Cybersecurity Engineer Level 4 - PAM
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Systems Engineer
Description
JOB TITLE:
Cybersecurity Engineer Level 4
SALARY RANGE: $105,843 - $143,948
DEPT/DIV:
Information Technology
SUPERVISOR:
Cyb Sec Off Mgr Acces Mgmt Ident Sec
LOCATION:
2 Broadway, New York, NY 10004
HOURS OF WORK: 9:00 am - 5:30 pm (7.5 hours/day) or as required
This position is eligible for teleworking, which is currently one day per week. New hires are eligible to apply 30 days after their effective date of hire.
OpeningThe Metropolitan Transportation Authority is North America's largest transportation network, serving a population of 15.3 million people across a 5,000-square-mile travel area surrounding New York City, Long Island, southeastern New York State, and Connecticut. The MTA network comprises the nation’s largest bus fleet and more subway and commuter rail cars than all other U.S. transit systems combined. MTA strives to provide a safe and reliable commute, excellent customer service, and rewarding opportunities.
Job SummaryThe purpose of this position is to provide technical expertise in managing and analyzing cybersecurity risks. Cybersecurity Engineer will be responsible for designing, building, and maintaining infrastructure and applications technology to support a secure cybersecurity posture. These include systems that support cybersecurity directly and/or the business operations for Information and Operational Technology disciplines. Secure building and configuration of systems (applications, infrastructure, wireless, carrier systems, cloud, operational technology, IOT, etc.)
from the outset reduces risk to MTA. Specialized and focused skill sets in various technology domains assist with the overall risk reduction for the MTA. The configuration, hardening, guidance, response, and analysis of these systems aid in the reduction and containment of Cyber Security risk. Risk assessments, data analytics tools, operational process reviews, and collaboration with security engineers, architects, developers, vendors, and business units to constantly improve the overall security of the MTA.
Skills
- Hands-on PAM platform engineering: privileged account vaulting, session management, credential rotation, and access request workflow configuration
- Experience with Privileged Identity Management (PIM) and Just-in-Time (JIT) access design and implementation, including approval workflows and time-bound elevation
- Tiered administration models (Tier 0–5): designing and enforcing privileged access controls, admin account separation, and secure administrative paths
- Knowledge of service account and non-human identity security: discovery, vaulting, rotation, and remediation coordination
- Strong experience with endpoint privilege management: least-privilege enforcement, elevation controls, and local admin removal
- Knowledge of operational support and troubleshooting of privileged access issues, including escalations and platform break/fix Integration of PAM with directory, MFA, SSO, and ITSM platforms
- Experience with infrastructure, OT, and application teams on remediation, while maintaining PAM ownership boundaries
- Researching emerging threats and vulnerabilities to aid in the identification of network incidents, and supporting the creation of new architecture, policies, standards, and guidance to address them
- Knowledge and practical implementation of secure system configuration and hardening standards
- Design, configure, and integrate secure solutions in the technology domains assigned
- Provide incident response support, including mitigating actions to contain activity and facilitating forensic analysis, system hardening, and recovery when necessary
- Provides installation, system configuration, hardening, and optimization for infrastructure, application, and security components…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).