Manager Information Technology Services Infomation Security
Listed on 2026-01-01
-
IT/Tech
Cybersecurity, IT Consultant
Location: New York
Duties Description Under the direction of senior leadership within the Office of Information Technology Services Chief Information Security Office Cyber Command Center, the incumbent will serve as Senior Security Operations Center (SOC) Use Case and Content Developer and be responsible for creation of procedures, implementation of processes and development of Use Cases and Contents for managing and maintaining NYSOC systems. The candidate will work closely with management, analysts, and threat intelligence team to create SIEM rules and analytic tool automations to improve event monitoring and response.
The incumbent will lead the development of use cases, rules, log source, application maintenance and updates. The candidate will collaborate with internal and external teams on SIEM functional requirements: logging, event collection, normalization, correlation, storage, system access, reporting, and customization.
This position requires the incumbent to possess a solid understanding of the current cyber threat landscape, the tactics, techniques, tools, and procedures commonly leveraged, and the steps necessary to swiftly identify and contain a potential cyber threat. Additionally, this position requires an incumbent to act with a great deal of independence in alignment with agency and upper-level management strategic direction.
Due to the nature of the work performed by the SOC, this position requires availability during off-shift hours to ensure appropriate response to security incidents or other critical activities as needed. This position is available and can be filled in any of the following NYSOC locations:
Latham, Rochester, or New York City. Additional information on work schedule will be discussed at time of interview.
If eligible, positions located in New York City will receive an additional $3,400 downstate adjustment location pay with regular annual salary. Positions located in the Mid-Hudson will receive an additional $1,650 adjustment location pay.
to permanent non-competitive and the official probationary period will begin.
- The Senior Use Case and Content Developer will work closely with management, analysts, and threat intelligence team to create SIEM rules and analytic tool automations to improve event monitoring and response.
- Work with internal and client ticketing and knowledge base systems for Incident and Problem tracking as well as procedures.
- Monitor the SIEM and Incident Management systems performance.
- Develop use cases, rules, log source, application maintenance and updates
- Provide training to other technical staff members
- Configure custom log sources for SOC applications, and management
- Collaborate with internal and external teams on SIEM functional requirements: logging, event collection, normalization, correlation, storage, system access, reporting, and customization
- Coordinate change management processes for testing and validating systems to production
- Review log sources, alerts, and integrations for auditing
- Conduct research, analysis, and correlation across a wide variety of SOC processes, procedures, and use cases
- Review cases escalated by SOC analysts to investigate, contain and remediate
- Plan and recommend modifications or adjustments based on testing results or system environment
- Identify new use cases and playbooks that need to be developed based on incident reviews
- Document and elevate incidents using information gathered from a variety of sources
- Create technical reports and executive summaries related to cyber security incidents and events.
- Provide guidance and input on active projects to help identify and resolve issues/problems to ensure successful outcomes are achieved
- May supervise subordinate staff in the proper performance of their duties and perform the full range of administrative supervisory responsibilities.
Minimum Qualifications Non-competitive:
Seven years of information technology, cybersecurity, or information assurance experience*, including one year at the supervisory level.
* Substitutions:
A bachelor’s or higher-level degree in any field including or supplemented by 15 semester credit hours in computer science…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).