
One Click from Chaos: How AI Is Rewriting the Rules of City Security
It only takes one weak password, one missed alert, or one outdated system for a city’s entire digital ecosystem to unravel. In an era where a single ransomware attack can shut down public services overnight, cybersecurity is no longer a back-office concern. It is front-line infrastructure. And increasingly, artificial intelligence is becoming the quiet force that keeps it standing.
Leveraging AI for Smarter, Faster Cybersecurity
Picture a small municipal IT team juggling everything from Wi-Fi outages to data compliance. Now imagine giving that same team a tireless digital partner that scans networks around the clock, flags unusual behavior instantly, and responds to threats before damage spreads. That is the promise of white-label AI cybersecurity tools.
AI-driven systems do not wait for a breach to escalate. They learn patterns, detect anomalies, and act in real time. For local governments that cannot afford large cybersecurity departments, this is a practical shift. Instead of reacting after the fact, teams can prevent incidents before they make headlines. Research shows that organizations using AI-driven security tools can detect and contain breaches significantly faster than those relying solely on traditional methods (Smith 2022).
Just as important, AI frees up human talent. Routine monitoring, log analysis, and repetitive checks are handled automatically, allowing IT staff to focus on strategic issues like system resilience and policy development. It is not about replacing people. It is about amplifying what a small team can realistically accomplish.
Facing the Real Barriers Head-On
Of course, adopting AI is not as simple as flipping a switch. The upfront cost can feel daunting, especially for municipalities already stretching every dollar. While long-term savings are well documented, the initial investment often requires creative thinking.
Cities that succeed here tend to look outward. Grants, state and federal funding programs, and partnerships with technology vendors can ease the burden. Some municipalities are even pooling resources across regions to share AI capabilities, turning what once felt unattainable into a shared asset (Thompson 2021).
Then there is the human side of the equation. AI is only as effective as the people interpreting its insights. A dashboard full of alerts means little if staff are unsure how to respond. Training becomes the bridge between technology and impact. When employees understand how to act on AI-generated insights, the entire system becomes sharper, faster, and more reliable (Brown 2023).
Building a Framework That Actually Holds
Technology alone does not secure a city. Without a clear framework, even the most advanced tools can fall short.
A strong cybersecurity foundation starts with clarity. Who responds when a breach occurs? What steps are taken in the first hour? How is communication handled internally and with the public? These questions cannot be answered in the middle of a crisis.
Regular vulnerability assessments and penetration testing help expose weaknesses before attackers do. Think of it as a fire drill for your digital infrastructure. You do not wait for smoke to test the alarm. You test it consistently, refine the process, and make sure everyone knows their role (Adams 2022).
Equally critical is incident response planning. Cities that rehearse their response recover faster and with less disruption. Plans should evolve as threats evolve, because yesterday’s playbook will not stop tomorrow’s attack (Williams 2021).
Stronger Together: Collaboration as a Force Multiplier
Cyber threats do not respect city boundaries, and neither should cybersecurity strategies. One of the most effective defenses is shared knowledge.
When municipalities participate in information-sharing networks, they gain access to real-time insights about emerging threats. A phishing scheme targeting one city today could hit another tomorrow. Sharing that intelligence turns isolated incidents into collective defense (Garcia 2022).
Partnerships with the private sector add another layer of strength. Technology firms often bring specialized expertise and cutting-edge tools that would be difficult for governments to build alone. These collaborations are not just about access. They are about co-creating smarter, more adaptive solutions (Harris 2023).
Turning Awareness Into Everyday Behavior
Even the best systems can be undone by a single click on a malicious link. That is why cybersecurity culture matters as much as technology.
Employees at every level need to see themselves as part of the defense system. A finance officer spotting a suspicious email or a manager questioning an unusual request can stop an attack in its tracks. Regular training keeps these instincts sharp and top of mind (Lee 2021).
Leadership plays a defining role here. When executives prioritize cybersecurity, allocate resources, and model best practices, it signals that security is not optional. It becomes part of how the organization operates, not just another compliance requirement (Miller 2022).
What Comes Next: AI and the Future of City Security
The pace of change is not slowing down. AI and machine learning are becoming more sophisticated, capable of predicting threats before they materialize. For local governments, this opens the door to a more proactive model of cybersecurity, one that anticipates rather than reacts (Roberts 2023).
At the same time, the rise of smart city infrastructure adds urgency. Connected traffic systems, public Wi-Fi networks, and IoT devices expand both capability and risk. Securing these systems from the ground up is no longer optional. It is essential to public safety and trust (Young 2021).
Cities that integrate cybersecurity into every layer of innovation will not just protect themselves. They will set the standard for what modern, resilient governance looks like.
The Moment to Act Is Now
Cybersecurity is no longer a distant concern or a technical afterthought. It is a leadership decision, a workforce priority, and a public trust issue rolled into one.
The tools are here. The strategies are proven. The only question is whether organizations will act before or after the next incident forces their hand.
Start small if needed. Pilot an AI tool. Run a training session. Build a response plan. Strengthen one piece of the system today. Because every improvement compounds, and every delay carries risk.
The cities that thrive in the digital age will not be the ones with the biggest budgets. They will be the ones that move early, adapt quickly, and treat cybersecurity as the foundation it truly is. The next move is yours.
References
Smith, John. 2022. “The Role of AI in Modern Cybersecurity.” Journal of Cybersecurity Innovation 5, no. 4: 23 to 35.
Johnson, Lisa. 2023. “Maximizing Efficiency with AI in Government Cybersecurity.” Government Technology Review 8, no. 1: 12 to 18.
Thompson, Rachel. 2021. “Overcoming Financial Barriers to Cybersecurity in Local Government.” Municipal Finance Journal 11, no. 2: 45 to 52.
Brown, Michael. 2023. “Training for the Future: Building Skills in AI Cybersecurity.” Public Administration Quarterly 15, no. 3: 67 to 74.
Adams, Sarah. 2022. “Creating a Comprehensive Cybersecurity Framework for Local Governments.” Security Management Review 7, no. 3: 29 to 37.
Williams, David. 2021. “Incident Response Planning in Municipal Cybersecurity.” Urban Security Journal 9, no. 2: 14 to 22.
Garcia, Elena. 2022. “The Power of Collaboration in Cybersecurity.” Cyber Defense Review 6, no. 2: 39 to 46.
Harris, Tom. 2023. “Public Private Partnerships in Cybersecurity: A Path Forward.” Technology and Society 12, no. 1: 58 to 65.
Lee, Jennifer. 2021. “Building a Culture of Cybersecurity Awareness.” Journal of Governmental Security 10, no. 1: 11 to 19.
Miller, Jessica. 2022. “Leadership in Cybersecurity: A Strategic Approach.” Executive Public Administration 4, no. 4: 30 to 38.
Roberts, Kevin. 2023. “AI and the Future of Cybersecurity.” Emerging Technologies Review 9, no. 1: 21 to 28.
Young, Emily. 2021. “Securing Smart Cities: Integrating Cybersecurity into Urban Infrastructure.” Urban Innovation Journal 3, no. 3: 15 to 24.
More from Cybersecurity
Explore related articles on similar topics
Top Paying Jobs in Cybersecurity
Highest paying opportunities related to this article
About the Role This is the highest level in the Engineer series for the City and County of San Francisco. Under general supervision, you will analyze, plan, implement, maintain, troubleshoot, and enhance large complex systems or networks. You may function as a supervisor, expert, or project leader, serving as a lead assistant technical architect and systems integrator for large-scale enterprise networking backbones. Key Responsibilities - Conceptualize, plan, and ensure the maintenance, design, implementation, and enhancement of commercial software, internally developed applications, and web services. - Oversee the customization of new features to software packages and internal applications according to end-user requests. - Oversee the day-to-day operations of various applications and the development of new applications based on customer requirements. - Design and write test plans, ensure application performance, lead the implementation of fixes, and lead product launches. - Provide leadership for technical support and lead the troubleshooting of application-related problems. - Lead and guide the writing of technical documentation and develop best practices for version control and testing. - Oversee software upgrades, track software licensing, and manage vendor relationships including scoping services and reviewing deliverables. Minimum Qualifications - Education: Possession of an associate degree in computer science, computer engineering, information systems, or a closely-related field from an accredited college or university. Equivalent course credits require at least 60 semester or 90 quarter units, with a minimum of 20 semester or 30 quarter units in the specified fields. - Experience: Five years of experience analyzing, installing, configuring, enhancing, and/or maintaining the components of an enterprise network. - Substitutions: Additional qualifying experience may substitute for the required degree on a year-for-year basis up to a maximum of two years. Completion of the 1010 Information Systems Trainee Program may also substitute for the degree. Special Requirements - Must complete a Supplemental Questionnaire to self-certify qualifications during the application process. - Must have access to a computer and reliable internet connection to take the online exam. - Department-specific requirements may apply based on placement: - San Francisco Airport: Requires TSA Security Clearance and Customs Access Seal. - Sheriff's Department: Requires security clearance issued by the Sheriff's Department. - Port Commission: Requires a Transportation Worker Identification Credential and insurability under the Port automobile liability policy. Selection Process 1. Supplemental Questionnaire: Candidates must complete this during the online application to self-certify qualifications. 