Cybersecurity Officer- Manager Cloud Security
Company: Metropolitan Transportation Authority
Location: New York City
Posted on: April 2, 2026
|
|
|
Job Description:
Description Position at MTA Headquarters JOB TITLE:
Cybersecurity Officer- Manager Cloud Security SALARY RANGE:
$148,784.00 - $196,730.00 HAY POINTS: 805 DEPT/DIV: Information
Technology / Cybersecurity SUPERVISOR: Cybersecurity Director
LOCATION: Various/ 2 Broadway, New York, NY 10004 HOURS OF WORK:
9:00 am - 5:30 pm (7.5 hours or as required) This position is
eligible for telework, which is currently two days per week. New
hires are eligible to apply 30 days after their effective date of
hire. Summary of Job The purpose of this position is to provide
technical leadership and management of MTA’s cybersecurity program
in one or more technical domains. This role deals with both
internal and external threats to the MTA systems, which can affect
both the safety of employees and customers, system integrity, and
the availability of operations. As part of managing the program,
the Cybersecurity Officer will need expertise in managing a complex
program with highly skilled staff, contracts, and processes
associated with risk management that are essential to maintaining
electronic and physical safety for MTA’s business in all areas that
utilize technology (Corporate, Customer Facing and Informational,
Fare Payment/PCI, Operational Technologies, 3 rd Party Managed,
Vendors, etc.). The Cybersecurity Officer will be responsible for
managing and developing staff, technology, and processes to reduce
risk with the evolving cyber threat landscape and changing
technology portfolio. This position works across multiple
technology and cybersecurity domains to ensure cybersecurity is
looked at holistically from user, data and component, and systems
perspectives. The position also considers all risk assessments,
data-driven analytics, and actively seeks to develop and maintain
standards, reference architectures, and reduce the risk of the MTA
through emerging technologies and trends in the industry. The
position is expected to have a level of expertise in one or more
domains of technology and effective management. There is a long
list of these specialized domains in the cybersecurity field, and
this list is growing and everchanging as the field evolves and as
risks and circumstances change. Preferred skills: Cloud security
expertise Cybersecurity knowledge Risk assessment and management
Compliance and regulations knowledge Identity and Access Management
(IAM) Encryption and data protection Incident response and
forensics Security architecture Security monitoring and SIEM
Cloud-specific security tools Communication and leadership Vendor
management Continuous learning Collaboration Problem-solving
Business acumen Adaptability Knowledge of cloud-native application
platforms Project management principles Cloud computing proficiency
Responsibilities Leadership Provide leadership to a strong talent
pool of technical professionals Lead a team of multi-functional
technical staff planning, building, and maintaining cybersecurity
tools, configurations, and risk mitigation to support Information
and Operational Technology applications and/or infrastructure
products Lead others, as appropriate, and when necessary, which
will consist of one or more agile coaches, data analytics
researchers, and other cybersecurity personnel Provide leadership
in the development of inter-team communication and cohesiveness;
sustain culture and support assigned staff during organizational
growth/changes. Provide direction on evaluation, selection,
implementation, and maintenance of cybersecurity tools, processes,
and techniques for their assigned cyber domains and products,
ensuring appropriate investment in strategic and operational
systems. Lead teams to complete projects when a project manager has
not been assigned. Attain significant achievements managing
technical teams, contractors, and vendors. Human Resource
Management Attract, develop, coach, and retain high-performance
team members, empowering them to elevate their level of
responsibility, span of control, and performance in conjunction
with the Cybersecurity Management and IT Workforce Planning &
Workload Management office. Build staff expertise and competence to
meet evolving demands within the Enterprise Product Management
unit. Financial Management Demonstrate consistent understanding of
funding, communications, and systems; recommend timelines and
