Stand out for this role — generate a tailored resume and cover letter in about a minute.
The New York City Department of Environmental Protection (DEP) seeks a Chief Information Security Officer (CISO) to lead cybersecurity strategy, architecture, and governance across IT and OT. The role focuses on protecting data, networks, and critical infrastructure, with oversight of incident response and regulatory compliance.
Reporting to the CIO, the CISO will manage a team, develop policies, and coordinate with agencies like NYC Cyber Command.
The NYC Department of Environmental Protection (DEP) enriches the environment and protects public health for all New Yorkers by providing 1.1 billion gallons of high-quality drinking water, managing wastewater and stormwater, and reducing air, noise, and hazardous materials pollution. DEP is the largest combined municipal and wastewater utility in the country, with nearly 6,000 employees. DEP's water supply system is comprised of 19 reservoirs and 3 controlled lakes throughout the system’s 2,000 square mile watershed that extends 125 miles north and west of the city.
The New York City Department of Environmental Protection (NYC DEP) Business Information Technology (BIT) division is responsible for providing quality business, technical, and information technology system support to agency users. This commitment is achieved through collaboration, strong relationships, and a unified vision with DEP partners to deliver technology solutions that support the agency’s operational needs. Providing these services ensures that DEP continues its tradition of delivering excellent service to the residents of New York City.
Reporting to the Chief Information Officer (CIO), the Business Information Technology team seeks to hire a Chief Information Security Officer (CISO). Responsibilities include cybersecurity strategy, architecture, solutions design, program coordination and execution, awareness and outreach, business management, and reporting on the effectiveness of the information security program. This position requires a seasoned leader with strong business acumen and a detailed working knowledge of information security technologies, practices, and policies and their application in a business environment. The CISO will research and recommend innovative solutions and improvements to existing procedures. The CISO is an implementer who possesses the poise and ability to act calmly and competently in high-pressure situations. This role is responsible for developing and managing strong strategic relationships within Information Technology (IT) and ensuring that projects, initiatives, and security platforms meet all required security standards.
Under varying levels of executive direction, with latitude for independent initiative, judgment, and decision making, the selected candidate will develop and implement the organization’s information security strategy to protect data and systems from cyber threats. The CISO will safeguard information system assets by identifying security risks, threats, and vulnerabilities affecting networks, systems, and applications across new and existing technology initiatives, the selected candidate will evaluate high-level information technology initiatives and provide technical guidance to ensure compliance with security policies, standards, and guidelines. Responsibilities include developing, implementing, enforcing, and communicating security policies and plans covering data, software applications, hardware, and telecommunications systems.
The role requires in-depth knowledge of Internet Protocol (IP) networking and networking protocols, along with security technologies including encryption, Internet Protocol Security (IPsec), Public Key Infrastructure (PKI), Virtual Private Networks (VPNs), firewalls, proxy services, Domain Name System (DNS), electronic mail systems, privileged access management, and access lists. Experience with Operational Technology (OT) networks and Supervisory Control and Data Acquisition (SCADA) environments is also required.
The candidate will serve as a recognized subject matter expert in internet, web, application, and network security engineering, including vulnerability assessments, network scanning, and threat surface analysis. The role also requires advanced knowledge of cloud service security models and enterprise data protection strategies, including backup architecture, disaster recovery planning, and business continuity frameworks.
The candidate will oversee the system’s cybersecurity program and also support the new NYS Cybersecurity requirements for water and wastewater.
The candidate must have:
Essential Job Functions:
EXECUTIVE PROGRAM SPECIALIST ( - 13393
1. A bachelor’s degree from an accredited college and 4 years of satisfactory experience of a nature to qualify for the duties and responsibilities of the position, at least 18 months of which must have been in an administrative, managerial, consultative, or executive capacity or supervising personnel performing activities related to the duties of the position; or 2. A combination of education and/or experience equivalent to "1" above. However, all candidates must have the 18 months of administrative, managerial, executive, consultative or supervisory experience described in "1" above.
As a prospective employee of the City of New York, you may be eligible for federal loan forgiveness programs and state repayment assistance programs. For more information, please visit the U.S. Department of Education’s website at https://studentaid.gov/pslf/
New York City residency is generally required within 90 days of appointment. However, City Employees in certain titles who have worked for the City for 2 continuous years may also be eligible to reside in Nassau, Suffolk, Putnam, Westchester, Rockland, or Orange County. To determine if the residency requirement applies to you, please discuss with the agency representative at the time of interview.
The City of New York is an inclusive equal opportunity employer committed to recruiting and retaining a diverse workforce and providing a work environment that is free from discrimination and harassment based upon any legally protected status or protected characteristic, including but not limited to an individual's sex, race, color, ethnicity, national origin, age, religion, disability, sexual orientation, veteran status, gender identity, or pregnancy.