Overview
On Site
USD 166,709.00 - 210,100.00 per year
Full Time
Skills
Preventive Maintenance
Performance Management
Telecommuting
Network
SAFE
Customer Service
Customer Facing
Payment Card Industry
Risk Assessment
Analytics
Agile Coaching
HR Management
Product Management
Financial Management
Business Management
Procurement
Employee Self-service
Business Process
Forms
Information Systems
IT Management
Information Technology
Acquisition
Business Planning
Reporting
Continuous Delivery
Service Level
Recruiting
Motivation
Human Resources
Workforce Planning
Business Cases
Cost-benefit Analysis
IT Architecture
Evaluation
Disaster Recovery
Vendor Management
Contract Management
Documentation
IT Security
Training
Information Security
System Testing
Talent Management
Risk Management
Leadership
Continuous Improvement
Threat Modeling
Incident Management
Management Reporting
Research
Emerging Technologies
Process Improvement
Invoices
Quality Assurance
Computer Science
Supervisory Management
CISSP
CISM
Project Management
Waterfall
Agile
Cyber Security
Operating Systems
Cloud Computing
TCP/IP
Internet
Intranet
OSI
Scripting
Perl
Python
Windows PowerShell
Productivity
Information Engineering
Internet Explorer
Microsoft Office
Data Analysis
IT Infrastructure
Computer Hardware
Communication
Budget
Management
Partnership
Innovation
Customer Focus
Customer Relationship Management (CRM)
Law
Finance
FDS
MTA
Military
Job Details
Description
JOB TITLE: Cybersecurity Director
SALARY RANGE: $166,709 - $210,100
HAY POINTS: 994
DEPT/DIV: Information Technology
SUPERVISOR: Deputy Chief
LOCATION: Vario 2 Broadway New York, NY 10004
HOURS OF WORK: 9:00 am - 5:30 pm (7.5 hours/day) or as required)
This position is eligible for telework which is currently two days per week. New hires are eligible to apply 30 days after their effective date of hire.
The Metropolitan Transportation Authority is North America's largest transportation network, serving a population of 15.3 million people across a 5,000-square-mile travel area surrounding New York City, Long Island, southeastern New York State, and Connecticut. The MTA network comprises the nation's largest bus fleet and more subway and commuter rail cars than all other U.S. transit systems combined. MTA strives to provide a safe and reliable commute, excellent customer service, and rewarding opportunities.
Summary:
The purpose of this position is to provide cybersecurity focused technical leadership and management of MTA's cybersecurity program in one or more technical domains.
This role deals with both internal and external threats to the MTA systems, which can affect both the safety of employees and customers, system integrity, and the availability of operations.
As part of managing the program, the Director will need expertise in leading a complex program with highly skilled managers and leaders, contracts, and processes associated with risk management that are essential to maintaining electronic and physical safety for MTA's business in all areas that utilize technology (Corporate, Customer Facing and Informational, Fare Payment/PCI, Operational Technologies, 3rd Party Managed, Vendors, etc.).
The Cybersecurity Director will be responsible for leading and managing multiple teams, overseeing the overall team effectiveness, developing people, technology, and processes to reduce risk with the evolving cyber threat landscape and changing technology portfolio.
This position works across multiple technology and cybersecurity domains to ensure cybersecurity is looked at holistically from user, data and component, and systems perspectives.
The position also considers all risk assessments, data-driven analytics, and actively seeks to develop and maintain standards, reference architectures, and reduce the risk of the MTA through emerging technologies and trends in the industry.
The position is expected to have a level of expertise in one or more domains of technology and effective management. There is a long list of these specialized domains in the cybersecurity field, and this list is growing and ever changing as the field evolves and as risks and circumstances change.
Responsibilities:
Leadership
Financial Management
Strategy & Planning
Acquisition & Deployment
Management and Oversight
Cybersecurity Director-Specific Accountabilities
Planning
Architecture
Contracts/Vendor Management
Documentation
Guidance, Communications, and Training Support
Operations
Research & Analysis
Qualifications:
Experience
Knowledge & Skills:
Must possess a deep understanding of technology and cybersecurity domain principles.
Proven ability to manage projects and initiatives.
Proven ability to add value to a team.
Understanding of Operating Systems, Cloud, Mobile, and Applications
Understanding of TCP/IP (OSI Layers 1- 4) and Internet and Intranet technologies required (OSI Layers 5-7).
Some Scripting or programming skills (PERL, Python, PowerShell, etc.) preferred as needed.
Proficient in Productivity Tools (ie, Office 365, Gsuite).