resources needed to achieve the program goals. Collaborates with IT
Business Management Services to identify procurement contracts to
support program related activities. Strategy & Planning Assesses
and makes recommendations on the improvement and re-engineering
within the IT Department, and works with the stakeholders to keep
the total cost of ownership down. Promote the use of employee
self-service and mobile connectivity within products to reduce the
reliance on paper. Recommends and supports automation of business
process creating in-line forms and approvals, reducing the reliance
on manual approvals that could be untimely. Uses judgment to form
conclusions that may challenge conventional wisdom Acquisition &
Deployment Coordinates and facilitates consultation with
stakeholders to define business and systems requirements for new
technology implementations, developing business cases and cost
justifications for such initiatives. Provides direction on
evaluation, selection, implementation, and maintenance of
information systems, ensuring appropriate investment in strategic
and operational systems. Advises MTA IT management, as information
becomes available, on the changing trends and emerging technology
and their potential use within the MTA. Directs the development of
the analysis required to determine if Information Technology
projects should follow a “Build” (develop with in-house staff) or
“Buy” (cloud or packaged solution) methodology. Manages the
development and implementation of new modules within assigned
products. Advises on the selection, prioritization, development,
and implementation of products as they relate to the selection,
acquisition, development, and installation of MTA IT and OT
Security, applications and infrastructure. Management and Oversight
Participates in overall business planning, bringing current
knowledge and future vision of technology and systems as related to
the company’s goals. Responsible for leading and reporting on
various product progress and deliverables, ensuring that the IT/OT
needs of the MTA are met on time and within budget, including
identifying weekly, monthly, and annual performance targets to show
progress on IT product work and OT objectives. Ensure continuous
delivery of product services through oversight of service level
agreements with end users and monitoring of product performance.
Responsible for the recruitment, development, motivation, training,
and retention of a diverse and high performing multi-level IT/OT
team professionals, conforming to budgetary objectives and Human
Resources policy and programs in conjunction with the IT Workforce
Planning & Workload Management office. Develop business case
justifications and cost/benefit analyses for IT spending and
initiatives, keeping customizations to a minimum and total cost of
ownership down. Cybersecurity Officer-Specific Accountabilities
Planning Manage and plan the future technical architecture,
providing insight into the future of their area of technology in
order to continually improve effectiveness and efficiency. Manage
and plan the development of roadmaps related to their area(s) of
expertise to manage and meet identified technology needs. Manage
and plan the evaluation of new technologies relative to their
domain(s) to determine applicability to and best meet the needs of
MTA and constituent agencies. Manage and ensure disaster recovery
and contingency plans for their domain(s) to provide users with
minimal interruptions in service. Architecture Oversees
architectural direction for domains under management to meet senior
management and cybersecurity goals. Understand, review, and approve
Cybersecurity Reference Architectures and Solutions for applying
them Revalidates systems to the most recent reference architectures
to determine gaps, develop and manage programs to align systems to
the newest standards and reference architectures Contracts/Vendor
Management Contribute to and own technical elements of RFPs and
RFIs, and negotiate with vendors on technical issues to ensure
results are delivered in line with user and organization
requirements. Manages contracts and expenses to ensure SLAs and
contract renewals are processed timely manner Provide contract
management support to ensure vendor deliverables are met Manage and
lead major projects and assign service providers with technical
expertise to address mission critical issues, evaluate ongoing
vendor service levels, and enforce SLAs and penalties.
