Please note: State agencies that contact job applicants do not usually request personal or financial information via text message or over the phone in connection with your response to a job posting. If you are contacted for such information by these methods, or any other method, please verify the identity of the individual before transmitting such information to that person.
Note: For questions about the job posting, please contact the agency that posted this position by using the contact information provided on the "Contact" tab for the position.

Review Vacancy

Date Posted 09/28/21

Applications Due12/31/21

Vacancy ID91916

AgencyInformation Technology Services, Office of

TitleNYS Chief Information Security Officer (NYS Deputy Chief Information Officer), #00025

Occupational CategoryAdministrative or General Management

Salary GradeNS

Bargaining UnitM/C - Management / Confidential (Unrepresented)

Salary RangeFrom $137883 to $173431 Annually

Employment Type Full-Time

Appointment Type Permanent

Jurisdictional Class Exempt Class

Travel Percentage 0%

Workweek Mon-Fri

Hours Per Week 37.50


From 9 AM

To 5 PM

Flextime allowed? No

Mandatory overtime? No

Compressed workweek allowed? No

Telecommuting allowed? No

County Albany

Street Address Empire State Plaza, Swan St. Building

Core 4, Flr 5

City Albany


Zip Code12220

Minimum Qualifications Bachelor’s degree* and 10 years of progressive experience in information technology, including 6 years of information security or information assurance experience, with at least 4 years in an information technology management position.

*Appropriate information security or information assurance experience may substitute for the bachelor’s degree on a year-for-year basis; an associate degree requires an additional two years of information technology, information security, or information assurance experience. Experience solely in information security or information assurance may substitute for the general information technology experience.

Preferred Qualifications

• Professional certifications such as Certified Information Systems Security Professional (CISSP), GIAC Strategic Planning, Policy & Leadership (GSTRT), GIAC Security Leadership (GSLC), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA).
• Excellent interpersonal, written, and verbal communications skills.
• Excellent analytical and problem-solving skills
• Experience presenting to executives and leadership teams, with the ability to communicate security and risk-related concepts.

Duties Description The Chief Information Security Officer will direct the Chief Information Security Office (CISO) within the NYS Office of Information Technology Services (ITS) to ensure the confidentiality, integrity, and availability of the State’s information assets. The CISO leads the development and implementation of security policies and ensures compliance and governance of ITS’ comprehensive enterprise information security and risk management program. This includes providing advisement on a broad range of information security mandates and standards, and guiding the application of industry-recommended practices, including alignment to the National Framework for Improving Critical Infrastructure Cybersecurity, to improve the State’s existing cybersecurity program. In addition, the CISO provides leadership and oversight to the NYS Cyber Command Center which includes event and threat analysis, digital forensics, red team testing and incident response.

Duties include, but are not limited to:

• Develop, maintain, and assure information security and risk management program governance, and compliance with policies, standards, protocols and best practices and create and facilitate cyber security risk assessment processes, including oversight and reporting on remediation efforts.
• Collaborate with ITS executive management to identify and understand the information assets that support critical business functions and assess and strategize to manage related cybersecurity risks in a manner consistent with the State’s overall cybersecurity risk management program and business objectives.
• Direct information security risk management initiatives across IT, advising executive management on cybersecurity risk and acceptable risk tolerances, ensuring protection and compliance with regulatory requirements.
• Manage detection activities and provide advisement on cyber security threats and vulnerabilities; direct the development and implementation of appropriate safeguards to ensure system resiliency, protect critical infrastructure services, and detect, contain, and respond to cybersecurity incidents.
• Oversee enterprise incident response, and coordinate efforts to restore and recover from events that may negatively affect information, systems, and critical infrastructure that support State business functions.
• Direct the development of effective information security awareness training programs for employees, contractors, and users, and facilitate cyber preparedness exercises involving business, technical and partner representatives.
• Provide routine updates on cyber risks, incidents and priority initiatives, and work with executive management to prioritize initiatives and spending to reduce cybersecurity risk and improve the overall information security program.
• Maintain collaborative internal and external information sharing partnerships to assure the State has timely and actionable cyber intelligence regarding threats, incidents, response strategies and solutions (e.g., Multi-State Information Sharing and Analysis Center, NYS Cyber Intelligence Center (Fusion Center), Federal Bureau of Investigation, U.S. Department of Homeland Security and State Department of Homeland Security and Emergency Service, and state and local agencies).
• Direct the CISO’s participation/integration as it pertains to ITS strategic planning, transformation initiatives, enterprise architecture and operations; procurement of services and solutions, secure system architecture, evaluation of security controls, configuration, and maintenance; enterprise security budget proposals; monitoring and reporting on spending; procuring and managing contracts related to managed security services; and performance metrics.
• Perform full range of supervisory responsibilities.

Additional Comments This posting will remain up until position is filled.

Some positions may require additional credentials or a background check to verify your identity.

Name Louise Nails

Telephone (518) 473-5282

Fax (518) 402-4924

Email Address


Street Empire State Plaza, Human Resources Management

Corning Tower, Floor 26

City Albany

State NY

Zip Code 12220


Notes on ApplyingPlease submit a clear, concise cover letter and resume to the attention of Louise Nails indicating you are applying for NYS Chief Information Security Officer, Ref. #00025, describing how you qualify to:, or mail to:

Louise Nails
NYS Office of General Services
Empire State Plaza
Corning Tower, Floor 26
Albany, NY 12220

Printable Version