Experience with Spreadsheets and Data Analysis.
Successful track record in the design of software systems to meet the current and future needs of a complex organization OR
Successful track record in the design and implementation of IT Infrastructure and related hardware and software technologies to meet the current and future needs of a complex transportation organization.
Strong Verbal/written communication skills.
Financial/budgeting planning and management experience is a plus.
Ability to fit in with the constantly shifting needs and demands of the business Departments.
Competencies:
Core Competency
Proficiency Level
Competency Definition
Collaborates
Expert
Building partnerships and working collaboratively with others to meet shared objectives
Cultivates Innovation
Expert
Creating new and better ways for the organization to be successful
Customer Focus
Expert
Building strong customer relationships and delivering customer-centric solutions
Communicates Effectively
Expert
Developing and delivering multi-mode communications that convey a clear understanding of the unique needs of different audiences
Tech Savvy
N/A
Anticipating and adopting innovations in business-building digital
and technology applications
Technical Skills
N/A
Specialized knowledge and expertise on tools, programs, domains, platforms, and products used for specific tasks
Values Diversity
Expert
Recognizing the value that different perspectives and cultures bring to an organization
OTHER INFORMATION:
Pursuant to the New York State Public Officers Law & the MTA Code of Ethics, all employees who hold a policymaking position must file an Annual Statement of Financial Disclosure (FDS) with the NYS Commission on Ethics and Lobbying in Government (the "Commission").
Equal Employment Opportunity
MTA and its subsidiary and affiliated agencies are Equal Opportunity Employers, including with respect to veteran status and individuals with disabilities.
The MTA encourages qualified applicants from diverse backgrounds, experiences, and abilities, including military service members, to apply.
JOB TITLE: Cybersecurity Director
SALARY RANGE: $166,709 - $210,100
HAY POINTS: 994
DEPT/DIV: Information Technology
SUPERVISOR: Deputy Chief
LOCATION: Vario 2 Broadway New York, NY 10004
HOURS OF WORK: 9:00 am - 5:30 pm (7.5 hours/day) or as required)
This position is eligible for telework which is currently two days per week. New hires are eligible to apply 30 days after their effective date of hire.
The Metropolitan Transportation Authority is North America's largest transportation network, serving a population of 15.3 million people across a 5,000-square-mile travel area surrounding New York City, Long Island, southeastern New York State, and Connecticut. The MTA network comprises the nation's largest bus fleet and more subway and commuter rail cars than all other U.S. transit systems combined. MTA strives to provide a safe and reliable commute, excellent customer service, and rewarding opportunities.
Summary:
The purpose of this position is to provide cybersecurity focused technical leadership and management of MTA's cybersecurity program in one or more technical domains.
This role deals with both internal and external threats to the MTA systems, which can affect both the safety of employees and customers, system integrity, and the availability of operations.
As part of managing the program, the Director will need expertise in leading a complex program with highly skilled managers and leaders, contracts, and processes associated with risk management that are essential to maintaining electronic and physical safety for MTA's business in all areas that utilize technology (Corporate, Customer Facing and Informational, Fare Payment/PCI, Operational Technologies, 3rd Party Managed, Vendors, etc.).
The Cybersecurity Director will be responsible for leading and managing multiple teams, overseeing the overall team effectiveness, developing people, technology, and processes to reduce risk with the evolving cyber threat landscape and changing technology portfolio.
This position works across multiple technology and cybersecurity domains to ensure cybersecurity is looked at holistically from user, data and component, and systems perspectives.
The position also considers all risk assessments, data-driven analytics, and actively seeks to develop and maintain standards, reference architectures, and reduce the risk of the MTA through emerging technologies and trends in the industry.
The position is expected to have a level of expertise in one or more domains of technology and effective management. There is a long list of these specialized domains in the cybersecurity field, and this list is growing and ever changing as the field evolves and as risks and circumstances change.
Responsibilities:
Leadership
- Provide leadership in the development of inter-team communication and cohesiveness; sustain culture and support assigned staff during organizational growth/changes.
- Lead a team of multi-functional technical staff planning, building, and maintaining cybersecurity tools, configurations, and risk mitigation to support Information and Operational Technology applications and/or infrastructure products
- Lead others, as appropriate, and when necessary, that will consist of one or more agile coaches, data analytics researchers, and other cybersecurity personnel
- Provide direction on evaluation, selection, implementation, and maintenance of cybersecurity tools, processes, and techniques for their assigned cyber domains and products, ensuring appropriate investment in strategic and operational systems.
