Information Systems Security Compliance Manager

NYSTEC

City of Rome, Northern (NY, KY)

Hybrid

USD 126,000 - 167,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

NYSTEC, a nonprofit technology consulting company, is seeking an Information Systems Security Compliance Manager in Rome, NY.

You will assist the deputy CISO, lead the governance, risk, and compliance program, and implement security controls across the enterprise to meet CMMC, HIPAA/HITRUST, and regulatory requirements.

This hybrid role requires coordinating with staff and partners, overseeing audits and remediation, and guiding security initiatives while balancing risk and productivity.

Qualifications

  • Knowledge of IT goals and objectives.
  • Knowledge of laws, policies, and governance frameworks for cybersecurity.
  • Proficiency with Windows, Office, email, and internet tools.
  • Experience in information security with developing and supporting standards.
  • Experience with security technologies: firewalls, IDS, DMZs, IPS, DNS, SMTP, HTTP proxies.
  • Knowledge of security best practices across Windows, Windows 365, Cisco IOS.
  • Project management to coordinate priorities and multiple tasks.
  • Strong written and verbal communication, time management, and organization.
  • Experience with GRC tools to document risks, incidents, and controls.

Responsibilities

  • Lead and develop the information security team and set priorities.
  • Oversee governance, risk, and compliance program including policies, standards, controls, risk management, and compliance processes.
  • Ensure compliance with CMMC, HIPAA/HITRUST, and state and federal regulations.
  • Translate evolving regulatory requirements into security controls and practices.
  • Advise Deputy CISO and senior leadership on cybersecurity risk and posture.
  • Oversee security audits, remediation, and ongoing compliance monitoring.
  • Partner with business/technical leaders to integrate security into initiatives.
  • Provide leadership for enterprise security initiatives and incident response.
  • Work in a hybrid model with on-site presence two days per week.

Skills

IT goals & objectives
Laws & governance
Windows & Office
Information security
Security technologies
GRC tools
Project management
Communication skills
Security frameworks

Education

Bachelor's degree in cybersecurity
Advanced education/experience equivalence

Tools

Hyperproof

Job description

Information Systems Security Compliance Manager

Job Category: Management

Requisition Number: INFOR001257

  • Full-Time
  • Hybrid
Locations

Showing 1 location

Rome, NY 13441, USA

  • Pay or shift range: $126,085 USD to $167,062.50 USD
Description
About Us:

NYSTEC is a nonprofit technology consulting company, advising agencies, organizations, institutions, and businesses since 1996. We’re independent and vendor-neutral, so we have our clients’ best interests at heart. At NYSTEC, we know that we succeed when individuals and teams flourish personally and professionally, so our benefits and perks support that mindset.

About the Role:

As an information systems security compliance manager in the Corporate Information Security practice area, you will assist the deputy chief information security officer (CISO) in administering the overall strategy, design, and implementation of information security initiatives on a company-wide basis. This position will interface with staff and management across all levels of NYSTEC, as well as with external business partners, to ensure that NYSTEC’s critical business functions and systems are secure and in accordance with best practices.

Serving as an information systems security compliance manager, your day-to-day role will include executing all information security functions for the company in keeping with a perspective to mitigate risk and to balance enhanced capacity and productivity.

Key Responsibilities
  • Lead and develop the information security team, establishing priorities and goals while supporting staff performance and professional development.
  • Oversee NYSTEC’s governance, risk, and compliance program, including security policies, standards, controls, risk management, and compliance processes
  • Ensure compliance with applicable security frameworks and requirements, including Cybersecurity Maturity Model Certification (CMMC), HIPAA/HITRUST, and state and federal regulations.
  • Interpret evolving regulatory, industry, and contractual requirements and translate them into appropriate security controls and practices.
  • Advise the Deputy CISO and senior leadership on cybersecurity risk, security posture, emerging issues, and potential business impacts.
  • Oversee security audits and assessments, including control effectiveness, findings, remediation activities, and ongoing compliance monitoring.
  • Partner with business and technical leaders to integrate security and data protection requirements into technology, processes, and organizational initiatives.
  • Provide leadership and oversight for enterprise security initiatives, including technical projects, security controls, and response to significant incidents and vulnerabilities
  • This role follows a hybrid work model, with an expectation of working on-site two days per week.
About you:
Required Qualifications
  • Knowledge of the organization’s enterprise information technology (IT) goals and objectives.
  • Knowledge of laws, policies, procedures, and governance frameworks relevant to organizational cybersecurity requirements.
  • Proficiency with Windows operating environments, Microsoft Office applications, email, and internet-based tools.
  • Experience in information security, including developing, documenting, and supporting the adoption of information security standards and procedures.
  • Experience with security technologies and protocols, such as firewalls, intrusion detection systems, demilitarized zones (DMZs), Internet Protocol Security (IPSec), Domain Name System (DNS), Simple Mail Transfer Protocol (SMTP), and Hypertext Transfer Protocol (HTTP) proxies.
  • Knowledge of security best practices across multiple platforms, such as Microsoft Windows, Microsoft 365, and Cisco Internetwork Operating System (IOS).
  • Project management skills, including the ability to coordinate priorities and manage multiple tasks.
  • Effective written and verbal communication, time-management, and organizational skills.
  • Experience with governance, risk, and compliance (GRC) tools, such as Hyperproof or similar platforms, to document risks, security exceptions, security incidents, policies, standards, and control procedures.
Preferred/Desired Qualifications
  • Certified information systems security professional (CISSP) or similar certification in information security preferred.
Education and Experience
  • A bachelors degree in cybersecurity or a similar discipline and ten years of related experience in security management frameworks (e.g., National Institute of Standards and Technology [NIST], SysAdmin, Audit, and Network and Security [SANS]).
  • An equivalent combination of advanced education, training, and experience will be considered.

