NYC Parks Arsenal West Logo

NYC Parks Arsenal West

Chief Information Security Officer

Posted 3 Days Ago
Be an Early Applicant
In-Office
Corona, NY, USA
84K-220K Annually
Mid level
In-Office
Corona, NY, USA
84K-220K Annually
Mid level
Leads DEP’s cybersecurity strategy and program across IT and OT environments. Responsibilities include managing security professionals, incidents, vulnerabilities, policies, compliance with New York cybersecurity regulations, risk reporting, audits, security architecture, threat monitoring, critical-response processes, backup strategies, and cybersecurity budgets. The CISO advises executives and technology teams, protects critical infrastructure, and coordinates with NYC Cyber Command and oversight agencies.
The summary above was generated by AI
Job Description

The NYC Department of Environmental Protection (DEP) enriches the environment and protects public health for all New Yorkers by providing 1.1 billion gallons of high-quality drinking water, managing wastewater and stormwater, and reducing air, noise, and hazardous materials pollution. DEP is the largest combined municipal and wastewater utility in the country, with nearly 6,000 employees. DEP's water supply system is comprised of 19 reservoirs and 3 controlled lakes throughout the system’s 2,000 square mile watershed that extends 125 miles north and west of the city.
The New York City Department of Environmental Protection (NYC DEP) Business Information Technology (BIT) division is responsible for providing quality business, technical, and information technology system support to agency users. This commitment is achieved through collaboration, strong relationships, and a unified vision with DEP partners to deliver technology solutions that support the agency’s operational needs. Providing these services ensures that DEP continues its tradition of delivering excellent service to the residents of New York City.
Reporting to the Chief Information Officer (CIO), the Business Information Technology team seeks to hire a Chief Information Security Officer (CISO). Responsibilities include cybersecurity strategy, architecture, solutions design, program coordination and execution, awareness and outreach, business management, and reporting on the effectiveness of the information security program. This position requires a seasoned leader with strong business acumen and a detailed working knowledge of information security technologies, practices, and policies and their application in a business environment. The CISO will research and recommend innovative solutions and improvements to existing procedures. The CISO is an implementer who possesses the poise and ability to act calmly and competently in high-pressure situations. This role is responsible for developing and managing strong strategic relationships within Information Technology (IT) and ensuring that projects, initiatives, and security platforms meet all required security standards.
Under varying levels of executive direction, with latitude for independent initiative, judgment, and decision making, the selected candidate will develop and implement the organization’s information security strategy to protect data and systems from cyber threats. The CISO will safeguard information system assets by identifying security risks, threats, and vulnerabilities affecting networks, systems, and applications across new and existing technology initiatives, the selected candidate will evaluate high-level information technology initiatives and provide technical guidance to ensure compliance with security policies, standards, and guidelines. Responsibilities include developing, implementing, enforcing, and communicating security policies and plans covering data, software applications, hardware, and telecommunications systems.
The role requires in-depth knowledge of Internet Protocol (IP) networking and networking protocols, along with security technologies including encryption, Internet Protocol Security (IPsec), Public Key Infrastructure (PKI), Virtual Private Networks (VPNs), firewalls, proxy services, Domain Name System (DNS), electronic mail systems, privileged access management, and access lists. Experience with Operational Technology (OT) networks and Supervisory Control and Data Acquisition (SCADA) environments is also required.
The candidate will serve as a recognized subject matter expert in internet, web, application, and network security engineering, including vulnerability assessments, network scanning, and threat surface analysis. The role also requires advanced knowledge of cloud service security models and enterprise data protection strategies, including backup architecture, disaster recovery planning, and business continuity frameworks.
The candidate will oversee the system’s cybersecurity program and also support the new NYS Cybersecurity requirements for water and wastewater.
The candidate must have:
-Proven knowledge of core cybersecurity principles, including the ability to understand, interpret, and apply cybersecurity policies, standards, and regulatory requirements.
-Practical, hands-on experience in system protection or risk management, demonstrating the ability to identify security risks, evaluate vulnerabilities, and support incident response activities.
-Experience implementing or supporting cybersecurity programs in environments involving critical infrastructure, public utilities, operational technology (OT), or similar high-risk systems.
-The capability to serve as the responsible authority for developing, maintaining, and ensuring compliance with the system’s cybersecurity program.
Essential Job Functions:
- Lead the development, coordination, and submission of materials required to maintain compliance with the New York State Cybersecurity Regulations for Public Water Systems.
- Manage and direct a team of information technology security professionals, providing leadership, guidance, and support.
- Manage cybersecurity incidents and attacks in coordination with the team and oversight agencies such as New York City Cyber Command (NYC Cyber Command).
- Track cyber security incidents and vulnerability reports, direct teams for remediation of issues.
- Design a critical response process for cyber security incidents.
- Continuously monitor threats to DEP’s information technology (IT) and operational technology (OT) environments.
- Develop cybersecurity Key Risk Indicators (KRIs) and dashboard metrics for reporting.
- Develop and document cybersecurity policies, procedures, and standards in alignment with Citywide Information Security Policies.
- Coordinate air-gapped backup strategies with agency business units.
- Participate in annual financial and technology audits for the agency.
- Examine computer systems to ensure secure operation and protection of data from internal and external threats.
- Perform security assessments to ensure compliance with security policies, procedures, and industry standards.
- Monitor, evaluate, and maintain security systems according to industry best practices to safeguard internal systems and databases.
- Assist with the review and definition of security requirements and evaluate systems for compliance with established standards.
- Investigate security violations and breaches and prepare reports on incidents and intrusions as required.
- Review and assess firewall logs and configure firewalls, intrusion detection systems, and other network security devices.
- Work with other BIT teams to design and implement cybersecurity solutions across DEP infrastructure, networks, and systems.
- Develop necessary budget analysis and related documentation for annual submissions of budget for cyber-security related solutions.
EXECUTIVE PROGRAM SPECIALIST ( - 13393

