
Policies Before Passwords: The Case for Governance-Led Cyber Strategy
Cities today are racing to be “smart,” but without smart governance, technology only amplifies risk. Cybersecurity isn’t just about defending networks- it’s about defining accountability, aligning decisions, and sustaining trust. A governance-first approach ensures that every cyber investment serves a purpose, every policy reflects shared values, and every response is measured and mature. Whether your city is modernizing its infrastructure or safeguarding citizen data, the real strength lies not in the tools you buy but in the structure you build. Governance is the blueprint for digital resilience.
Governance as the Cornerstone of Cybersecurity Maturity
A governance-first approach enables cities to align cybersecurity efforts with organizational priorities, risk tolerance, and legal obligations. Governance defines who is responsible for what, how decisions are made, and how outcomes are measured. Without clear governance, even the most advanced security tools can be misconfigured, underutilized, or misaligned with operational needs. The National Institute of Standards and Technology (NIST) emphasizes that cybersecurity governance is not a one-time effort but an ongoing function that must be embedded across all layers of management and operations1.
Effective governance frameworks typically incorporate a combination of leadership accountability, policy standardization, and continuous monitoring. These frameworks help cities prioritize investments, enforce compliance, and adapt to evolving threats. For example, the Center for Internet Security (CIS) recommends that local governments adopt governance structures that facilitate cross-departmental collaboration, define escalation paths for incidents, and include cybersecurity in strategic planning2. By treating governance as infrastructure, cities can build cybersecurity programs that are resilient, responsive, and transparent.
Leveraging Academic Models for Policy Design
Academic research institutions have developed robust models for structuring cybersecurity policy that are highly applicable to real-world environments. These models often include lifecycle-based governance, layered risk management, and evidence-based decision-making. For instance, Carnegie Mellon University's SEI Framework emphasizes the integration of cybersecurity principles into the full lifecycle of digital services, from procurement to decommissioning3. This approach reduces gaps and promotes sustainable practices.
Universities also play a key role in piloting modular policy templates that can be adapted by local governments. Programs like the University of Texas's Center for Infrastructure Assurance and Security provide municipalities with tested frameworks for incident response, data classification, and third-party risk management4. These academic partnerships enable cities to access rigorously validated methodologies without the overhead of developing policies from scratch. Adopting such research-backed structures ensures that city leaders are not relying solely on vendor guidance or outdated protocols.
The Workforce Imperative: Training Beyond Tools
Cybersecurity is not solely a technical issue. It is a human issue. Workforce training is essential to the success of any governance framework, particularly in environments where staff are responsible for critical infrastructure, citizen data, and emergency response. The Cybersecurity and Infrastructure Security Agency (CISA) has repeatedly highlighted that human error remains a leading cause of security breaches in local government systems5.
Structured workforce development programs should include awareness training for all employees, role-based training for technical staff, and leadership briefings to support executive decision-making. Cities that invest in ongoing education, tabletop exercises, and scenario-based simulations are significantly better prepared to respond to incidents. The Multi-State Information Sharing and Analysis Center (MS-ISAC) offers free training resources tailored to government environments, making this a practical starting point for cities enhancing their workforce readiness6.
Pilot Programs: Safe Zones for Innovation and Trust
Pilot programs offer cities a controlled environment to test new cybersecurity strategies, tools, and governance models before scaling them citywide. These initiatives can focus on high-risk systems, such as public safety networks or financial platforms, and provide valuable feedback loops for policymaking. By starting small, cities can identify gaps in policy, assess vendor performance, and refine procedures without exposing the entire organization to potential disruptions.
For example, the City of Los Angeles launched a pilot program to evaluate third-party risk management practices across its departments. The pilot revealed inconsistencies in contract language, insufficient monitoring, and fragmented data protection policies. These insights led to the development of a standardized vendor management framework adopted citywide7. This type of iterative innovation builds trust among stakeholders and demonstrates a commitment to measurable improvement.
Lifecycle Governance and Transparent Oversight: Building Long-Term Resilience
Long-term cybersecurity resilience requires governance that spans the entire lifecycle of digital assets. From acquisition and implementation to monitoring and retirement, every stage presents unique risks and accountability challenges. Cities that adopt lifecycle governance models can ensure continuity of controls, avoid technical debt, and maintain compliance with evolving regulations. The Federal Risk and Authorization Management Program (FedRAMP) provides a useful reference for lifecycle-based assessments, even though it is designed for federal use8.
