Chief Information Security Officer

City of New York•New York, NY
•$83,718 - $220,000

About The Position

The NYC Department of Environmental Protection (DEP) is seeking a Chief Information Security Officer (CISO) to lead its cybersecurity strategy, architecture, solutions design, program coordination, and execution. Reporting to the Chief Information Officer (CIO), this role is crucial for protecting the agency's data and systems from cyber threats. The CISO will be responsible for developing and implementing the organization’s information security strategy, safeguarding information system assets by identifying security risks, threats, and vulnerabilities. This position requires a seasoned leader with strong business acumen, detailed knowledge of information security technologies, practices, and policies, and the ability to act calmly in high-pressure situations. The CISO will also research and recommend innovative solutions, manage strategic relationships within IT, and ensure projects meet all required security standards. A key responsibility will be to ensure compliance with new NYS Cybersecurity requirements for water and wastewater systems.

Requirements

  • A bachelor’s degree from an accredited college and 4 years of satisfactory experience of a nature to qualify for the duties and responsibilities of the position, at least 18 months of which must have been in an administrative, managerial, consultative, or executive capacity or supervising personnel performing activities related to the duties of the position; or A combination of education and/or experience equivalent to the above.
  • Proven knowledge of core cybersecurity principles, including the ability to understand, interpret, and apply cybersecurity policies, standards, and regulatory requirements.
  • Practical, hands-on experience in system protection or risk management, demonstrating the ability to identify security risks, evaluate vulnerabilities, and support incident response activities.
  • Experience implementing or supporting cybersecurity programs in environments involving critical infrastructure, public utilities, operational technology (OT), or similar high-risk systems.
  • The capability to serve as the responsible authority for developing, maintaining, and ensuring compliance with the system’s cybersecurity program.
  • In-depth knowledge of Internet Protocol (IP) networking and networking protocols.
  • Knowledge of security technologies including encryption, Internet Protocol Security (IPsec), Public Key Infrastructure (PKI), Virtual Private Networks (VPNs), firewalls, proxy services, Domain Name System (DNS), electronic mail systems, privileged access management, and access lists.
  • Experience with Operational Technology (OT) networks and Supervisory Control and Data Acquisition (SCADA) environments.
  • Advanced knowledge of cloud service security models and enterprise data protection strategies, including backup architecture, disaster recovery planning, and business continuity frameworks.
  • Subject matter expertise in internet, web, application, and network security engineering, including vulnerability assessments, network scanning, and threat surface analysis.

Responsibilities

  • Lead the development, coordination, and submission of materials required to maintain compliance with the New York State Cybersecurity Regulations for Public Water Systems.
  • Manage and direct a team of information technology security professionals, providing leadership, guidance, and support.
  • Manage cybersecurity incidents and attacks in coordination with the team and oversight agencies such as New York City Cyber Command (NYC Cyber Command).
  • Track cyber security incidents and vulnerability reports, direct teams for remediation of issues.
  • Design a critical response process for cyber security incidents.
  • Continuously monitor threats to DEP’s information technology (IT) and operational technology (OT) environments.
  • Develop cybersecurity Key Risk Indicators (KRIs) and dashboard metrics for reporting.
  • Develop and document cybersecurity policies, procedures, and standards in alignment with Citywide Information Security Policies.
  • Coordinate air-gapped backup strategies with agency business units.
  • Participate in annual financial and technology audits for the agency.
  • Examine computer systems to ensure secure operation and protection of data from internal and external threats.
  • Perform security assessments to ensure compliance with security policies, procedures, and industry standards.
  • Monitor, evaluate, and maintain security systems according to industry best practices to safeguard internal systems and databases.
  • Assist with the review and definition of security requirements and evaluate systems for compliance with established standards.
  • Investigate security violations and breaches and prepare reports on incidents and intrusions as required.
  • Review and assess firewall logs and configure firewalls, intrusion detection systems, and other network security devices.
  • Work with other BIT teams to design and implement cybersecurity solutions across DEP infrastructure, networks, and systems.
  • Develop necessary budget analysis and related documentation for annual submissions of budget for cyber-security related solutions.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service