- Human Resource Management
- Attract, develop, coach, and retain high-performance team members, empowering them to elevate their level of responsibility, span of control, and performance in conjunction with the Cybersecurity Management and IT Workforce Planning & Workload Management office.
- Build staff expertise and competence to meet evolving demands within the Enterprise Product Management unit.
Financial Management
- Demonstrate consistent understanding of funding, communications, and systems; recommend timelines and resources needed to achieve the program goals.
- Collaborates with IT Business Management Services to identify procurement contracts to support program related activities.
Strategy & Planning
- Assesses and makes recommendations on the improvement and re-engineering within the IT Department and works with the stakeholders to keep the total cost of ownership down.
- Promote the use of employee self-service and mobile connectivity within products to reduce the reliance of paper.
- Recommends and supports automation of business process creating in-line forms and approvals, reducing the reliance on manual approvals that could be untimely.
- Automation of business process creating in-line forms and approvals, reducing the reliance on manual approvals that could be untimely.
Acquisition & Deployment
- Coordinates and facilitates consultation with stakeholders to define business and systems requirements for new technology implementations, developing business cases and cost justifications for such initiatives.
- Provides direction on evaluation, selection, implementation, and maintenance of information systems, ensuring appropriate investment in strategic and operational systems.
- Advises MTA IT management, as information becomes available, on the changing trends and emerging technology and their potential use within the MTA.
- Directs the development of the analysis required to determine if Information Technology projects should follow a "Build" (develop with in-house staff) or "Buy" (cloud or packaged solution) methodology.
- Leads the development and implementation of new modules within assigned products.
- Advises on the selection, prioritization, development, and implementation of products as they relate to the selection, acquisition, development, and installation of MTA IT and OT Security, applications, and infrastructure.
Management and Oversight
- Participates in overall business planning, bringing current knowledge and future vision of technology and systems as related to the company's goals.
- Responsible for leading and reporting on various product progress and deliverables, ensuring that the IT needs of the MTA are met on time and within budget, including identifying weekly, monthly, and annual performance targets to show progress on IT product work.
- Ensure continuous delivery of product services through oversight of service level agreements with end users and monitoring of product performance.
- Responsible for the recruitment, development, motivation, training, and retention of a diverse and high performing multi-level IT team of professionals, conforming to budgetary objectives and Human Resources policy and programs in conjunction with the IT Workforce Planning & Workload Management office.
- Develop business case justifications and cost/benefit analyses for IT spending and initiatives, keeping customizations to a minimum and total cost of ownership down.
Cybersecurity Director-Specific Accountabilities
Planning
- Lead and plan for the future technical architecture, providing insight into the future of their area of technology in order to continually improve effectiveness and efficiency.
- Lead and oversee the development of road maps related to their area(s) of expertise to manage and meet identified technology needs.
- Manage and plan the evaluation of new technologies relative to their domain(s) to determine applicability to and best meet the needs of MTA and constituent agencies.
- Ensure specific monitoring points are continually updated to assess the performance of technologies in their domain(s). Identify and manage the necessary actions to ensure optimal performance and reliability.
- Manage and ensure disaster recovery and contingency plans for their domain(s) to provide users with minimal interruptions in service.
- Provide escalation support to project teams in their area of expertise to promote technical understanding and talent development, and/or lead teams to complete projects when a project manager has not been assigned.
- Contribute and own technical elements of RFPs and RFIs, and negotiate with vendors on technical issues to ensure results are delivered in line with user and organization requirements.
- Manage and lead major providers with technical expertise to address mission critical issues, evaluate ongoing vendor service levels, and enforce SLAs and penalties.
Architecture
- Oversees architectural direction for domains under management to meet senior management and cybersecurity goals.
- Understand, review, and approve Cybersecurity Reference Architectures and Solutions for applying them
- Revalidates systems to the most recent reference architectures to determine gaps, develops and manages programs to align systems to the newest standards and reference architectures
Contracts/Vendor Management
- Contribute and own technical elements of RFPs and RFIs, and negotiate with vendors on technical issues to ensure results are delivered in line with user and organization requirements.
- Manage contracts and expenses to ensure SLAs and contract renewals are processed timely manner
- Provide contract management support to ensure vendor deliverables are met
- Manage and lead major projects and assign service providers with technical expertise to address mission critical issues, evaluate ongoing vendor service levels, and enforce SLAs and penalties.
Documentation
- Ensure detailed and updated documentation is in place for cybersecurity systems and user processes.
- Participate in the creation of enterprise security documents (policies, standards, baselines, guidelines, and procedures) under the direction of the IT Security Manager, where appropriate.
Guidance, Communications, and Training Support
- Provides timely and relevant updates to appropriate stakeholders and decision makers
- Communicates investigation findings to relevant business units to help improve the information security posture
- Provides technical guidance to project managers and senior leadership on cybersecurity and technology strategies
- Ensure quality and review, and guidance on tests of new systems and manage cybersecurity risks, and remediation system testing, baseline, and best practices
- Provide escalation support to project teams in their area of expertise to promote technical understanding and talent development
- Provide guidance and take input from Analysts, Engineers, Architects, and Technology Subject Matter Experts on cybersecurity and technology best practices, current threat landscape, and a risk management approach for optimal alignment
- Provides sound cybersecurity recommendations
Operations
- Provide leadership and advisement when necessary during incident response, and provide continuous improvement updates to the threat model for risks to the business and systems
- Ensure specific monitoring points are continually updated to assess the performance of technologies in their domain(s). Identify and manage the necessary actions to ensure optimal performance and reliability.
Research & Analysis
- Validates and maintains incident response plans and processes to address potential threats
- Compiles and analyzes data for management reporting and metrics
- Research emerging technologies and process improvements to stay current and plan for the evolving threat landscape to ensure strategy meetings current threats
- Monitors relevant information sources to stay up to date on current attacks and trends
- Ensure cybersecurity technology solutions meet strategy, meet security framework objectives, and business objectives
- Hypothesizes new threats and indicators of compromise
- Performs other duties and tasks as assigned.
- Observing the work performed by the contractor.
- Reviewing invoices and approving them if the work meets contractual standards.
- Addressing performance issues with the contractor when possible.
- Escalating issues to other parties as needed.
- Oversee rigorous quality assurance processes to deliver reliability, performance, and safety objectives
- Oversees staff workload and quality of work, addressing performance issues when needed.
Qualifications:
Experience
- Bachelor's degree required, preferably in Computer Science or related fields. An equivalent combination of education and experience may be considered in lieu of a degree.
- A minimum of 8 years of relevant experience with a minimum of four years supervisory/management experience.
- CISSP, CISM, or other advanced security-related certification preferred
- Certifications in technology subdomains preferred (i.e., Cloud, Applications, Infrastructure, Security Technology, etc.).
- Requires prior experience with installing, maintaining, and troubleshooting technology systems.
- Experience in Project Management Principles (Waterfall and Agile) preferred
Knowledge & Skills:
Must possess a deep understanding of technology and cybersecurity domain principles.
Proven ability to manage projects and initiatives.
Proven ability to add value to a team.
Understanding of Operating Systems, Cloud, Mobile, and Applications
Understanding of TCP/IP (OSI Layers 1- 4) and Internet and Intranet technologies required (OSI Layers 5-7).
Some Scripting or programming skills (PERL, Python, PowerShell, etc.) preferred as needed.
Proficient in Productivity Tools (ie, Office 365, Gsuite).
Experience with Spreadsheets and Data Analysis.
Successful track record in the design of software systems to meet the current and future needs of a complex organization OR
Successful track record in the design and implementation of IT Infrastructure and related hardware and software technologies to meet the current and future needs of a complex transportation organization.
Strong Verbal/written communication skills.
Financial/budgeting planning and management experience is a plus.
Ability to fit in with the constantly shifting needs and demands of the business Departments.
Competencies:
Core Competency
Proficiency Level
Competency Definition
Collaborates
Expert
Building partnerships and working collaboratively with others to meet shared objectives
Cultivates Innovation
Expert
Creating new and better ways for the organization to be successful
Customer Focus
Expert
Building strong customer relationships and delivering customer-centric solutions
Communicates Effectively
Expert
Developing and delivering multi-mode communications that convey a clear understanding of the unique needs of different audiences
Tech Savvy
N/A
Anticipating and adopting innovations in business-building digital
and technology applications
Technical Skills
N/A
Specialized knowledge and expertise on tools, programs, domains, platforms, and products used for specific tasks
Values Diversity
Expert
Recognizing the value that different perspectives and cultures bring to an organization
OTHER INFORMATION:
Pursuant to the New York State Public Officers Law & the MTA Code of Ethics, all employees who hold a policymaking position must file an Annual Statement of Financial Disclosure (FDS) with the NYS Commission on Ethics and Lobbying in Government (the "Commission").
Equal Employment Opportunity
MTA and its subsidiary and affiliated agencies are Equal Opportunity Employers, including with respect to veteran status and individuals with disabilities.
The MTA encourages qualified applicants from diverse backgrounds, experiences, and abilities, including military service members, to apply.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.