Review Vacancy
AgencyInformation Technology Services, Office of
TitleManager Information Technology Services 1 Information Security - 11746
Occupational CategoryI.T. Engineering, Sciences
Bargaining UnitPS&T - Professional, Scientific, and Technical (PEF)
Salary RangeFrom $111708 to $137590 Annually
Duties Description Within the Chief Technology Office/Shared Delivery Services/Data Center Networks, Cloud Operations group, this position will manage advanced design, network security, and deployment of multi-Cloud connectivity projects, networking activities, and ongoing mission-critical initiatives.
Specific duties may include, but are not limited to, the following:
• Serve as senior Cloud network security manager, engineer, subject matter expert, and liaison in the Cloud Operations group. Security tasks include: virtual network security, encryption management, identity and access governance, monitoring and threat detection.
• Serve as lead liaison to manage implementation of approved security designs and virtual network architectures across Cloud platforms Microsoft Azure, Amazon Web Services (AWS), Google Cloud Platform (GCP), and multiple New York State (NYS) data centers.
• Manage secure Cloud network connectivity for dozens of NYS agencies and their applications to/from/within Microsoft Azure, AWS, GCP, and multiple NYS data centers.
• Design, deploy, and maintain Cloud networking infrastructure in AWS, Azure, and GCP to support new and existing NYS agency application deployments in the Cloud.
• Design and implement on-premises to Cloud connectivity solutions as required by application needs in collaboration with the Chief Information Security Office and network/application/architecture teams.
• Design, deploy, and maintain network virtual appliances as needed including Arista CloudEOS and Palo Alto PAN-OS with integrations into Cloud Service Provider (CSP) network infrastructure (Google Cloud Network Connectivity Center, AWS Transit Gateway Connect, etc.).
• Manage ITSM Service Requests and Incidents related to the implementation and maintenance of network firewall security policies/profiles on Palo Alto Networks Cloud Next Generation Firewalls (NGFW).
• Manage Virtual Private Network (VPN) tunneling between firewalls on premises (ZEN and Utica) and within the Cloud environments (Azure, AWS, and GCP).
• Cross-train junior staff in physical, virtual, security, and Cloud network technologies.
• Utilize Terraform to develop Infrastructure as Code (IaC) uniform Cloud configuration and backup solutions.
• Manage and lead in the orchestration of multi-discipline technologies for the resolution of complex problems; communicate with technology and business leaders for problem resolution and make recommendations for system enhancements as required.
• Provide 24x7x365 on-call network support for advanced troubleshooting, escalation, and ticket resolutions on a rotating basis.
• Collaborate and troubleshoot with direct Cloud connectivity providers to develop solutions and solve problems.
• Troubleshoot carrier-class network equipment and end-to-end network connectivity; proficiency in Layer 3 routing required, including Border Gateway Protocol (BGP), Virtual Routing and Forwarding (VRF), route maps, redistribution, Network Address Translation (NAT), subnetting, etc.
• Provide in-depth analysis on network performance using tools such as Zenoss, Splunk, Palo Alto Panorama, Arista CloudVision as-a-Service, NfSen, Ixia, Gigastor, Wireshark, etc.
• Ensure that network availability of Cloud environments is maximized by overseeing Change Control procedures, code upgrades, network monitoring, installations, moves and changes, and troubleshooting complex issues.
• Participate in network performance analysis, training, and capacity planning.
• Document all design and implementation work using Microsoft Visio.
• Occasional travel may be required.
• Perform the full range of supervisory responsibilities.
Minimum Qualifications Non-competitive: Seven years of information technology, cybersecurity, or information
assurance experience, including one year at the supervisory level.
Substitutions:
A bachelor's or higher-level degree in any field including or supplemented by 15
semester credit hours in computer science or related field substitutes for three years of
required experience; any bachelor’s substitutes for two years of required experience.
An associate degree with 15 semester credit hours in computer science or related field
may substitute for one year of required experience. Candidates in a bachelor’s degree
program with at least 15 semester credit hours in computer science or related field may
substitute such credits for one year of required experience.
A master’s degree or higher in computer science or related field substitutes for one year
of required experience.