Transparency is equally vital. Governance structures should include mechanisms for public reporting, internal audits, and independent reviews. These oversight functions not only enhance operational integrity but also boost public confidence. Cities like Seattle and Boston have implemented cybersecurity dashboards and annual reports to keep elected officials and residents informed about cyber readiness initiatives9. When governance is visible, it becomes a shared responsibility rather than an isolated function.
Call to Action: Structuring the Path to Cyber Maturity
City leaders and IT executives are encouraged to assess their current cybersecurity governance structures against established maturity models such as the NIST Cybersecurity Framework or CIS Controls Implementation Groups. This comparison can highlight gaps, prioritize improvements, and align cybersecurity efforts with strategic outcomes. A structured self-assessment provides a practical first step toward building a resilient digital infrastructure.
Consider developing a comprehensive guide focused on Responsible Cyber Policy, tailored to your city's unique needs. This guide should be a living document, updated regularly with stakeholder input, legal developments, and lessons learned from pilot efforts. In addition, hosting an interdepartmental cybersecurity readiness workshop can foster cross-functional collaboration and embed governance principles across your organization. By treating governance as an operational priority, cities set the foundation for safer, smarter, and more sustainable digital services.
Structured Security for Sustainable Cities
A secure city is not built through instinct. It is built through structure. When governance leads the process, technology becomes safer, people become more confident, and modernization becomes something a city can sustain for years. Moving beyond tools to focus on architectural integrity and shared accountability ensures that cybersecurity is not an afterthought but an operational discipline.
Cities that invest in governance-first cybersecurity are not just protecting systems. They are protecting public trust, service continuity, and future innovation. The path to cyber maturity begins with leadership, evolves through structure, and succeeds through collaboration.
Bibliography
National Institute of Standards and Technology. Cybersecurity Framework Version 1.1. Gaithersburg, MD: NIST, 2018. https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf.
Center for Internet Security. CIS Controls v8. East Greenbush, NY: CIS, 2021. https://www.cisecurity.org/controls/v8.
Carnegie Mellon University Software Engineering Institute. Cybersecurity Engineering for Software Assurance. Pittsburgh, PA: SEI, 2020. https://resources.sei.cmu.edu/library/asset-view.cfm?assetID=640043.
University of Texas at San Antonio Center for Infrastructure Assurance and Security. Cybersecurity Program Development Resources. San Antonio, TX: UTSA CIAS, 2022. https://cias.utsa.edu/programs/.
Cybersecurity and Infrastructure Security Agency. Cyber Essentials Toolkit. Washington, DC: CISA, 2020. https://www.cisa.gov/sites/default/files/publications/CyberEssentialsToolkit.pdf.
Multi-State Information Sharing and Analysis Center. Cybersecurity Training Resources. Albany, NY: MS-ISAC, 2023. https://www.cisecurity.org/ms-isac/services/training.
City of Los Angeles Information Technology Agency. Cyber Risk Management Pilot Program Summary. Los Angeles, CA: City of Los Angeles, 2021. https://ita.lacity.org/cyber-risk-pilot.
Federal Risk and Authorization Management Program. FedRAMP Security Assessment Framework. Washington, DC: GSA, 2021. https://www.fedramp.gov/assets/resources/documents/CSP_Security_Assessment_Framework.pdf.
City of Seattle Information Technology Department. Cybersecurity Annual Report 2022. Seattle, WA: City of Seattle, 2023. https://www.seattle.gov/tech/initiatives/cybersecurity.
