Jobs
>
New York City

    Cyber Security Application Specialist - New York, United States - City of New York

    Default job background
    Description

    Job Description

    IMPORTANT NOTE:

    CANDIDATES WITH A PERMANENT COMPUTER SYSTEMS MANAGER OR COMPARABLE CIVIL SERVICE TITLE WITH SIMILAR DUTIES/RESPONSIBILITES ARE ENCOURAGED TO APPLY. PLEASE INCLUDE YOUR EMPLOYEE IDENTIFICATION NUMBER (EIN) WHEN APPLYING AND INDICATE IN YOUR COVER LETTER YOUR PERMANENT CIVIL SERVICE TITLE.

    The NYC Department of Finance (DOF) is responsible for administering the tax revenue laws of the city fairly, efficiently, and transparently to instill public confidence and encourage compliance while providing exceptional customer service.

    The Finance Information Technology (FIT) Division designs, builds, and supports all facets of DOFs computer systems, including hardware, software, applications, infrastructure, telephone, and data security. FIT delivers and administers tax-related payment programs for the City of New York by providing the information technology solutions needed to achieve its mission of collecting revenue while ensuring an efficient and improved customer experience. FIT is also responsible for the systems and websites which enable citywide payments, land records, property assessment, parking adjudications, customer service, and the Sheriffs public safety work.

    As a member of Finance Cyber Security Governance team, the selected candidate will work within a multi-disciplined team to provide expertise on application security and DevSecOps initiatives to guide the application development community to utilize the best security practices. The candidate will work to help further develop and refine the Finance Cyber Security program into SDLC as that process matures.

    Duties and responsibilities will include, but are not limited to:

    Provide engineering and development direction for application security designs that solve business problems.

    Collaborate with other teams to help architect solutions that are inherently secure.

    Conduct thorough assessment of applications to identify and analyze potential security vulnerabilities.

    Coordinate and perform penetration testing, code reviews, and other security tests to ensure applications meet security standards.

    Effectively use and manage security scanning tools to identify and mitigate security risks in applications.

    Evaluate and prioritize security risks, providing recommendations for remediation to enhance the overall security posture of applications.

    Develop, implement, and enforce security policies and best practices for application development and deployment.

    Work closely with development and IT teams to integrate security measures into the software development life-cycle and address security issues promptly.

    Actively participate in incident response activities, investigating and resolving security incidents related to applications.

    Promote security awareness among development teams, fostering a culture of security-conscious application development.

    Ensure applications comply with relevant security standards, regulations, and industry best practices.

    Maintain accurate documentation of security processes, assessments, and remediation efforts.

    Provide / partner to provide training sessions to educate development teams on secure coding practices and emerging security threats.

    Stay abreast of the latest security trends, vulnerabilities, and technologies, incorporating new knowledge into security strategies.

    Effectively communicate security risks and solutions to both technical and non-technical stakeholders, facilitating a clear understanding of potential threats.

    Contribute to cross-functional security initiatives, ensuring a holistic and integrated approach to overall organizational security.

    Knowledge of integrating software security into the software development cycle.

    Understanding how to develop secure coding guidelines and train developers on those guidelines.

    Ensure the number of software vulnerabilities are minimized by using static and dynamic analysis, including Fuzz testing, and penetration testing of applications.

    Help develop integrity checks to ensure data is accurate. Knowledge on how to develop production security algorithms to help protect users and data.

    Experience working with container security.

    Provide DevOps security solution integration with various security test tools.

    Working with application teams on security solution design and implementation. Be a security subject matter expert and respond to any internal security engineering questions/requests.

    Accessing security solutions proof of value and conducting proof of concepts.

    Educating other team members on application security standards and best practices.

    Participating in enterprise technology and functional planning processes to develop standards and best practices.

    Correctly balance security risk and product advancement.

    Perform proactive research to detect new attack vectors.

    Design and implement mitigations for common classes of bugs in a popular web framework before code is developed.

    Qualifications

    1. A master's degree in computer science from an accredited college or university and three (3) years of progressively more responsible, full-time, satisfactory experience in Information Technology (IT) including applications development, systems development, data communications and networking, database administration, data processing, or user services. At least eighteen (18) months of this experience must have been in an administrative, managerial or executive capacity in the areas of applications development, systems development, data communications and networking, database administration, data processing or in the supervision of staff performing these duties; or

    2. A baccalaureate degree from an accredited college or university and four (4) years of progressively more responsible, full-time, satisfactory experience as described in "1" above; or

    3. A four-year high school diploma or its educational equivalent, and six (6) years of progressively more responsible, full-time, satisfactory experience as described in "1" above; or

    4. A satisfactory combination of education and experience equivalent to "1", "2" or "3" above. However, all candidates must have at least a four-year high school diploma or its educational equivalent and must possess at least three (3) years of experience as described in "1" above, including the eighteen (18) months of administrative, managerial, executive or supervisory experience as described in "1" above.

    In the absence of a baccalaureate degree, undergraduate credits may be substituted for a maximum of two (2) years of the required experience in IT on the basis of 30 semester credits for six (6) months of the required experience. Graduate credits in computer science may be substituted for a maximum of one (1) year of the required experience in IT on the basis of 30 graduate semester credits in computer science for one (1) year of the required IT experience. However, undergraduate and/or graduate credits may not be substituted for the eighteen (18) months of experience in an administrative, managerial, executive, or supervisory capacity as described in "1" above.

    Additional Information

    The City of New York is an inclusive equal opportunity employer committed to recruiting and retaining a diverse workforce and providing a work environment that is free from discrimination and harassment based upon any legally protected status or protected characteristic, including but not limited to an individual's sex, race, color, ethnicity, national origin, age, religion, disability, sexual orientation, veteran status, gender identity, or pregnancy.



