×
Register Here to Apply for Jobs or Post Jobs. X

Information Security Manager - Rochester

Job in Rochester, Monroe County, New York, 14604, USA
Listing for: StateJobsNY
Full Time position
Listed on 2026-09-03
Job specializations:
  • IT/Tech
    Cybersecurity, IT Project Manager, IT Consultant, Information Security & Data Protection
Job Description & How to Apply Below
Position: Information Security Manager - 20001Rochester

Director Of Cyber Risk Management

ITS provides operational support to state agencies on a 24x7x365 basis; some positions may be required to provide this critical service at any time.

Under the direction of a Deputy Chief Information Security Officer within the Chief Information Security Office (CISO) the incumbent will serve as the Director of the Cyber Risk Management (CRM) bureau, providing oversight of the Vulnerability Management, Threat Response, and Cyber Process Improvement & Metrics sections. The CRM Bureau is responsible for the oversight and operations of a variety of security tools and response functions to help ensure optimal cybersecurity protections, identification and remediation of vulnerabilities, and cyber risk reduction for ITS and its client agencies.

The CRM bureau is also responsible for driving process improvement and developing metrics for the CISO division, as well as managing development and oversight of the Government Risk and Compliance (GRC) platform. The incumbent will provide direction and support for all activities and staff within the bureau, as well as subject matter expertise on vulnerability management and response, security program metrics, and process improvement.

The incumbent will act as a member of the Chief Information Security Office Leadership Team, helping shape and implement the strategic vision for cyber security within NYS.

The position requires an incumbent to act with a great deal of independence in alignment with agency and upper-level management strategic direction. The position requires communicating orally and in writing with various individuals including management, users, vendors, and other IT staff. The incumbent must be able to communicate clearly with subordinate staff regarding work priorities and performance. The incumbent will have to work with various teams and stakeholders to resolve technically complex and politically sensitive issues under pressure.

The position requires availability during off-shift hours to ensure appropriate response to security incidents or other critical activities that may impact sensitive information, critical systems, NYS agencies, or ITS.

Specific duties include, but are not limited to:

  • Lead and direct all the activities within the Cyber Risk Management (CRM) bureau across multiple managers.
  • Responsible for the overall vision and direction of the CRM bureau, including the development of strategic plans to revise and improve upon the bureau's work, drafting staffing plans, and the maintenance and development of charters, product catalogues, RACI charts, and other documentation.
  • Oversee the development and maturation of the threat and vulnerability response process, helping CISO to reduce cyber risk by efficiently prioritizing and responding to significant vulnerabilities and emerging cyber threats.
  • Oversee the team responsible for the GRC Platform and the CISO SharePoint site, including development, configurations, development, and maintenance through formalized tracking and release management.
  • Oversee the development and maturation of the CISO Metrics Program, including collecting and displaying various data points for stakeholders through reports and dashboards.
  • Oversee the creation of a vulnerability disclosure program to receive and triage vulnerabilities identified by security researchers.
  • Provide guidance on cyber risk management best practices and strategies for risk identification and remediation to support the development and improvement of the agency's GRC platform.
  • Provide leadership, guidance, and subject matter expertise across all teams within CRM.
  • Serve as an information security expert and ensure technology contracts adhere to NYS Security Policies and standards and align with the strategic direction of ITS and CISO.
  • Monitor and remain aware of information security industry trends, tools, and techniques.
  • Ensure that all communications, processes, and teams within CRM are done in consideration of the operational concerns and workloads of peer teams throughout CISO and ITS, and that staff maintain the collaborative attitude and open communications required to successfully carry out the mission of CISO and ITS.
  • Evaluate high-impact initiatives, monitor ongoing progress, and execute corrective strategies as needed
  • Mentor and supervise staff in the proper performance of their duties.
  • Perform additional duties as required.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary