Full-Time

Cybersecurity Officer-Application Security

Posted on 8/21/2025

Metropolitan Transportation Authority

Metropolitan Transportation Authority

1,001-5,000 employees

Operates regional public transit network

Compensation Overview

$148.8k - $196.7k/yr

New York, NY, USA

Hybrid

Telework eligible two days per week; location: 2 Broadway, New York, NY 10004; hybrid arrangement not remote-only.

Category
IT & Security (3)
, ,
Requirements
  • Bachelor’s degree required, preferably in Computer Science or related fields. An equivalent combination of education and experience may be considered in lieu of a degree.
  • A minimum of 5 plus years of relevant experience.
  • CISSP, CISM, or other advanced security-related certification preferred
  • Certifications in technology subdomains preferred (i.e., Cloud, Applications, Infrastructure, Security Technology, etc.).
  • Requires prior experience with installing, maintaining, and troubleshooting technology systems.
  • Experience in Project Management Principles (Waterfall and Agile) preferred.
  • Must possess a deep understanding of technology and cybersecurity domain principles.
  • Proven ability to manage projects and initiatives.
  • Proven ability to manage people.
  • Proven ability to add value to a team.
  • Understanding of Operating Systems, Cloud, Mobile, and Applications.
  • Understanding of TCP/IP (OSI Layers 1– 4) and Internet and Intranet technologies required (OSI Layers 5-7).
  • Some Scripting or programming skills (PERL, Python, PowerShell, etc.) preferred as needed.
  • Knowledge of programming languages, frameworks, databases, and software engineering is a must.
  • Proficient in Productivity Tools (i.e., Office 365, Gsuite).
  • Experience with Spreadsheets and Data Analysis.
  • Successful track record in design of software systems to meet the current and future needs of a complex organization, OR successful track record in design and implementation of IT Infrastructure and related hardware and software technologies to meet the current and future needs of a complex transportation organization.
  • Strong Verbal/written communication skills.
  • Financial/budgeting planning and management experience is a plus.
Responsibilities
  • Lead a team of multi-functional technical staff planning, building, and maintaining cybersecurity tools, configurations, and risk mitigation to support Information and Operational Technology applications and/or infrastructure products.
  • Lead others, as appropriate, and when necessary, that will consist of one or more agile coaches, data analytics researchers, and other cybersecurity personnel.
  • Provide leadership in the development of inter-team communication and cohesiveness; sustain culture and support assigned staff during organizational growth/changes.
  • Provide direction on evaluation, selection, implementation, and maintenance of cybersecurity tools, processes, and techniques for their assigned cyber domains and products, ensuring appropriate investment in strategic and operational systems.
  • Lead teams to complete projects when a project manager has not been assigned.
  • Attained significant achievements managing technical teams, contractors, and vendors.
  • Attract, develop, coach, and retain high-performance team members, empowering them to elevate their level of responsibility, span of control, and performance in conjunction with the Cybersecurity Management and IT Workforce Planning & Workload Management office.
  • Build staff expertise and competence to meet evolving demands within the Enterprise Product Management unit.
  • Demonstrate consistent understanding of funding, communications, and systems; recommend timelines and resources needed to achieve the program goals.
  • Collaborates with IT Business Management Services to identify procurement contracts to support program related activities.
  • Assess and makes recommendations on the improvement and re-engineering within the IT Department and works with the stakeholders to keep the total cost of ownership down.
  • Promote the use of employee self-service and mobile connectivity within products to reduce the reliance on paper.
  • Recommends and supports automation of business process creating in-line forms and approvals, reducing the reliance on manual approvals that could be untimely.
  • Uses judgment to form conclusions that may challenge conventional wisdom
  • Coordinates and facilitates consultation with stakeholders to define business and systems requirements for new technology implementations, developing business cases and cost justifications for such initiatives.
  • Provides direction on evaluation, selection, implementation, and maintenance of information systems, ensuring appropriate investment in strategic and operational systems.
  • Advises MTA IT management, as information becomes available, on the changing trends and emerging technology and their potential use within the MTA.
  • Directs the development of the analysis required to determine if Information Technology projects should follow a “Build” (develop with in-house staff) or “Buy” (cloud or packaged solution) methodology.
  • Manages the development and implementation of new modules within assigned products.
  • Advises on the selection, prioritization, development, and implementation of products as they relate to the selection, acquisition, development, and installation of MTA IT and OT Security, applications, and infrastructure.
  • Participates in overall business planning, bringing current knowledge and future vision of technology and systems as related to the company’s goals.
  • Responsible for leading and reporting on various product progress and deliverables, ensuring that the IT/OT needs of the MTA are met on time and within budget, including identifying weekly, monthly, and annual performance targets to show progress on IT product work and OT objectives.
  • Ensure continuous delivery of product services through oversight of service level agreements with end users and monitoring of product performance.
  • Responsible for the recruitment, development, motivation, training, and retention of a diverse and high performing multi-level IT/OT team of professionals, conforming to budgetary objectives and Human Resources policy and programs in conjunction with the IT Workforce Planning & Workload Management office.
  • Develop business case justifications and cost/benefit analyses for IT spending and initiatives, keeping customizations to a minimum and total cost of ownership down.
  • Manage and plan the future technical architecture, providing insight into the future of their area of technology to continually improve effectiveness and efficiency.
  • Manage and plan the development of roadmaps related to their area(s) of expertise to manage and meet identified technology needs.
  • Manage and plan the evaluation of new technologies relative to their domain(s) to determine applicability to and best meet the needs of MTA and constituent agencies.
  • Manage and ensure disaster recovery and contingency plans for their domain(s) to provide users with minimal interruptions in service.
  • Oversees architectural direction for domains under management to meet senior management and cybersecurity goals.
  • Understand, review, and approve Cybersecurity Reference Architectures and Solutions for applying them.
  • Revalidates systems to the most recent reference architectures to determine gaps, develops and manages programs to align systems to the newest standards and reference architectures
  • Contribute and own technical elements of RFPs and RFIs, and negotiate with vendors on technical issues to ensure results are delivered in line with user and organization requirements.
  • Manages contracts and expenses to ensure SLAs and contract renewals are processed timely manner?
  • Provide contract management support to ensure vendor deliverables are met
  • Manage and lead major projects and assign service providers with technical expertise to address mission-critical issues, evaluate ongoing vendor service levels, and enforce SLAs and penalties.
  • Ensure detailed and updated documentation is in place for cybersecurity systems and user processes.
  • Participate in the creation of enterprise security documents (policies, standards, baselines, guidelines, and procedures) under the direction of the IT Security Manager, where appropriate.
  • Provides timely and relevant updates to appropriate stakeholders and decision makers
  • Communicates investigation findings to relevant business units to help improve the information security posture
  • Provides technical guidance to project managers and senior leadership on cybersecurity and technology strategies
  • Ensure quality and review, and guidance on tests of new systems and manage cybersecurity risks, and remediation system testing, baseline, and best practices
  • Provide escalation support to project teams in their area of expertise to promote technical understanding and talent development
  • Provide guidance and take input from Analysts, Engineers, Architects, and Technology Subject Matter Experts on cybersecurity and technology best practices, current threat landscape, and a risk management approach for optimal alignment
  • Provides sound cybersecurity recommendations
  • Provide leadership during incident response, and provide continuous improvement updates to the threat model for risks to the business and systems
  • Ensure specific monitoring points are continually updated to assess the performance of technologies in their domain(s). Identify and manage the necessary actions to ensure optimal performance and reliability.
  • Validate and maintain incident response plans and processes to address potential threats
  • Compile and analyze data for management reporting and metrics
  • Research emerging technologies and process improvements to stay current and plan for the evolving threat landscape to ensure strategy meetings current threats
  • Monitors relevant information sources to stay up to date on current attacks and trends
  • Ensure cybersecurity technology solutions meet strategy, meet security framework objectives, and business objectives.
  • Hypothesizes new threats and indicators of compromise.
  • Performs other duties and tasks as assigned.
  • Observing the work performed by the contractor.
  • Reviewing invoices and approving them if the work meets contractual standards.
  • Addressing performance issues with the contractor when possible.
  • Escalating issues to other parties as needed.
  • Oversee rigorous quality assurance processes to deliver reliability, performance, and safety objectives
  • Oversees staff workload and quality of work, addressing performance issues when needed.
Desired Qualifications
  • Experience in governance, risk and compliance (GRC) programs and frameworks like NIST SP 800-37, 800-53, 800-64; ISO 27001/27002; NIST RMF; CIS Top 18; PCI-DSS; HIPAA; SOC 2; FedRAMP etc., with ability to apply to enterprise environment.
  • Experience with cloud security platforms and cloud security controls (e.g., AWS IAM, Azure AD, GCP IAM, Cloudflare, Zscaler, Prisma Access, Netskope, etc.).
  • Experience in securing critical infrastructure (critical networks, OT/ICS systems, ICS/SCADA, etc.).
  • Experience with integration of security testing and software development lifecycle (SSDLC) in regulated environments.
  • Experience with security incident response in cloud and on-prem environments and threat hunting.
  • Experience with secure development practices and DevSecOps.
  • Experience with application security testing tools and services and software composition analysis tools.
  • Experience with security architecture reviews and threat modeling.
  • Experience with Zero Trust Architecture.
  • Experience with container security and orchestration (Kubernetes, OpenShift).
  • Experience with CI/CD pipelines and secure deployment practices.
  • Experience with governance risk and compliance (GRC) frameworks and programs.
  • Experience with risk assessments and risk management.
  • Experience with vulnerability management and remediation programs.
  • Knowledge of hackable software and hardware and security protocols.
  • Experience with security controls and monitoring in OT/ICS environments.
  • Experience with incident response and forensic investigations.
  • Experience with privacy and data protection.
  • Experience with security testing tools and services in the cloud.
  • Experience with secure SDLC and DevSecOps.
  • Experience with developer security coaching and secure libraries.
  • Experience with secure coding standards.
  • Experience with secure coding training programs.
  • Experience with risk-based vulnerability management.
  • Experience with vendor management and contract management.
  • Experience with auditing and compliance activities.
  • Experience with security automation and orchestration.
  • Experience with security analytics and threat intelligence.
  • Experience with risk management frameworks.
  • Experience with product security roadmaps and governance.
  • Experience with threat modeling and secure design reviews.
  • Experience with threat detection and security monitoring.
  • Experience with security program management.
  • Experience with OWASP ASVS.
  • Experience with software bill of materials (SBOM).
  • Experience with software composition analysis.
  • Experience with secure software supply chain.
  • Experience with secure coding in multiple languages.
  • Experience with software asset management.
  • Experience with SDLC and DevSecOps maturity.
  • Experience with software supply chain security.
  • Experience with secure coding practices.
  • Experience with threat modeling and secure design reviews.
  • Experience with risk management and compliance.
  • Experience with cloud security architectures.
  • Experience with data protection and privacy.
  • Experience with security operations centers (SOCs).
  • Experience with incident handling and response.
  • Experience with vulnerability management and remediation.
  • Experience with security controls.
  • Experience with security incident response.
  • Experience with application security testing tools.
  • Experience with SCA/ SBOM.
  • Experience with secure software development lifecycle.
  • Experience with application security governance.
  • Experience with secure coding training.
  • Experience with secure development lifecycle.
  • Experience with threat modeling and secure design reviews.
  • Experience with security architecture reviews.
  • Experience with secure coding standards.
  • Experience with secure coding training.
  • Experience with secure software supply chain.
  • Experience with cloud security.
  • Experience with security testing.
  • Experience with DevOps security.
  • Experience with security architecture.
  • Experience with security governance.
  • Experience with security risk management.
  • Experience with application security.
  • Experience with vulnerability management.
  • Experience with cyber risk.
  • Experience with IT security.
  • Experience with information security.
  • Experience with risk management.
  • Experience with governance.
Metropolitan Transportation Authority

