CybersecurityJobs.io
← Back to all jobs

Job Description

DCWP is hiring a Cyber Security Analyst Level II to help defend agency information technology against cybersecurity incidents and support implementation of cybersecurity policies, standards, directives, and guidelines. The role is based in New York, NY and works closely with NYC OTI and ITOPS.

Key Responsibilities

  • Under supervision, assist DoTSS in liaising with the NYC Office of Technology and Innovation (OTI) by helping ensure DCWP mitigates security threats in a timely manner.
  • Respond to alerts and events that could impact the Agency’s information technology security posture while maintaining a proactive stance.
  • Characterize and analyze network traffic and server or cloud performance metrics to identify anomalous activity and potential threats.
  • Complete appropriate patching across multiple systems, including workstations, servers, and network equipment such as switches, voice gateways, and routers.
  • Analyze malicious activity to determine the means, methods, and details of exploitations against agency systems and applications.
  • Evaluate commercial software in coordination with OTI for safe use by NYC DCWP.
  • Guide ITOPS in reimage and restore activities to return devices and equipment to previous known good states after an incident.
  • Validate, analyze, investigate, and mitigate reported trouble tickets or incidents from OTI.
  • Follow up to ensure DCWP staff take and follow Cyber Security Training.
  • Support secure development: ensure new software (including COTS and on-prem or cloud-based CRM) is developed following citywide security standards and protocols, and that it passes through SDLC and security accreditation from OTI.
  • Follow up on incident reports and application scan reports to ensure proper mitigation occurs in a timely manner.
  • Conduct network monitoring and intrusion detection analysis using tools such as intrusion detection or prevention systems, firewalls, and host-based security systems; review and adjust ACL based on source, destination, and port requirements.
  • Perform log-based and endpoint-based threat detection to protect against threats from multiple sources.
  • Correlate activity across assets and environments (on-premises and cloud) to identify patterns of anomalous or suspicious activity.
  • Support business continuity and disaster recovery planning, including conducting disaster recovery tests, publishing results, and applying changes to address deficiencies.
  • Research emerging threats and vulnerabilities to support identification of incidents.
  • Provide incident response support to users, including actions to contain activity and support forensic analysis when necessary.
  • Perform security standards testing against computers and IT equipment prior to implementation to confirm security standards are met.
  • Coordinate with OTI and ITOPS on providing IT inventory, performing DCWP security audits, and coordinating Comptroller and Criminal Justice Information Security (CJIS) directive audits.

Required Qualifications

  • Baccalaureate degree from an accredited college including or supplemented by 24 semester credits in specified cyber/security/IT areas; or
  • Four-year high school diploma or equivalent approved by a State department of education or recognized accrediting organization, plus three years of satisfactory experience in relevant areas; or
  • Education and/or experience equivalent to the above. College education may substitute for up to two years of required experience as described: 60 semester credits equals one year of experience. Additionally, 24 credits in specified areas from an accredited college or graduate school may be applied as described.

Tools and Technologies

  • Intrusion detection or prevention systems, firewalls, and host-based security systems
  • COTS, on-prem, and cloud-based CRM
  • SDLC
  • ACL
  • IS0 27000-1, IS0 27000-2
  • COBIT
  • NIST 800-53, NIST 800-171
  • CISSP, CISA, CISM
  • Delinea, Centrify
  • CISA Binding Operational Directives
  • Trellix, McAfee, CrowdStrike, Rapid7
  • Azure
  • CJIS

Program and Compliance Information

  • 55-a Program: The position is also open to qualified persons with a disability eligible for the 55-a Program. Indicate at the top of your resume and cover letter that you would like to be considered through the 55-a Program.
  • Public Service Loan Forgiveness: As a City of New York prospective employee, you may be eligible for federal loan forgiveness programs and state repayment assistance. See https://studentaid.gov/pslf/ for more information.
  • Residency requirement: New York City residency is generally required within 90 days of appointment. City employees in certain titles who have worked for the City for 2 continuous years may be eligible to reside in Nassau, Suffolk, Putnam, Westchester, Rockland, or Orange County. Discuss with the agency representative at the time of interview to determine applicability.

Location and Compensation

Location: New York, NY (onsite)

Salary: USD 91,566 to 131,664 per year

Minimum Experience: 3 years

Similar Jobs