pertinent scientific, technical or related area; or
2. A four-year high school diploma or its equivalent approved by a State’s department of education or a recognized accrediting organization and three years of satisfactory experience in any of the areas described in “1” above; or
3. Education and/or experience equivalent to “1” or “2”, above. College education may be substituted for up to two years of the required experience in “2” above on the basis that sixty (60) semester credits from an accredited college is equated to one year of experience. In addition, twenty-four (24) credits from an accredited college or graduate school in cyber security, network security, computer science, computer programming, computer engineering, information technology, information science, information systems management, network administration, or a pertinent scientific, technical or related area; or a certificate of at least 625 hours in computer programming from an accredited technical school (post high school), may be substituted for one year of experience.
The preferred candidate should possess the following:
• Professional experience architecting/operating IAM solutions and frameworks built on AWS, Azure, or Google Cloud;
• In depth knowledge of IAM protocols such as SAML, SPML, XACML, SCIM, OpenID and OAuth;
• Experience communicating effectively across internal and external organizations, for complex mission-critical solutions;
• Security and cloud certifications (CySA+, GCIA, CCSP, Google Compute Platform, AWS, Azure, etc.);
• At least 2 years of experience working with Microsoft Azure AD in an enterprise environment;
• Experience implementing/working with Enterprise SSO, Federation, and API gateways, SOA services;
• Skill in configuring and utilizing software-based cybersecurity tools;
• Skill in configuring and utilizing cybersecurity hardware components;
• Experience with Windows and Linux;
• Outstanding written and verbal communication skills;
• Self-motivated with a commitment to learning and continuous improvement.
Special Note: Taking and passing civil service exams are necessary to maintain employment with the City of New York. Please check the Department of Citywide Administrative Services (DCAS) website (http://www.nyc.gov/html/dcas/html/work/exam_monthly.shtml) for important exam filing information. Please ensure that you are either a permanent employee in the civil service title listed on this posting, or, that you file for the examination when there is an open filing period. For more information regarding the civil service process, please visit the DCAS website at: http://www.nyc.gov/html/dcas/html/work/work.shtml
* Interested applicants with other civil service titles who meet the preferred requirements should also submit a resume for consideration
For City employees, please go to Employee Self Service (ESS), click on Recruiting Activities > Careers, and search for Job ID #467544
For all other applicants, please go to www.nyc.gov/jobs/search and search for Job ID #467544
SUBMISSION OF A RESUME IS NOT A GUARANTEE THAT YOU WILL RECEIVE AN INTERVIEW
APPOINTMENTS ARE SUBJECT TO OVERSIGHT APPROVAL
NOTE: This position is open to qualified persons with a disability who are eligible for the 55-a Program.
Please indicate in your cover letter that you would like to be considered for the position under the 55-a program.
Department of Information Technology & Telecommunications and the City of New York are equal opportunity employers.
DoITT participates in E-Verify
Day – Due to the necessary technical support duties of this position in a 24/7 operation, candidate may be required to work various shifts such as weekends and/or nights/evenings.
New York, NY
New York City residency is generally required within 90 days of appointment. However, City Employees in certain titles who have worked for the City for 2 continuous years may also be eligible to reside in Nassau, Suffolk, Putnam, Westchester, Rockland, or Orange County. To determine if the residency requirement applies to you, please discuss with the agency representative at the time of interview.