New York, United States | Posted on 04/22/2025
New York, NY 10038 (Hybrid – 3 days onsite / 2 days remote)
Note: Candidates with State, City, or Federal experience are required.
• Each candidate must submit a government-issued ID (Driver's License or Passport) and provide three professional references (names, official emails, and phone numbers).
Job Description:
The City of New York – OTI is seeking a Cyber Command Cloud Security Engineer to work within its Cloud Security & Enterprise Cyber Defense team. This individual will be responsible for designing and implementing identity assurance, cloud security hardening, privileged access management, and data loss prevention strategies in both cloud and on-premises environments. The role involves engaging with City Agencies and private sector partners to strengthen cybersecurity posture across all systems.
Specialty Areas:
Cloud Security & Identity Management – Implement and manage IAM, PAM, CASB, SSE, and cloud security controls.Risk Assessment & Compliance – Conduct cybersecurity risk analysis and develop strategies to mitigate agency-specific threats.Security Engineering – Deploy security frameworks for Zero Trust, Data Loss Prevention, and identity governance.Telemetry & Monitoring – Collect and process telemetry and event data across platforms for threat monitoring.Collaboration & Documentation – Work with multiple stakeholders and maintain detailed security documentation.Responsibilities:
Conduct organization-wide cybersecurity risk assessments and communicate findings.Develop and implement strategies for identity and cloud security.Manage cloud-based technologies including Azure, AWS, and Google Cloud environments.Design and deploy CASB, SSE, and DLP tools for proactive security enforcement.Translate compliance requirements into enforceable security controls.Guide teams on secure infrastructure design (“secure by default”).Monitor and resolve security vulnerabilities; enforce cloud security standards.Create cybersecurity metrics and reporting for leadership updates.Lead implementation of Zero Trust and Identity Governance policies.Work with incident responders and stakeholders to drive security solutions.Skill Matrix:
Information Security – 12+ yearsIT Infrastructure, Middleware, Architecture – 8+ yearsCloud Security (Azure, AWS, GCP) – 4+ yearsIAM, PAM, SAML, MFA, TLS/SSL – 8+ yearsCASB, SSE, DLP – 4+ yearsSecurity Telemetry & Event Data Tools – 4+ yearsWindows, Linux, or MacOS Administration – 4+ yearsEDR/XDR and Cloud Security Tools – 4+ yearsScripting (Python, Bash, PowerShell) – RequiredVulnerability & Application Scanning Tools – RequiredStrong Documentation & Collaboration Skills – RequiredMandatory Requirements:
Bachelor's degree in Computer Science, Information Systems, or related field.Minimum 12 years of experience in information security.At least 8 years in infrastructure, architecture, and IT operations.Minimum 4 years of experience in cloud environments (Azure, AWS, GCP).Familiarity with security frameworks, Zero Trust, DLP, SSE, and telemetry tools.Preferred Qualifications:
Experience with PAM solutions, SASE/CASB products (NetSkope, Zscaler, etc.).Familiarity with MS Entra AD, Defender for Office, Skyhigh Cloud.Understanding of CIS Controls and secure software development lifecycle.Experience with Log aggregation tools (Syslog-NG, LogScale/Humio).Strong understanding of endpoint security, configuration, and asset management.Excellent analytical, problem-solving, and communication skills.Submission Requirements:
• Three professional references (Names, official emails, phone numbers)
#J-18808-Ljbffr