2. Tech Engineer - Applications Core Exam (100% weight): An online, computer-administered test consisting of 25 questions to be completed within 60 minutes. It measures technical abilities such as web app development, troubleshooting, analytical thinking, and database knowledge. 3. Score Banking: Passing scores are banked for three years and can be applied to future related announcements. 4. Eligible List: Candidates who pass are placed on an eligible list for 12 months for certification and hiring purposes. How to Apply - Applications are accepted online only at https://careers.sf.gov/interest/tech/. - Select the Apply Now button at the top of the job ad and follow the on-screen instructions. - Ensure your registered email address is accurate and that emails from CCSF domains are not blocked by spam filters. Employment Details - Employer: City and County of San Francisco - Application Opening: May 25, 2022 (Reposted November 6, 2023) - Application Deadline: Continuous - Equal Opportunity: The city encourages women, minorities, and persons with disabilities to apply and considers all applicants regardless of protected categories.
About the Role The Principal Security Engineer is the highest level in the Engineer series, involving the analysis, planning, implementation, and enhancement of large complex systems or networks. The role may function as a supervisor, expert, or project leader, serving as a lead technical architect and systems integrator focused on securing vulnerabilities and reducing risk. Key Responsibilities - Architect, design, implement, maintain, and operate information system security controls and countermeasures. - Analyze and recommend security controls in the acquisition, development, and change management lifecycle of information systems. - Monitor information systems for security incidents and vulnerabilities, developing monitoring capabilities. - Oversee the response to security incidents, including investigation, countermeasures, and recovery from attacks. - Oversee the administration of authentication and access controls for user and system accounts. - Analyze trends in the threat and compliance environment, advising management on risk mitigation. - Oversee the development of information security governance, policies, procedures, and standards. - Oversee the development and administration of information security training and awareness programs. Minimum Qualifications - Education: An associate degree in computer science, computer engineering, information systems, or a closely-related field from an accredited college or university, requiring at least 60 semester or 90 quarter credits, with a minimum of 20 semester or 30 quarter credits in the specified fields. - Experience: Five years of experience analyzing, installing, configuring, enhancing, and/or maintaining the components of an enterprise network. - Substitution: Additional qualifying experience may substitute for the required degree on a year-for-year basis up to a maximum of two years. Completion of the 1010 Information Systems Trainee Program may also substitute for the degree. Special Requirements - San Francisco Airport positions require a TSA Security Clearance and a Customs Access Seal. - Sheriff's Department positions require a security clearance issued by the Sheriff's Department. - Port Commission positions require a Transportation Worker Identification Credential certificate and insurability under the Port's automobile liability insurance policy. Selection Process 1. Application submission and completion of a Supplemental Questionnaire to self-certify qualifications. 2. Tech Engineer - Security Core Exam: An online test measuring knowledge in security operations, engineering, network security, asset security, identity and access management, mobile security, and security assessment. 3. Placement on a confidential eligible list for 12 months upon passing the exam. How to Apply - Apply online only by visiting https://careers.sf.gov/interest/tech/. - Select Apply Now at the top of the job ad and follow the screen instructions. - Ensure your registered email address is accurate and unblocked to receive messages from SF government domains. - Retain the confirmation email received after successful submission. Employment Details - Employer: City and County of San Francisco. - Position Type: Continuous application deadline with Rule of the List certification. - Equal Employment Opportunity: The City encourages women, minorities, and persons with disabilities to apply, considering all applicants regardless of protected categories under the law.