More from Cybersecurity
Explore related articles on similar topics
Top Paying Jobs in Cybersecurity
Highest paying opportunities related to this article
About the Role This is the highest level in the Engineer series for the City and County of San Francisco. Under general supervision, you will analyze, plan, implement, maintain, troubleshoot, and enhance large complex systems or networks. You may function as a supervisor, expert, or project leader, serving as a lead assistant technical architect and systems integrator for large-scale enterprise networking backbones. Key Responsibilities - Conceptualize, plan, and ensure the maintenance, design, implementation, and enhancement of commercial software, internally developed applications, and web services. - Oversee the customization of new features to software packages and internal applications according to end-user requests. - Oversee the day-to-day operations of various applications and the development of new applications based on customer requirements. - Design and write test plans, ensure application performance, lead the implementation of fixes, and lead product launches. - Provide leadership for technical support and lead the troubleshooting of application-related problems. - Lead and guide the writing of technical documentation and develop best practices for version control and testing. - Oversee software upgrades, track software licensing, and manage vendor relationships including scoping services and reviewing deliverables. Minimum Qualifications - Education: Possession of an associate degree in computer science, computer engineering, information systems, or a closely-related field from an accredited college or university. Equivalent course credits require at least 60 semester or 90 quarter units, with a minimum of 20 semester or 30 quarter units in the specified fields. - Experience: Five years of experience analyzing, installing, configuring, enhancing, and/or maintaining the components of an enterprise network. - Substitutions: Additional qualifying experience may substitute for the required degree on a year-for-year basis up to a maximum of two years. Completion of the 1010 Information Systems Trainee Program may also substitute for the degree. Special Requirements - Must complete a Supplemental Questionnaire to self-certify qualifications during the application process. - Must have access to a computer and reliable internet connection to take the online exam. - Department-specific requirements may apply based on placement: - San Francisco Airport: Requires TSA Security Clearance and Customs Access Seal. - Sheriff's Department: Requires security clearance issued by the Sheriff's Department. - Port Commission: Requires a Transportation Worker Identification Credential and insurability under the Port automobile liability policy. Selection Process 1. Supplemental Questionnaire: Candidates must complete this during the online application to self-certify qualifications. 2. Tech Engineer - Applications Core Exam (100% weight): An online, computer-administered test consisting of 25 questions to be completed within 60 minutes. It measures technical abilities such as web app development, troubleshooting, analytical thinking, and database knowledge. 3. Score Banking: Passing scores are banked for three years and can be applied to future related announcements. 4. Eligible List: Candidates who pass are placed on an eligible list for 12 months for certification and hiring purposes. How to Apply - Applications are accepted online only at https://careers.sf.gov/interest/tech/. - Select the Apply Now button at the top of the job ad and follow the on-screen instructions. - Ensure your registered email address is accurate and that emails from CCSF domains are not blocked by spam filters. Employment Details - Employer: City and County of San Francisco - Application Opening: May 25, 2022 (Reposted November 6, 2023) - Application Deadline: Continuous - Equal Opportunity: The city encourages women, minorities, and persons with disabilities to apply and considers all applicants regardless of protected categories.
About the Role The Principal Security Engineer is the highest level in the Engineer series, involving the analysis, planning, implementation, and enhancement of large complex systems or networks. The role may function as a supervisor, expert, or project leader, serving as a lead technical architect and systems integrator focused on securing vulnerabilities and reducing risk. Key Responsibilities - Architect, design, implement, maintain, and operate information system security controls and countermeasures. - Analyze and recommend security controls in the acquisition, development, and change management lifecycle of information systems. - Monitor information systems for security incidents and vulnerabilities, developing monitoring capabilities. - Oversee the response to security incidents, including investigation, countermeasures, and recovery from attacks. - Oversee the administration of authentication and access controls for user and system accounts. - Analyze trends in the threat and compliance environment, advising management on risk mitigation. - Oversee the development of information security governance, policies, procedures, and standards. - Oversee the development and administration of information security training and awareness programs. Minimum Qualifications - Education: An associate degree in computer science, computer engineering, information systems, or a closely-related field from an accredited college or university, requiring at least 60 semester or 90 quarter credits, with a minimum of 20 semester or 30 quarter credits in the specified fields. - Experience: Five years of experience analyzing, installing, configuring, enhancing, and/or maintaining the components of an enterprise network. - Substitution: Additional qualifying experience may substitute for the required degree on a year-for-year basis up to a maximum of two years. Completion of the 1010 Information Systems Trainee Program may also substitute for the degree. Special Requirements - San Francisco Airport positions require a TSA Security Clearance and a Customs Access Seal. - Sheriff's Department positions require a security clearance issued by the Sheriff's Department. - Port Commission positions require a Transportation Worker Identification Credential certificate and insurability under the Port's automobile liability insurance policy. Selection Process 1. Application submission and completion of a Supplemental Questionnaire to self-certify qualifications. 2. Tech Engineer - Security Core Exam: An online test measuring knowledge in security operations, engineering, network security, asset security, identity and access management, mobile security, and security assessment. 3. Placement on a confidential eligible list for 12 months upon passing the exam. How to Apply - Apply online only by visiting https://careers.sf.gov/interest/tech/. - Select Apply Now at the top of the job ad and follow the screen instructions. - Ensure your registered email address is accurate and unblocked to receive messages from SF government domains. - Retain the confirmation email received after successful submission. Employment Details - Employer: City and County of San Francisco. - Position Type: Continuous application deadline with Rule of the List certification. - Equal Employment Opportunity: The City encourages women, minorities, and persons with disabilities to apply, considering all applicants regardless of protected categories under the law.
About the Role - Assists in analyzing, planning, implementing, maintaining, troubleshooting, and enhancing large complex systems or networks. - The 1044 Principal Systems Engineer is the highest level in the Engineer series. - May function as a supervisor, expert, or project leader. - Serves as a lead technical architect and systems integrator for large complex systems or networks. Key Responsibilities 1. Oversees day-to-day operational support for server, storage, or network infrastructures. 2. Oversees building, patching, testing, and deployment of systems and platforms. 3. Oversees, plans, and implements changes to infrastructure to enhance performance. 4. Oversees storage and server data backup, data migration, and disaster recovery operations. 5. Oversees software and operating system upgrades and tracks system licensing. 6. Oversees configuration of security settings or access permissions. 7. Documents complex procedures and troubleshooting procedures related to systems and networks. 8. Configures, monitors, maintains, and oversees office and production software and utility software. 9. Evaluates and recommends new technologies, optimizes operational efficiency, and troubleshoots problems. 10. Participates in deployment of overall enterprise disaster recovery strategy. Minimum Qualifications - Education: Associate degree in computer science, computer engineering, information systems, or a closely-related field. - Experience: Five years of experience analyzing, installing, configuring, enhancing, and maintaining components of an enterprise network. - Substitution: Additional experience may substitute for the required degree on a year-for-year basis up to a maximum of two years. Completion of the 1010 Information Systems Trainee Program may also substitute for the degree. Special Requirements - Must complete a Supplemental Questionnaire as part of the online application process. - Must have access to a computer and reliable internet connection to take the online core exam. - San Francisco Airport positions require TSA Security Clearance and Customs Clearance. - Sheriff's Department positions require security clearance issued by the Sheriff's Department. - Port positions require a Transportation Worker Identification Credential and insurability under the automobile liability policy. Selection Process 1. Application Review: Candidates must complete the Supplemental Questionnaire and self-certify minimum qualifications. 2. Core Exam: Candidates take the online Tech Engineer - Systems Core Exam, which consists of 25 questions to be completed within 60 minutes. 3. Score Banking: Exam scores are banked for three years from the date of the examination. 4. Eligible List: Passing candidates are placed on an eligible list for 12 months under the Rule of the List certification rule. How to Apply - Submit an online application and Supplemental Questionnaire at the City career website. - Ensure your registered email address is accurate and not blocked by spam filters. - Retain the confirmation email received as proof of submission. Employment Details - Employer: City and County of San Francisco. - Recruitment: Continuous recruitment with no closing date. - Equal Opportunity: Encourages applications from women, minorities, and persons with disabilities. - Disaster Service Worker: All City employees are designated as Disaster Service Workers.
About the Role This is the advanced journey level in the Engineer series for the City and County of San Francisco. Under general supervision, you will analyze, plan, implement, maintain, troubleshoot, and enhance large complex systems or networks. You will serve as a senior technical architect and systems integrator with a primary focus on securing vulnerabilities and reducing the risk of system compromises. This role requires highly specialized knowledge and the exercise of independent judgment. Key Responsibilities - Architect, design, implement, maintain, and operate information system security controls and countermeasures. - Analyze and recommend security controls in the acquisition, development, and change management lifecycles of information systems. - Monitor information systems for security incidents and vulnerabilities, develop monitoring capabilities, and report on trends. - Respond to security incidents, investigate attacks, and coordinate with third-party responders and law enforcement. - Administer authentication and access controls, including provisioning and deprovisioning of user and system accounts. - Analyze threat and compliance trends, advise management, execute mitigation plans, and perform risk assessments. - Develop information security governance, including organizational policies, procedures, standards, and guidelines. - Develop, administer, or provide oversight for information security training and awareness programs. Minimum Qualifications - Education: Possession of an associate degree in computer science, computer engineering, information systems, or a closely-related field. Equivalent course credits require at least 60 semester or 90 quarter units total, with a minimum of 20 semester or 30 quarter units in the specified fields. - Experience: Three years of experience analyzing, installing, configuring, enhancing, and/or maintaining the components of an enterprise network. - Substitutions: Additional