Cybersecurity Engineer Level 1-7 (AWS Cloud & SaaS Security)

17 May 2024

Vacancy expired!

Description

Job Title: Cybersecurity Engineer Level 1-7 (AWS Cloud & SaaS Security)

Salary Range: Level 1: $82,857.04 - $105,000

Level 2: $87,685.20 - $115,500

Level 3: $95,929.32 - $127,050

Level 4: $102,760.32 -$139,755

Level 5: $114,537.24 -$153,731

Level 6: $124,311.32 -$169,104

Level 7: $140,917.09 -$186,014

POINTS:

Level 1 - 282

Level 2 - 393

Level 3 - 451

Level 4 - 551

Level 5 - 479

Level 6 - 551

Level 7 - 634

DEPT/DIV: MTA Information Technology/ Office of IT Cyber Security

SUPERVISOR: Director, Application Security

LOCATION: 2 Broadway, New York, NY 10004

HOURS OF WORK: 9:00am - 5:30am (7.5hrs)

In order to protect our employees and continue to provide safe and reliable service to our communities, as of November 14, 2021, we are requiring all new MTA hires to be fully vaccinated against COVID-19 prior to their start date. MTA will consider exceptions for religious and medical reasons, where appropriate. "Fully vaccinated" means you must have both doses of a 2-dose vaccine and two weeks have elapsed since the second dose or have received 1 dose of a 1-dose vaccine and two weeks have elapsed since the dose. Proof of your vaccination status in the form of a CDC vaccine card must be submitted prior to your start date.

The purpose of this position is to provide critical technical expertise in managing and analyzing cybersecurity risks. Cybersecurity Analyst will be responsible for early and accurate detection, prevention response, containment, and guidance to remediation of threats directed against the MTA. The analysis is conducted through technology risk assessments, data analytics tools, business processes reviews and collaborate with security engineers, architects, developers, vendors, business units to constantly improve the overall security of the MTA. The cybersecurity analyst will focus on specific domains and specialties within cybersecurity with a great degree of specialty to detect, protect and advise the organization proactively and reactively