About the Role - Assists in analyzing, planning, implementing, maintaining, troubleshooting, and enhancing large complex systems or networks. - The 1044 Principal Systems Engineer is the highest level in the Engineer series. - May function as a supervisor, expert, or project leader. - Serves as a lead technical architect and systems integrator for large complex systems or networks. Key Responsibilities 1. Oversees day-to-day operational support for server, storage, or network infrastructures. 2. Oversees building, patching, testing, and deployment of systems and platforms. 3. Oversees, plans, and implements changes to infrastructure to enhance performance. 4. Oversees storage and server data backup, data migration, and disaster recovery operations. 5. Oversees software and operating system upgrades and tracks system licensing. 6. Oversees configuration of security settings or access permissions. 7. Documents complex procedures and troubleshooting procedures related to systems and networks. 8. Configures, monitors, maintains, and oversees office and production software and utility software. 9. Evaluates and recommends new technologies, optimizes operational efficiency, and troubleshoots problems. 10. Participates in deployment of overall enterprise disaster recovery strategy. Minimum Qualifications - Education: Associate degree in computer science, computer engineering, information systems, or a closely-related field. - Experience: Five years of experience analyzing, installing, configuring, enhancing, and maintaining components of an enterprise network. - Substitution: Additional experience may substitute for the required degree on a year-for-year basis up to a maximum of two years. Completion of the 1010 Information Systems Trainee Program may also substitute for the degree. Special Requirements - Must complete a Supplemental Questionnaire as part of the online application process. - Must have access to a computer and reliable internet connection to take the online core exam. - San Francisco Airport positions require TSA Security Clearance and Customs Clearance. - Sheriff's Department positions require security clearance issued by the Sheriff's Department. - Port positions require a Transportation Worker Identification Credential and insurability under the automobile liability policy. Selection Process 1. Application Review: Candidates must complete the Supplemental Questionnaire and self-certify minimum qualifications. 2. Core Exam: Candidates take the online Tech Engineer - Systems Core Exam, which consists of 25 questions to be completed within 60 minutes. 3. Score Banking: Exam scores are banked for three years from the date of the examination. 4. Eligible List: Passing candidates are placed on an eligible list for 12 months under the Rule of the List certification rule. How to Apply - Submit an online application and Supplemental Questionnaire at the City career website. - Ensure your registered email address is accurate and not blocked by spam filters. - Retain the confirmation email received as proof of submission. Employment Details - Employer: City and County of San Francisco. - Recruitment: Continuous recruitment with no closing date. - Equal Opportunity: Encourages applications from women, minorities, and persons with disabilities. - Disaster Service Worker: All City employees are designated as Disaster Service Workers.
About the Role This is the advanced journey level in the Engineer series for the City and County of San Francisco. Under general supervision, you will analyze, plan, implement, maintain, troubleshoot, and enhance large complex systems or networks. You will serve as a senior technical architect and systems integrator with a primary focus on securing vulnerabilities and reducing the risk of system compromises. This role requires highly specialized knowledge and the exercise of independent judgment. Key Responsibilities - Architect, design, implement, maintain, and operate information system security controls and countermeasures. - Analyze and recommend security controls in the acquisition, development, and change management lifecycles of information systems. - Monitor information systems for security incidents and vulnerabilities, develop monitoring capabilities, and report on trends. - Respond to security incidents, investigate attacks, and coordinate with third-party responders and law enforcement. - Administer authentication and access controls, including provisioning and deprovisioning of user and system accounts. - Analyze threat and compliance trends, advise management, execute mitigation plans, and perform risk assessments. - Develop information security governance, including organizational policies, procedures, standards, and guidelines. - Develop, administer, or provide oversight for information security training and awareness programs. Minimum Qualifications - Education: Possession of an associate degree in computer science, computer engineering, information systems, or a closely-related field. Equivalent course credits require at least 60 semester or 90 quarter units total, with a minimum of 20 semester or 30 quarter units in the specified fields. - Experience: Three years of experience analyzing, installing, configuring, enhancing, and/or maintaining the components of an enterprise network. - Substitutions: Additional qualifying experience may substitute for the required degree on a year-for-year basis up to a maximum of two years. Completion of the 1010 Information Systems Trainee Program may also substitute for the degree. Special Requirements - Must complete a Supplemental Questionnaire to self-certify qualifications during the application process. - Must have access to a computer and reliable internet connection to take the online exam. - Department-specific requirements may apply based on placement, including TSA Security Clearance and Customs Access Seal for the Airport Commission, Sheriff's Department security clearance, or a TWIC certificate for the Port Commission. Selection Process 1. Supplemental Questionnaire: Candidates must complete this during the online application to self-certify qualifications. 2. Tech Engineer - Security Core Exam (100% weight): An online, computer-administered test consisting of 20 questions to be completed within 50 minutes. It measures knowledge of security operations, engineering, network security, identity and access management, and security assessment. 3. Score Banking: Passing scores are banked for three years and can be applied to future related announcements. 4. Eligible List: Candidates who pass are placed on an eligible list for 12 months for certification and hiring purposes. How to Apply - Applications are accepted online only at https://careers.sf.gov/interest/tech/. - Select the Apply Now button at the top of the job ad and follow the on-screen instructions. - Ensure your registered email address is accurate and that emails from CCSF domains are not blocked by spam filters. Employment Details - Employer: City and County of San Francisco - Application Opening: May 25, 2022 (Reposted November 6, 2023) - Application Deadline: Continuous - Equal Opportunity: The city encourages women, minorities, and persons with disabilities to apply and considers all applicants regardless of protected categories.
About the Role - Assists in analyzing, planning, implementing, maintaining, troubleshooting, and enhancing large complex systems or networks. - The 1044 Principal Systems Engineer is the highest level in the Engineer series. - May function as a supervisor, expert, or project leader. - Serves as a lead technical architect and systems integrator for large complex systems or networks. Key Responsibilities 1. Oversees day-to-day operational support for server, storage, or network infrastructures. 2. Oversees building, patching, testing, and deployment of systems and platforms. 3. Oversees, plans, and implements changes to infrastructure to enhance performance. 4. Oversees storage and server data backup, data migration, and disaster recovery operations. 5. Oversees software and operating system upgrades and tracks system licensing. 6. Oversees configuration of security settings or access permissions. 7. Documents complex procedures and troubleshooting procedures related to systems and networks. 8. Configures, monitors, maintains, and oversees office and production software and utility software. 9. Evaluates and recommends new technologies, optimizes operational efficiency, and troubleshoots problems. 10. Participates in deployment of overall enterprise disaster recovery strategy. Minimum Qualifications - Education: Associate degree in computer science, computer engineering, information systems, or a closely-related field. - Experience: Five years of experience analyzing, installing, configuring, enhancing, and maintaining components of an enterprise network. - Substitution: Additional experience may substitute for the required degree on a year-for-year basis up to a maximum of two years. Completion of the 1010 Information Systems Trainee Program may also substitute for the degree. Special Requirements - Must complete a Supplemental Questionnaire as part of the online application process. - Must have access to a computer and reliable internet connection to take the online core exam. - San Francisco Airport positions require TSA Security Clearance and Customs Clearance. - Sheriff's Department positions require security clearance issued by the Sheriff's Department. - Port positions require a Transportation Worker Identification Credential and insurability under the automobile liability policy. Selection Process 1. Application Review: Candidates must complete the Supplemental Questionnaire and self-certify minimum qualifications. 2. Core Exam: Candidates take the online Tech Engineer - Systems Core Exam, which consists of 25 questions to be completed within 60 minutes. 3. Score Banking: Exam scores are banked for three years from the date of the examination. 4. Eligible List: Passing candidates are placed on an eligible list for 12 months under the Rule of the List certification rule. How to Apply - Submit an online application and Supplemental Questionnaire at the City career website. - Ensure your registered email address is accurate and not blocked by spam filters. - Retain the confirmation email received as proof of submission. Employment Details - Employer: City and County of San Francisco. - Recruitment: Continuous recruitment with no closing date. - Equal Opportunity: Encourages applications from women, minorities, and persons with disabilities. - Disaster Service Worker: All City employees are designated as Disaster Service Workers.