  • Newmark New York, United States

    You will also partner with the Product team to help prioritize requirements by sharing user insights, and articulate user problems to inform the product roadmap. You must love interacting with people, and exhibit an empathetic, patient, and inquisitive attitude. · **Key Responsib ...


  • Rose Associates Inc. New York, United States

    **Overview** · **Essential Job Functions** · - Work closely with our Enterprise Application Manager, oversee the Yardi property management system, ensuring its optimal performance and utilization. · - Assist in the implementation of new Yardi modules, ensuring they align with bus ...


  • NYC Careers Manhattan, United States

    **Cyber Security Application Specialist**: · - Apply**Cyber Security Application Specialist**: · - Agency: DEPARTMENT OF FINANCE · - Posted on: 04/23/2024- Job type: Full-time · Location · MANHATTAN · - Title Classification: Exam may be required · Department · Cyber Security · - ...


  • Sumitomo Mitsui Banking Corporation Jersey City, United States

    SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 130 offices and 80,000 ...


  • Mediaform Informationssysteme GmbH New York, United States

    Willkommen bei der Mediaform Unternehmensgruppe Seit über 30 Jahren sind wir in der DACH-Region führende Experten für Datenerfassungs-, Kennzeichnungs- und Auto-ID-Systeme. Mit starken Produkten und innovativen Lösungen schaffen wir Impulse und Mehrwerte im Gesundheitswesen und d ...


  • Univar Solutions USA I&S LLC Brooklyn, United States

    **A Place Where People Matter.** · Start your career journey with Univar Solutions Here you can make an impact on the world around you and accelerate your career in areas that energize and excite you. · As an Application Development Specialist (ADS) you will provide technical ser ...


  • Horizon Ventures East Newark, United States

    We are looking for an IT application specialist for medical information systems (m/f/d) for our clinic network in East Newark. · Starting immediately | Kempten | Ref. No. 661 · OUR COMPANY · The Allgäu Clinic Network includes hospitals in Kempten, Mindelheim, Immenstadt, Ottobeur ...


  • Deutschetelekomitsolutions New York, United States

    **llsazonost:** 121629_HU_2 · **Application Support Specialist - Lotus Notes** · **Helyszn:** · Budapest Debrecen Pcs Szeged · Egy nmet logisztikai multinacionlis nagyvllalat (DPDHL) projektjre keresnk ambicizus, nmetl magabiztosan beszl?, fejleszt?i feladatokat ellt szakembert ...


  • Columbia University New York, United States

    Job Type: Officer of Administration · Regular/Temporary: Regular · Hours Per Week: 35 · Building: Studebaker · Salary Range: $95,000 - $105,000 · The salary of the finalist selected for this role will be set based on a variety of factors, including but not limited to departm ...


  • WSP New York, United States

    This Opportunity · The Federal Cloud Operations Team is looking for an Applications Support Specialist to assist our architecture and engineering project teams to carry out work on behalf of the U.S. Government. This individual will help users resolve issues with their CAD/BIM s ...


  • LENSAR, Inc. New York City, United States

    * LENSAR currently has one Clinical Applications Specialist opportunity available that's posted in different cities within the Southeast and Northeast regions.* · Company Overview · LENSAR, Inc. is the leader in advanced femtosecond laser technology for refractive cataract surger ...


  • Mattermore New York, United States

    About Mattermore: · Support the founding team at Mattermore as we revolutionize the future of work. Our AI-powered organizational ops enhancement tool provides data-driven insights and real-time feedback to help managers support their teams, grow as leaders, and drive business gr ...


  • New York Technology Partners New York, United States

    Job Summary: · The Fircosoft Application Specialist supports the Fircosoft Sanctions screening systems and services within the Compliance Technology division. The Sanctions screening system ensures that SMBC meets all its risk, legal, and regulatory responsibilities related to Sa ...


  • Osaic New York, United States

    Application Support Specialist · Contract Duration: 8 Months · Remote · Pay: $21.00/hr · SUMMARY · Work in a team environment and perform a wide variety of duties pertaining to Infinex's overall technology needs. · DUTIES AND RESPONSIBILITIES · Performs a variety of activities ...


  • Ortho Clinical Diagnostics New York, United States

    Quidel. Ortho unites the strengths of Quidel Corporation and Ortho Clinical Diagnostics, creating a world-leading in vitro diagnostics company with award-winning expertise in immunoassay and molecular testing, clinical chemistry and transfusion medic Specialist, Application, Fiel ...


  • Atria Institute New York, United States

    About Atria: · Atria is a membership-based preventive health care practice delivering cutting-edge primary and specialty care from the comfort of your home, at our practices in Palm Beach and New York, or wherever you are in the world. · We bring together a multidisciplinary team ...


  • Carestream New York, NY, USA, United States

    Innovation that sparks imagination. Continue on to your next challenge with us. · Carestream is a worldwide provider of medical imaging systems and solutions; x-ray imaging systems for non-destructive testing; manufacturing of film and precision contract coating services for a wi ...


  • Carestream New York, NY, USA, United States

    Innovation that sparks imagination. Continue on to your next challenge with us. · Carestream is a worldwide provider of medical imaging systems and solutions; x-ray imaging systems for non-destructive testing; manufacturing of film and precision contract coating services for a wi ...


  • City of New York New York, United States

    Job Description · Only those applicants with permanent civil service status as a Certified IT Developer are eligible to apply to this job posting, otherwise you will not be considered for an interview. On your cover letter, please state that you are a permanent Certified IT Deve ...


  • beqom International New York, United States

    At beqom, our people are our number one priority. We are a fun group of people who specialize in developing, selling, supporting, and marketing our total compensation management solution. Headquartered in Switzerland and operating around the world, it is our mission is to make th ...