All jobs

Incident Response Analyst, Office of Chief Information Officer

100% Remote Full-time Open now

About the position The Office of Information Security (OIS) leads the implementation of an integrated, modern, framework-based security program across the Department of Health and Mental Hygiene to preserve the integrity of agency services and protect sensitive business data from current and emerging cyber threats, and to preserve the reputation of the agency and its ability to protect and promote the health of all New Yorkers. The Cyber Incident Response team provide detection and response to cybersecurity events, events of interest, and incidents for DOHMH. It also collects forensic user evidence requested by legal and investigative entities.

Responsibilities

  • Automate processes leveraging scripts (Python, batch, etc.). Run reports to gather data from SQL databases (SQL). Run penetration testing tools (AppScan).
  • Responsible for vulnerability management.
  • Knowledge of SOAR responses and their implementation.
  • Create SIEM dashboards to help visualize data and events.
  • Set the program strategy and develop approaches to integrate automation/orchestration services into existing and future processes that will support the verticals within Threat Management.
  • Perform technical and forensic investigations.
  • Analyze system services, operating systems, networks, and applications to address possible cyber-attacks.
  • Remain current on cybersecurity trends and intelligence to enhance the security analysis and the identification capabilities for the IR Team.
  • Respond and resolve basic operational technical Incidents and Requests.
  • Summarize events/incidents effectively to different constituencies such as legal counsel, executive management, and technical staff, both in written and verbal forms.
  • On-call availability as needed/required. Schedules may include several days per month, after hours and weekend support.

Requirements

  • A baccalaureate degree, from an accredited college including or supplemented by twenty-four (24) semester credits in cyber security, network security, computer science, computer programming, computer engineering, information technology, information science, information systems management, network administration, or a pertinent scientific, technical or related area.
  • A four-year high school diploma or its equivalent approved by a State's department of education or a recognized accrediting organization and three years of satisfactory experience in any of the areas described in '1' above.
  • Education and/or experience equivalent to '1' or '2', above. College education may be substituted for up to two years of the required experience in '2' above on the basis that sixty (60) semester credits from an accredited college is equated to one year of experience.
  • Twenty-four (24) credits from an accredited college or graduate school in cyber security, network security, computer science, computer programming, computer engineering, information technology, information science, information systems management, network administration, or a pertinent scientific, technical or related area; or a certificate of at least 625 hours in computer programming from an accredited technical school (post high school), may be substituted for one year of experience.

Nice-to-haves

  • Self-starter, detail-oriented, reliable and accountable.
  • Excellent organizational, time-management and multi-tasking skills, including the ability to take initiative, prioritize duties, and work both independently and within a team.
  • Applicant should be able to work with little or no supervision.
  • Familiarity with SIEM and creation of relevant dashboards.
  • Knowledge of cyber security tools and protocols.
  • Knowledge of Windows and Linux operating systems.
  • Knowledge of security best practices.
  • Knowledge of Windows desktop/server environments, Azure and Microsoft O365.
  • Excellent written and verbal communication skills.
  • Knowledgeable of penetration/vulnerability assessment methodologies and the cyber kill chain.
  • Familiarity with cyber threat intelligence and MITRE's ATT&CK framework.
  • Knowledgeable of cyber incident handling and response processes.
  • Familiarity of vulnerability management and remediation.
  • Experienced in integrated cybersecurity assessment frameworks and lifecycles.

Benefits

  • A premium-free health insurance plan that saves employees over $10K annually, per a 2024 assessment.
  • Additional health, fitness, and financial benefits may be available based on the position's associated union/benefit fund.
  • A public sector defined benefit pension plan with steady monthly payments in retirement.
  • A tax-deferred savings program.
  • A robust Worksite Wellness Program that offers resources and opportunities to keep you healthy while serving New Yorkers.
  • Work From Home Policy: Depending on your position, you may be able to work up to two days during the week from home.
  • Job Security - you could enjoy more job security compared to private sector employment.

Apply tot his job Apply To this Job

You might also like

Urgently Need Sr. Cyber Security Analyst – Incident Response - REMOTE in Owings Mills, MD

100% Remote Full-time

Senior Analyst/ Innovative Finance/ IIX /Philippines/

100% Remote Full-time

[Remote] Incident Response Analyst (Remote)

100% Remote Full-time

Associate Director, Institutional Clients, Impact Investing in New York City, NY – Global Impact Investing Network – vsmartpros

100% Remote Full-time

Industrial Engineer 2 - Elizabethtown, PA

100% Remote Full-time

[Remote] Project Engineer SR (Industrial Engineer)

100% Remote Full-time

Influencer Marketing Manager for Leading Mobile Games and Digital Content Publisher in Africa (Part-Time Remote Opportunity)

100% Remote Full-time

Industrial Engineer- Remote

100% Remote Full-time

Industrial Engineer II, Supply Chain Walnut, CA Posted yesterday

100% Remote Full-time

IT Workday Security Manager

100% Remote Full-time

Remote Customer Service and Sales Representative - Virtual Customer Support and Sales Career Opportunity with arenaflex

100% Remote Full-time

Senior Budget Analyst, DHS Office of the Chief Human Capital Officer in Washington DC

100% Remote Full-time

Client Service Coordinator - Select - Remote - Chattanooga, TN

100% Remote Full-time

Enterprise IT Support Officer - Location Support Center

100% Remote Full-time

Senior Data Engineer, Data Products

100% Remote Full-time

Experienced Customer Service Representative – Overnight Shift – Work from Home Opportunity – Delivering Exceptional Patient Care and Support

100% Remote Full-time

Join Today: Amazon Remote Work From Home Jobs & Careers

100% Remote Full-time

Southwest Airlines Customer Service Job – Starting Pay $20/Hour

100% Remote Full-time

Experienced Live Chat Specialist - Customer Engagement & Support

100% Remote Full-time

DevOps Engineer

100% Remote Full-time