ABOUT THE ROLE This position is within the Legal Services Division of the District of Columbia Health Benefit Exchange Authority (DCHBX). The incumbent provides legal consultation to the HBX Board of Directors, Senior Management, and staff. The role specifically oversees the agency's privacy and security processes, ensures compliance with District and federal laws, and advises leadership on the adoption, governance, and implementation of Artificial Intelligence (AI) tools. KEY RESPONSIBILITIES - Serve as a key advisor to the General Counsel, Deputy General Counsel, and Executive Director on privacy, security, AI, and other policy matters. - Act as lead agency counsel on privacy and security, developing policies, monitoring legal changes, overseeing incident protocols, and delivering training. - Serve as staff lead for the agency AI governance committee, supporting the development and maintenance of AI governance frameworks, policies, and controls. - Advise on AI risk identification, mitigation strategies, human oversight, testing protocols, and review proposed AI use cases for bias and risks. - Research and prepare responses to sensitive inquiries from Congress, the Mayor, Council members, media, and the public. - Prepare testimony for senior management for public hearings before the Council of the District of Columbia and congressional committees. - Prepare legal documents, summary analyses, and policy recommendations on complex and urgent matters. MINIMUM QUALIFICATIONS - Juris Doctor (J.D.) from an accredited law school. - Active membership in the District of Columbia Bar. - At least one year of specialized experience equivalent to the next lower grade level in the normal line of progression for the occupation. SPECIAL REQUIREMENTS - Tour of Duty: Monday through Friday, 8:15 a.m. to 4:45 p.m. - Pay Plan, Series, Grade: LA-0905-15. - Security Sensitive: Subject to enhanced suitability screening, requiring successful passage of a criminal background and consumer credit check, with periodic checks during tenure. - Residency Requirement: Applicants claiming Residency Preference must maintain residency in the District of Columbia for a minimum of seven years. SELECTION PROCESS - Area of Consideration: Open to the Public. - Candidates will be evaluated based on specialized experience and alignment with the required qualifications. - Final selection is contingent upon successfully passing enhanced suitability screening, including criminal background and consumer credit checks. HOW TO APPLY 1. Submit an application through the official District of Columbia government job portal. 2. Ensure all required documentation reflecting specialized experience and qualifications is accurately detailed. 3. Apply before the closing date of August 22, 2026. EMPLOYMENT DETAILS - Employer: District of Columbia Health Benefit Exchange Authority (DCHBX) - Location: 1225 I Street, NW, Washington, DC - Job Type: Full-Time, Regular, Legal Service - Regular Appointment - Job ID: 33004 - Grade: 15 - Bargaining Unit: Not part of a collective bargaining unit - Opening Date: 07/24/2026 - Closing Date: 08/22/2026
About The Role The Network Team Supervisor leads the strategy, operations, and continuous improvement of MassDOT’s enterprise network infrastructure environment. This role oversees the implementation, support, security, and lifecycle management of core networking technologies across on-premises and cloud environments. The Supervisor manages a team of engineers and administrators to ensure reliability, performance, availability, security, compliance, and disaster recovery readiness. This position drives operational excellence through automation, standardization, and proactive service management while serving as a technical lead for small to mid-sized infrastructure projects. Key Responsibilities - Lead day-to-day operations of the enterprise network infrastructure team supporting switches, routers, firewalls, load balancers, and related technologies - Establish operational priorities, allocate resources, and manage workloads to align with organizational goals - Provide leadership, coaching, mentoring, and professional development to technical staff - Foster a collaborative, accountable, and customer-focused team culture promoting knowledge sharing and cross-training - Ensure compliance with MassDOT and EOTSS cybersecurity, operational, and governance standards - Oversee vulnerability remediation, patch management, audit response activities, and regulatory compliance initiatives - Develop and enforce network security standards, policies, and operational procedures - Ensure network infrastructure is monitored, documented, backed up, and recoverable per business continuity requirements - Implement monitoring, alerting, automation, and configuration management solutions to improve efficiency - Track, analyze, and report on operational metrics, service availability, and SLA performance - Manage relationships with network service providers and vendors - Lead incident response and escalation management to minimize downtime and service disruption - Identify modernization opportunities through automation, cloud integration, and process optimization - Collaborate with cybersecurity, cloud, systems, application, and vendor teams to resolve complex technical issues - Develop and review network architecture designs, implementation plans, technical standards, and documentation - Serve as project manager or technical lead for small to mid-sized projects including planning, execution, and risk management - Participate in budgeting, forecasting, vendor coordination, and strategic technology planning - Provide 24x7 operational leadership support for critical infrastructure incidents and emergency response as needed - Perform hands-on administration of network equipment when necessary Minimum Qualifications - At least three years of full-time or equivalent part-time professional experience in IT service management operations - Substitutions: Associate’s degree substitutes for one year; Bachelor’s degree substitutes for two years; Master’s degree substitutes for all required experience - All applications must be submitted online through MassCareers - Current MassDOT employees must use their internal MassCareers account Special Requirements - Preferred experience with cloud networking and infrastructure technologies including AWS - Preferred experience with network automation and Infrastructure as Code (IaC) tools - Familiarity with zero trust architecture, SD-WAN, and modern network security frameworks - ITIL certification or equivalent IT service management experience preferred - Relevant industry certifications such as CCNP, Fortinet NSE, or AWS preferred - Potentially eligible for a hybrid work schedule - Must be available for 24x7 operational leadership support during critical incidents Selection Process First consideration will be given to applicants who apply within the first 14 days. The requisition remains open until filled. Applicants must submit a complete, accurate, and current resume/application via MassCareers to determine if minimum entrance requirements are met. For questions regarding the posting, email talentacquisition@dot.state.ma.us. For general inquiries, call HR at 857-368-4722. For disability-related accommodations, contact ADA Coordinator Lucy Bayard at 857-274-1935 or Diversity Officer Derrick Mann at 857-368-8541. How To Apply Submit a complete application and resume online through MassCareers. Current MassDOT employees must apply via their internal MassCareers account. Applications are reviewed to verify minimum entrance requirements. Employment Details - Agency: Massachusetts Department of Transportation - Official Title: IT Service Mgmt & Ops Supv - Primary Location: 10 Park Plaza, Boston, Massachusetts - Schedule: Full-time, Day Shift - Bargaining Unit: DOT - Number of Openings: 1 - Confidential: No - Equal Opportunity/Affirmative Action Employer encouraging females, minorities, veterans, and persons with disabilities to apply
ABOUT THE ROLE Reporting to the Manager of Information Security Programs within the Security Technology and Programs Department, this role plays a key part in adopting and maturing the agency's Information Security Program. The specialist will own policy, training, risk, and governance frameworks, partnering with Departmental Information Security Officers to ensure consistent implementation. Additionally, the role involves researching, developing, and managing an Artificial Intelligence security program for the Office of the Chief Security Officer across a large, complex, and operationally intensive environment. KEY RESPONSIBILITIES - Build and mature the Information Security Program through strong governance, automation, and continuous improvement - Elevate Information Security awareness and strengthen relationships with Departmental Information Security Officers and Security Information Managers - Review agency presentations, drawings, and documents to ensure protected information is not exposed before external distribution - Develop agency-wide training for the Information Security Handbook - Manage AI and cybersecurity risks by anticipating threats, assessing controls, and driving practical mitigations - Evaluate and pilot emerging technologies alongside agency innovation initiatives - Assist with Insider Risk, SAFETY Act applications, security governance, and business continuity programs MINIMUM QUALIFICATIONS - Bachelor's degree in Criminal Justice, Technology, Law, Public Administration, Cybersecurity, or a related field - At least 3 years of experience in information security, technology, risk management, or program management - Demonstrated experience in information security, risk analysis, or security governance within a large or complex organization - Demonstrated experience collaborating with diverse technical, operational, and external stakeholders - Strong ownership mindset, proactive problem-solving skills, and the ability to drive initiatives across multiple departments SPECIAL REQUIREMENTS - Must undergo and clear a background investigation conducted by the Port Authority Police Department - Remote work is permitted a maximum of one day per week; regular in-office or team collaboration days are required based on business needs - Location flexibility: Can be based in New York or New Jersey depending on the selected candidate's preference SELECTION PROCESS - Initial phone interview for qualified candidates - In-depth interview(s) and/or assessment(s) - Conditional job offer followed by a mandatory background check HOW TO APPLY - Submit a resume through the official Port Authority of New York and New Jersey careers portal by clicking the "Apply Now" button - Only applicants under consideration will be contacted EMPLOYMENT DETAILS - Job ID: 64371 - Department: Security Technology & Programs - Employer: Port Authority of New York and New Jersey - Work Location: Jersey City, NJ (or New York, based on candidate preference) - Telework: Hybrid (Maximum one day per week remote) - Job Type: Full-Time





