Overview
Skills
Job Details
Position Summary
This role supports the design, implementation, and ongoing enhancement of enterprise security architecture across corporate and operational units within the MTA agencies. The position focuses on aligning business strategies with security frameworks, protecting enterprise information, and ensuring systems comply with industry standards and best practices. The role requires strong collaboration, technical expertise, and analytical capabilities.
Key Responsibilities
Security Requirements & Analysis
Evaluate business strategies to determine security requirements
Conduct system security assessments and vulnerability analyses
Research and apply information security standards
Identify system integration issues and prepare cost estimates
Security Architecture & Design
Develop strategic, tactical, and project-level security architecture plans
Design secure network solutions for LAN, WAN, VPNs, routers, firewalls, and related devices
Design and manage Public Key Infrastructure (PKI), including digital certificates and signatures
Ensure adherence to industry standards and security frameworks
Implementation & Operations
Implement intrusion detection and prevention methodologies
Direct installation, configuration, and calibration of security tools and systems
Develop preventive and reactive security measures
Manage cryptographic key creation, transmission, and maintenance
Provide technical support and maintain system documentation
Monitoring & Continuous Improvement
Monitor the security environment for threats and vulnerabilities
Evaluate and deploy system upgrades and enhancements
Track emerging security technologies, standards, and best practices
Reporting & Governance
Prepare security reports by collecting and analyzing data and trends
Develop, document, and maintain security policies, procedures, and standards
Participate in professional development and security organizations
Required Knowledge & Skills
Experience developing and documenting security architectures, roadmaps, and plans
Strong understanding of information security management frameworks (e.g., NIST, ISO 27001)
Expertise in network infrastructure: routers, switches, firewalls, VPNs, and network protocols
Hands-on experience with security technologies:
Network security appliances
Identity and Access Management (IAM)
Anti-malware solutions
Automated policy compliance tools
Endpoint and desktop security tools
Strong analytical and problem-solving skills
Ability to translate business requirements into effective security controls
Experience developing and maintaining security policies and standards