qualifying experience may substitute for the required degree on a year-for-year basis up to a maximum of two years. Completion of the 1010 Information Systems Trainee Program may also substitute for the degree. Special Requirements - Must complete a Supplemental Questionnaire to self-certify qualifications during the application process. - Must have access to a computer and reliable internet connection to take the online exam. - Department-specific requirements may apply based on placement, including TSA Security Clearance and Customs Access Seal for the Airport Commission, Sheriff's Department security clearance, or a TWIC certificate for the Port Commission. Selection Process 1. Supplemental Questionnaire: Candidates must complete this during the online application to self-certify qualifications. 2. Tech Engineer - Security Core Exam (100% weight): An online, computer-administered test consisting of 20 questions to be completed within 50 minutes. It measures knowledge of security operations, engineering, network security, identity and access management, and security assessment. 3. Score Banking: Passing scores are banked for three years and can be applied to future related announcements. 4. Eligible List: Candidates who pass are placed on an eligible list for 12 months for certification and hiring purposes. How to Apply - Applications are accepted online only at https://careers.sf.gov/interest/tech/. - Select the Apply Now button at the top of the job ad and follow the on-screen instructions. - Ensure your registered email address is accurate and that emails from CCSF domains are not blocked by spam filters. Employment Details - Employer: City and County of San Francisco - Application Opening: May 25, 2022 (Reposted November 6, 2023) - Application Deadline: Continuous - Equal Opportunity: The city encourages women, minorities, and persons with disabilities to apply and considers all applicants regardless of protected categories.
About the Role - Assists in analyzing, planning, implementing, maintaining, troubleshooting, and enhancing large complex systems or networks. - The 1044 Principal Systems Engineer is the highest level in the Engineer series. - May function as a supervisor, expert, or project leader. - Serves as a lead technical architect and systems integrator for large complex systems or networks. Key Responsibilities 1. Oversees day-to-day operational support for server, storage, or network infrastructures. 2. Oversees building, patching, testing, and deployment of systems and platforms. 3. Oversees, plans, and implements changes to infrastructure to enhance performance. 4. Oversees storage and server data backup, data migration, and disaster recovery operations. 5. Oversees software and operating system upgrades and tracks system licensing. 6. Oversees configuration of security settings or access permissions. 7. Documents complex procedures and troubleshooting procedures related to systems and networks. 8. Configures, monitors, maintains, and oversees office and production software and utility software. 9. Evaluates and recommends new technologies, optimizes operational efficiency, and troubleshoots problems. 10. Participates in deployment of overall enterprise disaster recovery strategy. Minimum Qualifications - Education: Associate degree in computer science, computer engineering, information systems, or a closely-related field. - Experience: Five years of experience analyzing, installing, configuring, enhancing, and maintaining components of an enterprise network. - Substitution: Additional experience may substitute for the required degree on a year-for-year basis up to a maximum of two years. Completion of the 1010 Information Systems Trainee Program may also substitute for the degree. Special Requirements - Must complete a Supplemental Questionnaire as part of the online application process. - Must have access to a computer and reliable internet connection to take the online core exam. - San Francisco Airport positions require TSA Security Clearance and Customs Clearance. - Sheriff's Department positions require security clearance issued by the Sheriff's Department. - Port positions require a Transportation Worker Identification Credential and insurability under the automobile liability policy. Selection Process 1. Application Review: Candidates must complete the Supplemental Questionnaire and self-certify minimum qualifications. 2. Core Exam: Candidates take the online Tech Engineer - Systems Core Exam, which consists of 25 questions to be completed within 60 minutes. 3. Score Banking: Exam scores are banked for three years from the date of the examination. 4. Eligible List: Passing candidates are placed on an eligible list for 12 months under the Rule of the List certification rule. How to Apply - Submit an online application and Supplemental Questionnaire at the City career website. - Ensure your registered email address is accurate and not blocked by spam filters. - Retain the confirmation email received as proof of submission. Employment Details - Employer: City and County of San Francisco. - Recruitment: Continuous recruitment with no closing date. - Equal Opportunity: Encourages applications from women, minorities, and persons with disabilities. - Disaster Service Worker: All City employees are designated as Disaster Service Workers.
