Demo

Senior Security Engineer

GovServicesHub
New York, NY Full Time
POSTED ON 2/9/2025
AVAILABLE BEFORE 5/7/2025

Job Description

Job Location :   New York, NY, Onsite.

Job Description : SCOBPE OF SERVICES

MyCity is a single portal for all City services and benefits.

The vision is a simple, seamless, and intuitive experience interacting with City government digitally.

It is designed with New Yorkers at the center of the process to prioritize features by conducting user research.

MyCity produces value for New Yorkers, early and often through phased releases.

There are several phases within the MyCity portal workstream (Child Care, Business Portal, Workforce Development Services and others).

OTI Cyber Command is looking for additional support as the cyber threat landscape continues to evolve and Citywide cybersecurity solutions are deployed in large, complex networked environments.

The needed resource skill set is specialized in : providing guidance at various stages of planning and implementing security design, processes and solutions, testing and validation, and pivot between numerous technical projects communicating status at various leadership levels.

The resource will have significant interaction with NYC Cyber Command leadership, its engineering, architecture, and application security teams, incident response and other cyber security practitioners.

TASKS :

Perform organization wide cybersecurity risk analysis and maintain updates on the identified risks

Create, socialize and obtain approval for cybersecurity strategy and plans to address generic and specific cybersecurity risks to the organization

Create and follow a process to track progress against cybersecurity plans

Lead the implementation of cybersecurity initiatives for MyCity Portal development project

Create network architecture diagrams, collect communication flow information, and build high level and low level design documents

Work on complex network problems, interact with vendor support teams, and drive the issue to resolution

Translate compliance requirements into specific security controls and present compensating security controls

Report to upper management on current cybersecurity posture and progress on mitigating identified risks

Identify cybersecurity gaps and maintain a risk register

Create metrics to measure cybersecurity controls efficacy

Work with partners to create and maintain incident response plans

Monitor and respond to alerts

Review and optimize existing cybersecurity controls

Ensure the organization compliance with cybersecurity best practices, policies and standards

Enforce endpoint security standards

Analyze vulnerabilities and work with Application Development, IT and Systems teams to ensure timely remediation and validation

Perform threat simulations to detect possible risks and provide cybersecurity recommendations on topics like network perimeter, identity management, API security, microservices design and / or application development

Instruct and guide other teams to craft "secure by default" infrastructure; they may also investigate, build, and recommend innovative technologies or other methods that will improve the security of cloud-based and on-premises environments

MANDATORY SKILLS / EXPERIENCE

Bachelor's degree in Computer Science, Information Systems or equivalent work experience

At least 12 years of experience in information security

At least 8 years in IT infrastructure management, application architecture, risk management, data architecture, middleware technology, and IT operations and project management

At least 8 years of experience with networking, load-balancing, DNS, TLS / SSL digital certificates, SAML and Single Sign-on technologies, Kerberos, MFA technologies, and Identity management

At least 4 years of experience working with tools and techniques for collecting and processing Network Security Telemetry and Security Event Data.

At least 4 years of experience working in cloud environment (Azure, AWS, GCP)

At least 4 years of experience working in securing Internet-facing applications, utilizing WAF technologies (eg : Akamai CDN and WAF, CloudFlare, Azure CDN and WAF, Azure FrontDoor, AWS CloudFront and WAF, and similar reverse-proxy technologies)

At least 4 years of experience architecting, deploying, and managing endpoint security and EDR technology

At least 4 years of experience using scripting languages (Python, Bash, Powershell, etc.)

At least 4 years of experience with Windows, Linux, or MacOS administration

At least 4 years of experience working with vulnerability management and scanning tools

At least 4 years of experience working with application scanning tools

REQUIRED SKILLS / EXPERIENCE :

Experience in implementing and operating Network Security Telemetry Collection Systems in multi-cloud and on-prem environments

Experience in implementing and operating Data Loss Prevention Systems

Experience of information security principles and practices, especially the implementation of practical technical controls to support organization policy

Strong understanding of networking protocols, firewalls, and cybersecurity protection concepts, including software development lifecycle, and compensating controls

Strong understanding of cloud-based services such as O365, AzureAD, IAM, Entra ID

Strong understanding of CIS controls

Experience with Syslog-NG, LogScale (Humio) or similar SIEM / log aggregation systems

Experience with SSO products and services such as Entra ID, PingFederate, or Okta

Experience with NetSkope, Zscaler, Palo Alto Networks Prisma Access or similar cloud proxies

Familiarly with CASB / SASE products

Experience with Cloud-based EDR / XDR tools

Knowledge of endpoint security management, configuration policies, and procedures

Experience with asset management and on-prem / cloud-based vulnerability management tools

Highly flexible / willing to learn new technologies

Highly organized with excellent analytical, problem solving and decision-making skills

Excellent communication and collaboration skills

Requirements

1.Level III- More than seven (7) years of experience working on complex projects with 2 or more years in a leadership role as a Specialist 2.More than 7 years of experience in Organizational Change Management (OCM) for state human service eligibility systems, including leading large-scale initiatives focusing on people, process, and technology transformations within public sector or government environments, including defining strategies for stakeholder engagement, creating communication plans, conducting readiness assessments, and creating and delivering training plans. 3.More than 7 years' experience in applying industry standard change management principles, methods and tools, and developing key performance metrics to assess impact and effectiveness. Qualifications : 1.At least 5 years of hands-on experience in the human service domain (e.g., SNAP, HEAP, PA, Child Care) and experience with IT-driven OCM projects. 2.At least 7 years' experience working on an OCM project in the human service domain that is federally funded, aligning to federal requirements prior to implementation. Examples include testing, deployment, and pilot requirements and federal program specific requirements. 3.At least 7 years implementing change for "external stakeholders". Examples include County, state, federal entities that are not designated as a sponsor of the project. 4.At least 7 years working on IT driven OCM projects, utilizing industry change management lifecycle methodologies and standards. 5.At least 5 years' experience managing deliverables-based vendors on projects. 6.Advanced degree or certification in change management (e.g., Prosci Certified Change Practitioner). 7.Experience defining strategies for stakeholder engagement, creating comprehensive communication plans, conducting readiness assessments, developing, and delivering training plans, and managing risk.

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Senior Security Engineer?

Sign up to receive alerts about other jobs on the Senior Security Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$164,835 - $201,088
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at GovServicesHub

GovServicesHub
Hired Organization Address Richmond, VA Full Time
Job Description Job Location : Richmond, VA, Hybrid. Note : 10 Years of experience required.Please submit your profile o...
GovServicesHub
Hired Organization Address Richmond, VA Full Time
Job Location : Richmond, VA, Hybrid. Job Description : Skills : Ability to perform Data Networking technology and operat...
GovServicesHub
Hired Organization Address Brooklyn, NY Full Time
Job Location : Brooklyn, NY, Hybrid. Job Description : 8 : 30 am Through 4 : 30 pm EST The Business Analyst must be avai...
GovServicesHub
Hired Organization Address Schenectady, NY Full Time
Job Description Job Location : Available to work Onsite, Schenectady, NY Job Description : Duties MUMPS / Cache' program...

Not the job you're looking for? Here are some other Senior Security Engineer jobs in the New York, NY area that may be a better fit.

Senior Software Engineer - Scoring

Abnormal Security, New York, NY

Senior DevOps Engineer

Armis Security, New York, NY

AI Assistant is available now!

Feel free to start your new journey!