What are the responsibilities and job description for the Cybersecurity Engineer - Security Specialty OT (Level 6) position at Metropolitan Transportation Authority?
Job ID : 9719
Business Unit : MTA Headquarters
Location : New York, NY, United States
Regular / Temporary : Regular
Department : IT CISO
Date Posted : Jan 15, 2025
Description
JOB TITLE : Cybersecurity Engineer - Security Specialty OT (Level 6)
SALARY RANGE : $124,311 - $169,104
HAY POINTS : 634
DEPT / DIV : Information Technology / Cybersecurity
SUPERVISOR : Cybersecurity Manager, IT Cyber Security
LOCATION : Various / 2 Broadway New York, NY 10004
HOURS OF WORK : 9 : 00 am - 5 : 30 pm (7.5 hours or as required)
APPLICATION DEADLINE : November 29, 2024
This position is eligible for telework which is currently two day per week. New hires are eligible to apply 30 days after their effective date of hire.
About us :
The MTA transportation network has very large systems and infrastructure for financial, business, automated train, transportation, power, and physical security. The MTA IT Department, is centrally responsible for providing a full range of Information and Operational Technology services to the MTA agencies and administrative units through its operating and support units.
The MTA IT Cybersecurity organization, is responsible for identifying, developing, implementing, and integrating cybersecurity-related processes internal and third-party supplier organizations to reduce the operational risks, reputational risks and financial risks. The organization also has robust cybersecurity operations functions designed to protect the MTA in real-time on a 7 / 24 / 365 basis.
Summary of Job
The purpose of this position is to provide technical expertise in managing and analyzing cybersecurity risks. Cybers ecurity Engineer will be responsible for design, building and maintaining infrastructure, applications technology to support a secure cybersecurity posture. These include systems that support cybersecurity directly and / or the business operations for Information and Operational Technology disciplines. Secure building and configuration of systems (applications, infrastructure, wireless, carrier systems, cloud, operational technology, IOT, etc.) from the outset reduces risk to MTA. Specialized and focused skillets in various technology domains assist with the overall risk reduction for the MTA. The configuration, hardening, guidance, response, and analysis of these systems aide in reduction and containment of Cyber Security risk. Risk assessments, data analytics tools, operational process reviews, and collaboration with security engineers, architects, developers, vendors, business units to constantly improve the overall security of the MTA
Responsibilities
- Researching emerging threats and vulnerabilities to aid in the identification of network incidents, and supports the creation of new architecture, policies, standards, and guidance to address them
- Knowledge and practical implementation of secure system configuration and hardening standards
- Design, configure and integrated secure solutions in the technology domains assigned
- Provide incident response support, including mitigating actions to contain activity and facilitating forensics analysis, system hardening and recovery when necessary
- Provides installation, system configuration, hardening and optimization for infrastructure, application, and security components and systems such as servers, workstations, mobile devices, directory services, operating systems, middleware, IOT, web and next generation firewalls, machine and human behavior learning tools, host-based security system, security event and incident monitoring systems, virtual, physical, and cloud platforms.
- Identifies configuration gaps independently and / or with vendors to reduce cybersecurity risks
- Reviews alerts and data from sensors and documents formal, technical incident reports
- Tests new systems and manage cybersecurity risks and remediation system testing, baseline, and best practices
- Responds to computer security incidents according to the computer security incident response policy and procedures
- Provides technical guidance to first responders for handling information security incidents
- Provides timely and relevant updates to appropriate stakeholders and decision makers
- Communicates investigation findings to relevant business units to help improve the information security posture
- Validates and maintains incident response plans and processes to address potential threats
- Compiles and analyzes data for management reporting and metrics
- Monitors relevant information sources to stay up to date on current attacks and trends
- Analyzes potential impact of new threats and communicates risks back to detection analyst, architect, technology SME, and management functions
- Performs root-cause analysis to document findings, and participate in root-cause elimination activities as required
- Uses judgment to form conclusions that may challenge conventional wisdom
- Hypothesizes new threats and indicators of compromise
- Monitors threat intelligence feeds to identify a range of threats, including indicators of compromise and advanced persistent threats (APTs)
- Identifies the tactics, techniques and procedures (TTPs) of potential threats through the MITRE ATT&CK or similar frameworks.
- Participate in the creation of enterprise security documents (policies, standards, baselines, guidelines, and procedures) under the direction of the IT Security Manager, where appropriate.
The role will provide a proactive approach to cybersecurity while also performing investigation of security incidents related to MTA operations related to Cyber Security.
Level 6
Qualifications :
Education and experience :
Competencies : Management Level
Proficiency Level
Standard Competencies
Level 6
Expert
Communicates Effectively
Advanced
Technical Skills
Tech Savvy
Values Diversity
Collaborates
Adept
Customer Focus
Cultivates Innovation
Preferred Technical Skills :
Soft Skills :
GENERAL :
Pursuant to the New York State Public Officers Law & the MTA Code of Ethics, all employees who hold a policymaking position must file an Annual Statement of Financial Disclosure (FDS) with the NYS Commission on Ethics and Lobbying in Government (the "Commission").
MTA and its subsidiary and affiliated agencies are Equal Opportunity Employers, including with respect to veteran status and individuals with disabilities.
The MTA encourages qualified applicants from diverse backgrounds, experiences, and abilities, including military service members, to apply.
Salary : $124,311 - $169,104