Preferred Qualifications:
• Proven ability to work independently and as a team member
• Proven ability to lead teams and develop network engineers
• Proven analytical, problem solving, organizational and time management skills
• Good communication (written and oral) and interpersonal skills
• Good organizational, multi-tasking, and time-management skills
• Expert AWS network infrastructure: VPCs, subnets, security groups, route tables, VPGs, Transit Gateway, NACLs, load balancers, peering, logging, alerting, and troubleshooting
• Expert Azure network infrastructure: VNets, subnets, NSGs, route tables, VNGs, load balancers, logging, alerting, and troubleshooting
• Expert GCP network infrastructure: VPCs, subnets, firewall rules, VPC routing, Cloud Router, CloudVPN, CloudNAT, load balancers, private service connections, logging, alerting, and troubleshooting
• Basic working knowledge of CSP application platforms and their networking requirements (Kubernetes engines/services, ASE, serverless, etc.)
• Proficiency with Cloud Shell in all platforms for data extraction and reporting at scale
• Proficiency in Terraform to lead in the development of Infrastructure as Code (IaC) uniform Cloud configuration and backup solutions
• Proficiency in Layer 3 routing including BGP, VRFs, route maps, redistribution, NAT, subnetting, etc.
• Proficiency in Arista CloudEOS including routing, tunnels, upgrades, logging, and monitoring
• Proficiency in Palo Alto PAN-OS including security policies, NAT policies, zones, routing, tunnels, upgrades, logging, and monitoring
• Proficiency in IPSec and MACsec encrypted transport for Cloud connectivity across carrier networks and the Internet
• Proficiency in Domain Name System (DNS) and managing split-brain public/private resolution designs
• Experience supporting CSP dedicated connectivity (AWS DirectConnect, Azure ExpressRoute, GCP Interconnect)
• Experience working with Telco carriers to troubleshoot circuit connectivity problems
• Experience working with monitoring and packet capture/analysis tools such as Zenoss, Splunk, Palo Alto Panorama, Arista CloudVision as-a-Service, NfSen, Ixia, Gigastor, Wireshark, etc.
• Proficiency in Microsoft Visio for solutions documentation
• Networking certifications (CCNA/CCNP, PCNSA/PCNSE, Network+, etc.) are a plus
Additional Comments ITS will not offer permanent employment to any candidate unless the candidate provides documentation that they are authorized to accept work in the United States on a permanent basis. It is the policy of ITS not to hire F1 or H1 visa holders for permanent employment or to sponsor non-immigrant aliens for temporary work authorization visas or for permanent residence.
Some positions may require fingerprinting.
Some positions may require up to 25% travel and/or lifting up to 50 lbs. Some positions are pending Civil Service approval. Details of position(s) will be described further if you are selected for an interview.
If eligible, positions located in New York City will receive an additional $3,400 downstate adjustment location pay with regular annual salary. Positions located in the Mid-Hudson will receive an additional $1,650 adjustment location pay.
to permanent non-competitive and the official probationary period will begin.
Benefits of Working for NYS Generous benefits package, worth 65% of salary, including:
Holiday & Paid Time Off
• Thirteen (13) paid holidays annually
• Up to Thirteen (13) days of paid vacation leave annually
• Up to Five (5) days of paid personal leave annually
• Up to Thirteen (13) days of paid sick leave annually for PEF.
• Up to three (3) days of professional leave annually to participate in professional development
Health Care Benefits
• Eligible employees and dependents can pick from a variety of affordable health insurance programs
• Family dental and vision benefits at no additional cost
Additional Benefits
• New York State Employees’ Retirement System (ERS) Membership
• NYS Deferred Compensation
• Access to NY 529 and NY ABLE College Savings Programs, as well as U.S. Savings Bonds
• Public Service Loan Forgiveness (PSLF)
• And many more.
The Office of Information Technology Services is an equal opportunity employer, and we recognize that diversity in our workforce is critical to fulfilling our mission. We encourage all individuals with disabilities to apply.
Some positions may require additional credentials or a background check to verify your identity.
Email Address PostingResponses@its.ny.gov
Address
Notes on ApplyingTo apply for this position, please submit a cover letter and resume clearly indicating how you qualify. Ensure that you include the vacancy ID in the subject of your email for prompt routing. Your Social Security number may be required to confirm eligibility.