Level 1
  • Understanding of TCP/IP (OSI Layers 1- 4) and Internet and Intranet technologies required (OSI Layers 5-7) required.
Level 2
  • Basic knowledge and familiarity with installing, maintaining and troubleshooting technology systems.
  • Proven ability to troubleshoot and support technical issues.
  • Proven ability to analyze a security risk assessment
  • Proven ability to troubleshoot and support technical issues.
  • Understanding of TCP/IP (OSI Layers 1- 4) and Internet and Intranet technologies required (OSI Layers 5-7) required.
  • Some scripting or programming skills (PERL, Python, PowerShell, etc.) preferred as needed.
  • Understanding of Operating Systems and Configuration Hardening.
  • Understanding of security concepts for technical domain
Level 3
  • Proven ability to troubleshoot and support technical issues using standardized procedures.
  • Proven ability to analyze a security risk assessment or conduct one with guidance
  • Understanding of TCP/IP (OSI Layers 1- 4) and Internet and Intranet technologies required (OSI Layers 5-7) required.
  • Some scripting or programming skills (PERL, Python, PowerShell, etc.) preferred as needed.
  • Proficient in Operating Systems and Configuration Hardening.
  • Understanding of security concepts for technical domain.
Level 4
  • Proven ability to independently evaluate and resolve most problems within an area of infrastructure, applications within a security domain context.
  • Proven ability to analyze and/or conduct a security risk assessment
  • Advanced understanding of TCP/IP (OSI Layers 1- 4) and Internet and Intranet technologies required (OSI Layers 5-7) required.
  • Some scripting or programming skills (PERL, Python, PowerShell, etc.) preferred as needed.
Level 5
  • Advanced understanding of common IT security frameworks, controls and protocols, technologies, threats, and vulnerabilities are necessary.
  • Progressive cybersecurity related accomplishments.
  • Requires broad technical knowledge of multiple technologies, or an in-depth knowledge of one technology including its impact on other technologies.
  • Proven ability to analyze and/or conduct a security risk assessment.
  • Advanced understanding of TCP/IP (OSI Layers 1- 4) and Internet and Intranet technologies required (OSI Layers 5-7) required.
  • Some scripting or programming skills (PERL, Python, PowerShell, etc.) preferred as needed.
Level 6
  • Requires seasoned expertise in multiple technologies and strong understanding of the current and future technology architecture, including the inter-operability of technologies.
  • Advanced ability to conduct and analyze a security risk assessment
  • Expert understanding of TCP/IP (OSI Layers 1- 4) and Internet and Intranet technologies required (OSI Layers 5-7) required.
  • Some scripting or programming skills (PERL, Python, PowerShell, etc.) preferred as needed.
Level 7
  • Significant practical expertise in cybersecurity related disciplines
  • Requires seasoned expertise in multiple security domains, technologies and strong understanding of the current and future technology and security architecture, including the inter-operability of security solutions and technologies.
  • Requires proven track record of successful implementation of architectural designs.
  • Requires proven track record in configuration and hardening of systems.
Level 1
  • Associate degree in Computer Science or related fields. An equivalent combination of education and experience may be considered in lieu of a degree.
  • Basic knowledge and familiarity with monitoring, installing, maintaining and/or troubleshooting cybersecurity related issues associated to applications and/or infrastructure systems
Level 2
  • Associate degree in Computer Science or related fields. An equivalent combination of education and experience may be considered in lieu of a degree and 2+ years of relevant experience, or a bachelor's degree in Computer Science or related fields.
Level 3
  • Bachelor's Degree in Computer Science or related fields. An equivalent combination of education and experience may be considered in lieu of a degree.
  • 2+ years of relevant experience.
  • CISSP or other advanced security-related certification preferred but not required.
  • Certifications in technology subdomains preferred but not required (ie. Cloud, Applications, Infrastructure, Security Technology, etc.)
  • Requires prior experience with installing, maintaining and troubleshooting technology systems.
Level 4
  • Bachelor's Degree in Computer Science or related fields. An equivalent combination of education and experience may be considered in lieu of a degree.
  • Current CISSP or other advanced security-related certification preferred but not required.
  • Certifications in technology subdomains preferred but not required (ie. Cloud, Applications, Infrastructure, Security Technology, etc.)
  • 3+ years of relevant experience or 18 months of experience in a specific cybersecurity subdomain (Cloud, Applications, Infrastructure, Security Technology, etc.)
Level 5
  • Bachelor's Degree in Computer Science or related fields. An equivalent combination of education and experience may be considered in lieu of a degree.
  • 5+ years of relevant experience or 2.5 years of experience in a specific cybersecurity subdomain (Cloud, Applications, Infrastructure, Security Technology, etc.).
  • CISSP or other advanced security-related certification preferred
  • Certifications in technology subdomains preferred but not required (ie. Cloud, Applications, Infrastructure, Security Technology, etc.)
  • Current and updated security certification
Level 6
  • Bachelor's Degree in Computer Science or related fields. An equivalent combination of education and experience may be considered in lieu of a degree.
  • 8+ years of relevant experience or 4 years of experience in a specific cybersecurity subdomain (Cloud, Applications, Infrastructure, Security Technology, etc.) CISSP or other advanced security-related certification preferred.
  • Certifications in technology subdomains preferred but not required (ie. Cloud, Applications, Infrastructure, Security Technology, etc.)
  • Verifiable implementation of security domain controls for enterprise technologies
Level 7
  • Bachelor's Degree in Computer Science or related fields. An equivalent combination of education and experience may be considered in lieu of a degree.
  • 10+ years of relevant technology based or cybersecurity experience or 5 years of experience in a specific cybersecurity subdomain (Cloud, Applications, Infrastructure, Security Technology, etc.).
  • CISSP and other advanced security-related certification preferred
As an employee of MTA Headquarters, you may be required to complete an annual financial disclosure statement with the State of New York, if your position earns more than $105,472 (this figure is subject to change) per year or if the position is designated as a policy maker.

Qualified employees can submit an online application by clicking on the 'APPLY NOW' button from either the CAREERS HOME page or the JOB DESCRIPTION page.

For instructions on completing the online application, go to the MTA intranet site and click on the PeopleSoft Information hyperlink. From there select the User Guides hyperlink to gain access to the "Viewing/Applying for Jobs On Line" guide under the Recruiting section of the page.

MTA and its subsidiary and affiliated agencies are Equal Opportunity Employers, including with respect to veteran status and individuals with disabilities.

The MTA encourages qualified applicants from diverse backgrounds, experiences, and abilities, including military service members, to apply.

  • ID: #49952324
  • State: New York New york city 10001 New york city USA
  • City: New york city
  • Salary: USD TBD TBD
  • Job type: Permanent
  • Showed: 2023-05-17
  • Deadline: 2023-07-15
  • Category: Et cetera