IT OPERATIONS MANAGER

HEREFORD INSURANCE COMPANYNew York, NY
$110,000 - $115,000Onsite

About The Position

The IT Operations Manager owns daily IT operations across four areas: the internal IT Service Desk, governance of the IT Managed Service Provider (MSP) for infrastructure, governance of the Managed Security Service Provider (MSSP) for cybersecurity operations, and the third-party vendor security audit program supporting NYDFS 23 NYCRR 500 compliance. The role is the accountable internal owner for service delivery, infrastructure operations, security operations, and vendor risk, ensuring HIC meets the operational and regulatory standards expected of a NYDFS-regulated insurer. This position is responsible for ensuring operational stability across the network, servers, cloud services, endpoints, and security platforms. Responsibilities include incident management, change control, vendor governance, asset lifecycle oversight, and adherence to IT policies and regulatory requirements. Position requires access to Personally Identifiable Information and/or Personal Health Information to complete the job requirements.

Requirements

  • Bachelor’s degree in IT, Computer Science, or related field.
  • Five+ years of IT operations, infrastructure management, or service desk leadership experience.
  • Experience governing IT MSPs and/or MSSPs, including QBRs, SLA scorecards, and escalation management.
  • Demonstrated experience operating a third-party vendor security risk program (intake, tiering, annual reviews, SOC 2 review, vendor risk register).
  • Strong understanding of networks, servers, cloud platforms, and endpoint management.
  • Familiarity with cybersecurity concepts, vulnerability management, and compliance.
  • Strong communication, leadership, and vendor management skills.
  • Basic understanding of network concepts and security principles.

Nice To Haves

  • CISSP or ITIL certification preferred.
  • Hands-on experience supporting NYDFS 23 NYCRR 500 and/or SOC 2 audits, including evidence collection, control mapping, and third-party service provider security assessments (NYCRR 500.11).
  • Experience in regulated environments such as insurance or financial services.
  • Certifications such as Network+, Security+, or Microsoft.
  • Experience with ticketing systems, asset tools, and monitoring platforms.

Responsibilities

  • Oversees daily Service Desk operations and ensures high-quality user support.
  • Monitors ticket queues, SLAs, and escalation patterns.
  • Coaches Service Desk technicians and maintains SOPs and support standards.
  • Ensures documentation accuracy and knowledge base maintenance.
  • Acts as the Service Desk authority for sign-off on patches, security policy pushes, and production changes proposed by the MSP or MSSP, including pilot validation and post-push rollback decisions.
  • Serves as the primary liaison to the IT Managed Service Provider (MSP).
  • Oversees MSP performance, uptime, patching, backups, and incident response.
  • Coordinates lifecycle replacements, upgrades, and infrastructure improvements.
  • Reviews MSP reports and escalates performance or compliance concerns.
  • Serves as the primary internal owner of the Managed Security Service Provider (MSSP), governing 24x7 monitoring, alerting, vulnerability management, EDR/XDR, PAM, and incident response services.
  • Oversees MFA governance, privileged access reviews, endpoint compliance, and security hardening.
  • Runs formal MSSP governance — quarterly business reviews (QBRs), SLA scorecards, KPI tracking, and escalation of performance or compliance issues.
  • Owns internal accountability for NYDFS 23 NYCRR Part 500 control operation and SOC 2 readiness, working with the vCISO and MSSP to maintain a current control inventory, evidence library, and remediation tracker.
  • Owns coordination and evidence delivery for internal IT audits, NYDFS examinations, SOC 2 audits, and the annual Superintendent’s Certification (NYCRR 500.17).
  • Owns HIC’s Third-Party Service Provider Security Program in accordance with NYDFS 23 NYCRR 500.11 and HIC ITSEC-09 (Vendor Risk Management).
  • Maintains the in-scope third-party vendor inventory; classifies vendors by risk tier (high/medium/low) based on data access, system criticality, and PII/PHI exposure.
  • Issues, collects, and adjudicates annual vendor security assessments (questionnaires, SOC 2 reports, penetration test summaries, evidence of MFA, encryption, access controls, and incident response capabilities).
  • Operates a rolling quarterly review schedule, ensuring all in-scope vendors are validated at least annually with findings logged in the vendor risk register.
  • Reviews vendor security clauses in contracts and renewals (e.g., breach notification, right-to-audit, data return/destruction) and partners with Legal and the vCISO on remediation of identified gaps.
  • Reports vendor risk posture quarterly to the CIO and (as required) the IT Steering Committee, including high-risk findings, remediation status, and contracts with unresolved security exceptions.
  • Leads IT incident, problem, and change management processes.
  • Maintains IT asset lifecycle, inventory accuracy, and onboarding/offboarding workflows.
  • Oversees configuration documentation, runbooks, and operational procedures.
  • Works with business units to prepare for upgrades and technology changes.
  • Supports infrastructure modernization, cloud adoption, and security projects.
  • Manages IT vendor relationships, renewals, and performance reviews.
  • Ensures alignment with architectural standards, compliance, and budget constraints.
  • Ensures adherence to IT policies, procedures, and cybersecurity controls.
  • Provides operational reporting on risks, performance, and service metrics.
  • Performs other related duties and special projects as assigned.
  • Working manager and gets involved when required to help with technical issues.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service