Documentation Ensure detailed and updated documentation is in place
for cybersecurity systems and user processes. Participate in the
creation of enterprise security documents (policies, standards,
baselines, guidelines, and procedures) under the direction of the
IT Security Manager, where appropriate. Guidance, Communications,
and Training Support Provides timely and relevant updates to
appropriate stakeholders and decision makers Communicates
investigation findings to relevant business units to help improve
the information security posture Provides technical guidance to
project managers and senior leadership on cybersecurity and
technology strategies Ensure quality and review, and guidance on
tests of new systems and manage cybersecurity risks and remediation
system testing, baseline, and best practices Provide escalation
support to project teams in their area of expertise to promote
technical understanding and talent development Provide guidance and
take input from Analysts, Engineers, Architects, and Technology
Subject Matter Experts on cybersecurity and technology best
practices, current threat landscape, and a risk management approach
for optimal alignment Provides sound cybersecurity recommendations
Operations Provide leadership and advisement when necessary during
incident response, and provide continuous improvement updates to
the threat model for risks to the business and systems Ensure
specific monitoring points are continually updated to assess the
performance of technologies in their domain(s). Identify and manage
the necessary actions to ensure optimal performance and
reliability. Research & Analysis Validates and maintains incident
response plans and processes to address potential threats Compiles
and analyzes data for management reporting and metrics Research
emerging technologies and process improvements to stay current and
plan for the evolving threat landscape to ensure strategy meetings
are current threats Monitors relevant information sources to stay
up to date on current attacks and trends Ensure cybersecurity
technology solutions meet strategy, meet security framework
objectives, and business objectives. Hypothesizes new threats and
indicators of compromise Qualifications: Experience Bachelor’s
Degree in Computer Science or related fields, or equivalent
experience. An equivalent combination of education and experience
may be considered in lieu of a degree. CISSP, CISM, or other
advanced security-related certification preferred Certifications in
technology subdomains preferred (ie, Cloud, Applications,
Infrastructure, Security Technology, etc.). A minimum of 4 plus
years of relevant experience. Requires prior experience with
installing, maintaining, and troubleshooting technology systems.
Experience in Project Management Principles (Waterfall and Agile)
preferred. Competencies Must possess a deep understanding of
technology and cybersecurity domain principles. Proven ability to
manage projects and initiatives. Proven ability to manage people.
Proven ability to add value to a team. Understanding of Operating
Systems, Cloud, Mobile, and Applications. Understanding of TCP/IP
(OSI Layers 1– 4) and Internet and Intranet technologies required
(OSI Layers 5-7) required. Some Scripting or programming skills
(PERL, Python, PowerShell, etc.) preferred as needed. Proficient in
Productivity Tools (ie, Office 365, G-Suite). Experience with
Spreadsheets and Data Analysis. Successful track record in design
of software systems to meet the current and future needs of a
complex organization, OR successful track record in design and
implementation of IT Infrastructure and related hardware and
software technologies to meet the current and future needs of a
complex transportation organization. Strong Verbal/written
communication skills. Financial/budgeting planning and management
experience is a plus. Ability to fit in with the constantly
shifting needs and demands of the business Departments. Core
Competency Proficiency Level Competency Definition Collaborates
Expert Building partnerships and working collaboratively with
others to meet shared objectives Cultivates Innovation Expert
Creating new and better ways for the organization to be successful
Customer Focus Expert Building strong customer relationships and
delivering customer-centric solutions Communicates Effectively
Expert Developing and delivering multi-mode communications that
convey a clear understanding of the unique needs of different
audiences Tech Savvy N/A Anticipating and adopting innovations in
business-building digital and technology applications Technical
Skills N/A Specialized knowledge and expertise on tools, programs,
domains, platforms, and products used for specific tasks Values
Diversity Expert Recognizing the value that different perspectives
and cultures bring to an organization GENERAL: May need to work
outside of normal work hours (i.e., evenings and weekends) Travel
may be required to other MTA locations or other external sites
Pursuant to the New York State Public Officers Law & the MTA Code
of Ethics, all employees who hold a policymaking position must file
an Annual Statement of Financial Disclosure (FDS) with the NYS
Commission on Ethics and Lobbying in Government (the “Commission”).
MTA and its subsidiary and affiliated agencies are Equal
Opportunity Employers, including with respect to veteran status and
individuals with disabilities. The MTA encourages qualified
applicants from diverse backgrounds, experiences, and abilities,
including military service members, to apply.
Keywords: Metropolitan Transportation Authority, Lower Merion , Cybersecurity Officer- Manager Cloud Security, IT / Software / Systems , New York City, Pennsylvania