Qualifications

1. A bachelor’s degree from an accredited college and 4 years of satisfactory experience of a nature to qualify for the duties and responsibilities of the position, at least 18 months of which must have been in an administrative, managerial, consultative, or executive capacity or supervising personnel performing activities related to the duties of the position; or 2. A combination of education and/or experience equivalent to "1" above. However, all candidates must have the 18 months of administrative, managerial, executive, consultative or supervisory experience described in "1" above.

Additional Information

The City of New York is an inclusive equal opportunity employer committed to recruiting and retaining a diverse workforce and providing a work environment that is free from discrimination and harassment based upon any legally protected status or protected characteristic, including but not limited to an individual's sex, race, color, ethnicity, national origin, age, religion, disability, sexual orientation, veteran status, gender identity, or pregnancy.

HQ

NYC Parks Arsenal West New York, New York, USA Office

New York, NY, United States

NYC Parks Arsenal West Flushing, New York, USA Office

Flushing, United States, 0

NYC Parks Arsenal West New York, New York, USA Office

New York, United States, 0

NYC Parks Arsenal West New York, New York, USA Office

New York, United States

NYC Parks Arsenal West New York, New York, USA Office

New York, United States, 0

NYC Parks Arsenal West Queens, New York, USA Office

Queens, United States

Similar Jobs

One Month Ago
Hybrid
2 Locations
550K-650K Annually
Senior level
550K-650K Annually
Senior level
Legal Tech
The Chief Information Security Officer leads DLA Piper’s enterprise cybersecurity strategy, governance, risk management, incident response, data protection, third-party security, security awareness, and operational resilience programs. The role advises executives and governance bodies, oversees security controls and emerging technology risk, translates technical risks into business and legal impacts, and builds a high-performing global information security organization. The CISO also manages security policies, audits, regulatory and client obligations, vendor oversight, budgets, talent development, and executive communications.
Top Skills: Ai SdlcCis ControlsCloudData Loss PreventionDevsecopsEmail SecurityEncryptionEndpoint ProtectionIdentity And Access ManagementIso/Iec 27001Logging And MonitoringNistZero Trust Architecture
One Month Ago
In-Office
New York, NY, USA
100K-180K Annually
Senior level
100K-180K Annually
Senior level
Agency
Lead FDNY's information security strategy, manage risk and compliance (e.g., GDPR, ISO 27001), direct incident response, develop policies, lead security team, and promote security awareness across the organization.
Top Skills: Enterprise ArchitectureGdprIso 27001It InfrastructureNetwork ArchitectureSolutions Architecture
One Month Ago
Hybrid
New York City, NY, USA
270K-320K Annually
Expert/Leader
270K-320K Annually
Expert/Leader
Fintech • Software • Financial Services
Lead and execute the firms cybersecurity and operational risk programs, including AI security strategy, incident response, vendor security, compliance (SEC/FINRA/SOC2), secure architecture, and day-to-day security operations. Partner with executives, oversee audits and certifications, and build security awareness across the organization while remaining hands-on with tooling, design reviews, and threat management.
Top Skills: Ai/Ml SecurityCis ControlsCloud SecurityDetection EngineeringEncryptionEndpoint ProtectionIso 27001Network SecurityNistPenetration TestingSecurity MonitoringSoc 2Threat HuntingVulnerability Management

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account