Role Overview & Specifications

Minimum Qualifications

Bachelor’s degree* with at least 15 credit hours in cyber security, information assurance, or information technology; and two years of information technology experience, including one year of information security or information assurance experience**.

Substitution: bachelor’s degree candidates without at least 15 course credits in cyber security, information assurance, or information technology require an additional year of general information technology experience to qualify. Appropriate information security or information assurance experience may substitute for the bachelor’s degree on a year-for-year basis; an associate’s degree requires an additional two years of general information technology experience. Experience solely in information security or information assurance may substitute for the general information technology experience.

Preferred Qualifications

Certifications in one or more of the following:Cyber Defense (e.g., GCIA, GCIH, GCED, GSOM, GSOC, GMON, GCDA)Cyber Threat Intelligence (e.g., GCTI, CTIA, CCIP, GOSI)Information Security Management (e.g., CISSP, CISM, CCISO) 1+ years’ experience in one or more of the following:Working as a SOC analystConducting log analysis (e.g., firewall logs, DNS logs, proxy logs, IDS/IPS logs)Using SIEM technologies to support in-depth investigationsParticipating in cyber incident response Strong understanding of enterprise IT environments, including but not limited to system administration, network architecture, operating systems, endpoint detection and response tools, and network-based security solutions (e.g., IDS/IPS, firewalls). Strong understanding of the foundations of Information Security, such as the CIA triad, information classification, identity and access management, risk management, vulnerability management, secure architecture and engineering, network security, software development security, etc. Excellent oral and written communication skills including the ability to clearly articulate information technology and information security concepts to a varied audience to facilitate wide understanding. Demonstrated critical thinking, problem solving and analytical skills.

Duties Description

Under the direction of senior leadership within the Office of Information Technology Services\Chief Information Security Office\Cyber Command Center\ New York Security Operations Center (NYSOC), the incumbent will be a Threat Hunting Analyst working in the NYSOC. The incumbent will leverage a variety of threat intelligence sources and indicators of compromise (IOCs) to perform both proactive and reactive threat hunting across a large and diverse multi-entity environment. The incumbent will participate in the ingestion and response to all forms of threat intelligence and vulnerability announcements received from many third parties such as vendors, DHS CISA, MS-ISAC, NYSP, and other sources of open-source intelligence.

This position requires the incumbent to possess a solid understanding of the current cyber threat landscape, the tactics, techniques, tools, and procedures commonly leveraged, and the steps necessary to swiftly identify and contain a potential cyber threat. Additionally, this position requires an incumbent to act with a great deal of independence in alignment with agency and upper-level management strategic direction.

Due to the nature of the work performed by the SOC, this position requires availability during off-shift hours to ensure appropriate response to security incidents or other critical activities as needed.

Duties Include, But Are Not Limited To

Monitor and report on current and emerging threats including exploitable vulnerabilities, and details of those vulnerabilities Conduct research, analysis, and correlation across a wide variety of all source data sets such as IOCs, IOAs and warnings Perform threat hunting across a multi-OS/multi-cloud environment to ensure a timely and effective response to new cyber threats Identify tactics, techniques, and procedures (TTPs) for intrusion sets Respond to ad-hoc request, research, threat hunts, and assist with other business units as needed Assist with creating detection content based on threat hunting findings Document all threat hunt, track, and create trends based on the findings Classify/categorize hunting use cases based on MITRE ATT&CK framework and cyber kill chain Create daily, monthly, and yearly intelligence information in support of NYSOC business needs Create technical reports and executive summaries related to cyber security incidents and events Participate in active projects to help identify and resolve issues/problems to ensure successful outcomes are achieved Perform the full range of supervisory responsibilities, as assigned

Additional Comments

Additional details on work shift will be discussed at time of interview.

Background check and fingerprinting are required.

Benefits of Working for NYS

Generous benefits package, worth 65% of salary, including:

Holiday & Paid Time Off Thirteen (13) paid holidays annually Up to thirteen (13) days of paid vacation leave annually Up to five (5) days of paid personal leave annually Up to thirteen (13) days of paid sick leave annually for PEF Up to three (3) days of professional leave annually to participate in professional development

Health Care Benefits

Eligible employees and dependents can pick from a variety of affordable health insurance programs Family dental and vision benefits at no additional cost

Additional Benefits

New York State Employees’ Retirement System (ERS) Membership NYS Deferred Compensation Access to NY 529 and NY ABLE College Savings Programs, as well as U.S. Savings Bonds Public Service Loan Forgiveness (PSLF) Up to 50% telecommuting And many more.

About Nys Office Of Information Technology Services

Nys Office Of Information Technology Services is an actively verified employer hiring talent across technology, engineering, and operations.

  • Headquarters: United States / United Kingdom
  • Company Size: 1,000+ employees
  • Trust Rating: 95 / 100 (Official Registry Audited)

View all openings at Nys Office Of Information Technology Services →