The target base salary for this position is $129,085.00to $167,062.00 per year. When determining compensation, we analyze and carefully consider several factors, including skill set, experience, location, and job-related qualifications.

It is NYSTEC's policy to provide equal employment opportunity (EEO) to all individuals, regardless of actual or perceived race, color, creed, religion, sex, or gender (including pregnancy, childbirth, and related medical conditions), gender identity or gender expression (including transgender status), age, national origin, ancestry, citizenship status, physical or mental disability, protected medical condition as defined by applicable state or local law, genetic information, military service and veteran status, sexual orientation, marital status, or any other characteristic protected by local, state, or federal laws and ordinances. NYSTEC is strongly committed to this policy and believes in the concept and spirit of the law.

Federal law requires employers to provide reasonable accommodation to qualified individuals with disabilities. Please contact recruitment@nystec.com if you require a reasonable accommodation to apply for or to perform this job. Examples of reasonable accommodation include making a change to the application process or work procedures, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.

Applicants must be authorized to work in the United States without the need for visa sponsorship now or in the future.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Consultant - Technical Project Manager
Senior Consultant - Technical Project Manager

NYSTEC • City of Albany (NY), Northern (KY)

On-site
USD 84,000 - 110,000
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

Cymertek Corporation • Aurora (CO)

On-site
USD 130,000 - 170,000
Excellent Salaries
Flexible Work Schedule
Cafeteria Style Benefits
+3
Information Systems Security Manager
Information Systems Security Manager

Kranze Technology Solutions, Inc. • Des Plaines (IL)

On-site
USD 100,000 - 150,000
Paid Time Off
Health Care package
401(k) retirement plan
+2
Manager, Security Compliance
Manager, Security Compliance

CardWorks Servicing LLC • United States

On-site
USD 128,490 - 142,767
Competitive pay
Medical, Dental, and Vision coverage
401(k) Plan with Company Match
+1
Information System Security Officer
Information System Security Officer

Cymertek Corporation • San Antonio (TX)

On-site
USD 110,000 - 150,000
Excellent Salaries
Flexible Work Schedule
401k Matching
+2
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

Cymertek Corporation • Maryland

On-site
USD 120,000 - 180,000
Excellent Salaries
Flexible Work Schedule
401k Matching
+3
ISSE / ISSO - multiple levels - FULLY CLEARED with POLYGRAPH REQUIRED
ISSE / ISSO - multiple levels - FULLY CLEARED with POLYGRAPH REQUIRED

Constellation Technologies, Inc • Columbia (MD)

On-site
USD 120,000 - 180,000
Healthcare
Dental Insurance
Vision Insurance
+5
ISSE / ISSO - multiple levels - FULLY CLEARED with POLYGRAPH REQUIRED
ISSE / ISSO - multiple levels - FULLY CLEARED with POLYGRAPH REQUIRED

Constellation Technologies, Inc • Hanover (MD)

On-site
USD 120,000 - 180,000
Healthcare options
HSA funding
Dental insurance
+5
Senior Cybersecurity Compliance Consultant (US Remote)
Senior Cybersecurity Compliance Consultant (US Remote)

Intelligent Technical Solutions • Washington

Remote
USD 95,000 - 120,000
Medical Insurance Plan
Dental & Vision
Retirement Plan
ISSE / ISSO - multiple levels - FULLY CLEARED with POLYGRAPH REQUIRED
ISSE / ISSO - multiple levels - FULLY CLEARED with POLYGRAPH REQUIRED

Constellation Technologies, Inc • Laurel (MD)

On-site
USD 120,000 - 180,000
Affordable healthcare
Dental insurance
Vision insurance
+6