ABOUT THE ROLE This position is within the Legal Services Division of the District of Columbia Health Benefit Exchange Authority (DCHBX). The incumbent provides legal consultation to the HBX Board of Directors, Senior Management, and staff. The role specifically oversees the agency's privacy and security processes, ensures compliance with District and federal laws, and advises leadership on the adoption, governance, and implementation of Artificial Intelligence (AI) tools. KEY RESPONSIBILITIES - Serve as a key advisor to the General Counsel, Deputy General Counsel, and Executive Director on privacy, security, AI, and other policy matters. - Act as lead agency counsel on privacy and security, developing policies, monitoring legal changes, overseeing incident protocols, and delivering training. - Serve as staff lead for the agency AI governance committee, supporting the development and maintenance of AI governance frameworks, policies, and controls. - Advise on AI risk identification, mitigation strategies, human oversight, testing protocols, and review proposed AI use cases for bias and risks. - Research and prepare responses to sensitive inquiries from Congress, the Mayor, Council members, media, and the public. - Prepare testimony for senior management for public hearings before the Council of the District of Columbia and congressional committees. - Prepare legal documents, summary analyses, and policy recommendations on complex and urgent matters. MINIMUM QUALIFICATIONS - Juris Doctor (J.D.) from an accredited law school. - Active membership in the District of Columbia Bar. - At least one year of specialized experience equivalent to the next lower grade level in the normal line of progression for the occupation. SPECIAL REQUIREMENTS - Tour of Duty: Monday through Friday, 8:15 a.m. to 4:45 p.m. - Pay Plan, Series, Grade: LA-0905-15. - Security Sensitive: Subject to enhanced suitability screening, requiring successful passage of a criminal background and consumer credit check, with periodic checks during tenure. - Residency Requirement: Applicants claiming Residency Preference must maintain residency in the District of Columbia for a minimum of seven years. SELECTION PROCESS - Area of Consideration: Open to the Public. - Candidates will be evaluated based on specialized experience and alignment with the required qualifications. - Final selection is contingent upon successfully passing enhanced suitability screening, including criminal background and consumer credit checks. HOW TO APPLY 1. Submit an application through the official District of Columbia government job portal. 2. Ensure all required documentation reflecting specialized experience and qualifications is accurately detailed. 3. Apply before the closing date of August 22, 2026. EMPLOYMENT DETAILS - Employer: District of Columbia Health Benefit Exchange Authority (DCHBX) - Location: 1225 I Street, NW, Washington, DC - Job Type: Full-Time, Regular, Legal Service - Regular Appointment - Job ID: 33004 - Grade: 15 - Bargaining Unit: Not part of a collective bargaining unit - Opening Date: 07/24/2026 - Closing Date: 08/22/2026
About The Role The Network Team Supervisor leads the strategy, operations, and continuous improvement of MassDOT’s enterprise network infrastructure environment. This role oversees the implementation, support, security, and lifecycle management of core networking technologies across on-premises and cloud environments. The Supervisor manages a team of engineers and administrators to ensure reliability, performance, availability, security, compliance, and disaster recovery readiness. This position drives operational excellence through automation, standardization, and proactive service management while serving as a technical lead for small to mid-sized infrastructure projects. Key Responsibilities - Lead day-to-day operations of the enterprise network infrastructure team supporting switches, routers, firewalls, load balancers, and related technologies - Establish operational priorities, allocate resources, and manage workloads to align with organizational goals - Provide leadership, coaching, mentoring, and professional development to technical staff - Foster a collaborative, accountable, and customer-focused team culture promoting knowledge sharing and cross-training - Ensure compliance with MassDOT and EOTSS cybersecurity, operational, and governance standards - Oversee vulnerability remediation, patch management, audit response activities, and regulatory compliance initiatives - Develop and enforce network security standards, policies, and operational procedures - Ensure network infrastructure is monitored, documented, backed up, and recoverable per business continuity requirements - Implement monitoring, alerting, automation, and configuration management solutions to improve efficiency - Track, analyze, and report on operational metrics, service availability, and SLA performance - Manage relationships with network service providers and vendors - Lead incident response and escalation management to minimize downtime and service disruption - Identify modernization opportunities through automation, cloud integration, and process optimization - Collaborate with cybersecurity, cloud, systems, application, and vendor teams to resolve complex technical issues - Develop and review network architecture designs, implementation plans, technical standards, and documentation - Serve as project manager or technical lead for small to mid-sized projects including planning, execution, and risk management - Participate in budgeting, forecasting, vendor coordination, and strategic technology planning - Provide 24x7 operational leadership support for critical infrastructure incidents and emergency response as needed - Perform hands-on administration of network equipment when necessary Minimum Qualifications - At least three years of full-time or equivalent part-time professional experience in IT service management operations - Substitutions: Associate’s degree substitutes for one year; Bachelor’s degree substitutes for two years; Master’s degree substitutes for all required experience - All applications must be submitted online through MassCareers - Current MassDOT employees must use their internal MassCareers account Special Requirements - Preferred experience with cloud networking and infrastructure technologies including AWS - Preferred experience with network automation and Infrastructure as Code (IaC) tools - Familiarity with zero trust architecture, SD-WAN, and modern network security frameworks - ITIL certification or equivalent IT service management experience preferred - Relevant industry certifications such as CCNP, Fortinet NSE, or AWS preferred - Potentially eligible for a hybrid work schedule - Must be available for 24x7 operational leadership support during critical incidents Selection Process First consideration will be given to applicants who apply within the first 14 days. The requisition remains open until filled. Applicants must submit a complete, accurate, and current resume/application via MassCareers to determine if minimum entrance requirements are met. For questions regarding the posting, email talentacquisition@dot.state.ma.us. For general inquiries, call HR at 857-368-4722. For disability-related accommodations, contact ADA Coordinator Lucy Bayard at 857-274-1935 or Diversity Officer Derrick Mann at 857-368-8541. How To Apply Submit a complete application and resume online through MassCareers. Current MassDOT employees must apply via their internal MassCareers account. Applications are reviewed to verify minimum entrance requirements. Employment Details - Agency: Massachusetts Department of Transportation - Official Title: IT Service Mgmt & Ops Supv - Primary Location: 10 Park Plaza, Boston, Massachusetts - Schedule: Full-time, Day Shift - Bargaining Unit: DOT - Number of Openings: 1 - Confidential: No - Equal Opportunity/Affirmative Action Employer encouraging females, minorities, veterans, and persons with disabilities to apply
ABOUT THE ROLE Reporting to the Manager of Information Security Programs within the Security Technology and Programs Department, this role plays a key part in adopting and maturing the agency's Information Security Program. The specialist will own policy, training, risk, and governance frameworks, partnering with Departmental Information Security Officers to ensure consistent implementation. Additionally, the role involves researching, developing, and managing an Artificial Intelligence security program for the Office of the Chief Security Officer across a large, complex, and operationally intensive environment. KEY RESPONSIBILITIES - Build and mature the Information Security Program through strong governance, automation, and continuous improvement - Elevate Information Security awareness and strengthen relationships with Departmental Information Security Officers and Security Information Managers - Review agency presentations, drawings, and documents to ensure protected information is not exposed before external distribution - Develop agency-wide training for the Information Security Handbook - Manage AI and cybersecurity risks by anticipating threats, assessing controls, and driving practical mitigations - Evaluate and pilot emerging technologies alongside agency innovation initiatives - Assist with Insider Risk, SAFETY Act applications, security governance, and business continuity programs MINIMUM QUALIFICATIONS - Bachelor's degree in Criminal Justice, Technology, Law, Public Administration, Cybersecurity, or a related field - At least 3 years of experience in information security, technology, risk management, or program management - Demonstrated experience in information security, risk analysis, or security governance within a large or complex organization - Demonstrated experience collaborating with diverse technical, operational, and external stakeholders - Strong ownership mindset, proactive problem-solving skills, and the ability to drive initiatives across multiple departments SPECIAL REQUIREMENTS - Must undergo and clear a background investigation conducted by the Port Authority Police Department - Remote work is permitted a maximum of one day per week; regular in-office or team collaboration days are required based on business needs - Location flexibility: Can be based in New York or New Jersey depending on the selected candidate's preference SELECTION PROCESS - Initial phone interview for qualified candidates - In-depth interview(s) and/or assessment(s) - Conditional job offer followed by a mandatory background check HOW TO APPLY - Submit a resume through the official Port Authority of New York and New Jersey careers portal by clicking the "Apply Now" button - Only applicants under consideration will be contacted EMPLOYMENT DETAILS - Job ID: 64371 - Department: Security Technology & Programs - Employer: Port Authority of New York and New Jersey - Work Location: Jersey City, NJ (or New York, based on candidate preference) - Telework: Hybrid (Maximum one day per week remote) - Job Type: Full-Time