Metropolitan Transportation Authority

View

MTA runs North America’s largest public transit network, serving about 15.3 million people across New York City, Long Island, southeastern New York State, and Connecticut through six agencies: NYC Transit, MTA Bus, LIRR, Metro-North, Bridges and Tunnels, and Construction & Development. It moves roughly 2.6 billion trips each year using subways, buses, commuter rails, bridges and tunnels, and related facilities. It differentiates itself by operating multiple transit modes under one umbrella, providing integrated services across districts and modes with extensive infrastructure. Its goal is to provide safe, clean, efficient public transportation that serves as the region’s lifeline and mobility backbone while supporting staff with solid benefits.

Company Size

1,001-5,000

Company Stage

N/A

Total Funding

N/A

Headquarters

New York City, New York

Founded

1834

Simplify Jobs

Simplify's Take

What believers are saying

  • $68 billion 2025-2029 Capital Plan funds 2,390 new subway cars.
  • Congestion pricing revenues accelerate signal upgrades and accessibility.
  • Board approves 435 R211 cars and 44 LIRR locomotives in 2025.

What critics are saying

  • $51 billion plan underfunds subway signals, causing delays in 6-12 months.
  • Federal freeze withholds $3.5 billion over emissions in 12-18 months.
  • TWU lawsuit triggers strike, halting operations in 6-12 months.

What makes Metropolitan Transportation Authority unique

  • MTA serves 11 million daily passengers across 12 counties.
  • MTA manages seven toll bridges and two tunnels daily.
  • Janno Lieber leads modernization since January 2022 appointment.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options

Flexible Work Hours

Company News

Forbes
May 16th, 2025
Nj Transit Strike: What To Know As Work Stoppage Affects Thousands Of Commuters—And Could Impact Beyoncé Concertgoers

Topline. Rail engineers working for New Jersey Transit went on strike early Friday, suspending service for one of the busiest train systems in the country and impacting approximately a hundred thousand riders each day, marking the first major strike to affect the train system in four decades. People board a New Jersey Transit train in Manhattan on May 15 in New York City.Getty Images Key Facts

Government Technology
Oct 14th, 2020
Traffic AI Startup Brings Anthony Foxx, Stuart McKee Aboard

Hayden AI, founded last year, has pulled in two big names along with $5 million in investment money. The company plans to put cameras on vehicles like city buses and run the video through AI.

INACTIVE