CityGov is proud to partner with Datawheel, the creators of Data USA, to provide our community with powerful access to public U.S. government data. Explore Data USA

Skip to main content
Ransomware Doesn’t Respect City Limits: Building Whole‑Region Cyber Resilience

Ransomware Doesn’t Respect City Limits: Building Whole‑Region Cyber Resilience

When cybercriminals can rent attack kits like software subscriptions, no city IT department- no matter how devoted- can win this fight alone. Regional cyber ecosystems flip the balance of power: one city’s close call becomes everyone’s early warning, a single university lab trains talent for an entire region, and shared services turn small budgets into big defenses. By plugging into regional threat intelligence, academic pipelines, and low-cost statewide programs, cities of any size can upgrade from “call IT when something breaks” to a coordinated, whole‑region shield against modern cyberattacks.

Why Regional Cyber Ecosystems Outperform Isolated City IT Departments

Traditional city IT departments often operate with limited budgets, legacy systems, and siloed teams. These departments are typically tasked with maintaining infrastructure, responding to incidents, and ensuring regulatory compliance, but they may lack the scale or expertise to respond to sophisticated cyber threats. Cybercriminals are becoming more organized, employing tactics like ransomware-as-a-service and large-scale phishing campaigns that outpace the reactive capabilities of isolated departments. By contrast, regional ecosystems bring together shared intelligence, pooled resources, and specialized expertise that no single city department can cultivate alone.

For example, regional cyber networks such as the Multi-State Information Sharing and Analysis Center (MS-ISAC) enable cities to receive real-time alerts, threat indicators, and mitigation guidance from a national pool of intelligence^1. When cities connect with academic institutions and industry partners, they gain access to advanced threat modeling, penetration testing, and security assessments that far exceed in-house capabilities. These partnerships also foster innovation by allowing cities to pilot emerging technologies in controlled environments before full-scale adoption. As a result, cities embedded within a regional framework are better equipped to prevent, detect, and recover from cyber incidents.

Building Talent Pipelines Through Academic and Civic Collaboration

One of the most effective strategies for long-term cyber resilience is investing in local talent pipelines. Universities and community colleges are increasingly aligning their curricula with the cybersecurity needs of local governments. Programs like the National Centers of Academic Excellence in Cybersecurity (CAE) designate institutions that meet rigorous standards for cyber education, making them valuable partners for city leaders seeking to develop a steady stream of qualified candidates^2. These academic partners can provide internships, capstone projects, and research collaborations that directly benefit city operations.

In practice, this means that cities can co-create training programs with nearby institutions to ensure that students graduate with relevant, mission-critical skills. For example, the City of San Antonio has partnered with the University of Texas at San Antonio's Cybersecurity Manufacturing Innovation Institute to train students on cyber-physical systems that protect water utilities and transportation networks^3. By participating in these models, cities not only build workforce capacity but also retain local talent by offering career pathways that begin in education and lead to civic service.

Integrating Cyber Education with City Workforce Development

Cybersecurity cannot be confined to IT departments alone. Phishing attacks, credential theft, and insider threats often target non-technical staff, making cyber awareness a citywide responsibility. Integrating cybersecurity training into workforce development programs ensures that all employees, from 911 dispatchers to procurement officers, understand their role in maintaining digital hygiene. Cities like Los Angeles have implemented comprehensive workforce cyber training as part of their Cyber Intrusion Command Center strategy, which includes tabletop exercises, phishing simulations, and secure data handling protocols^4.

Workforce integration also means creating roles that merge operational and cyber responsibilities. For example, appointing a Chief Information Security Officer (CISO) who reports to both the city manager and the IT department helps embed cybersecurity into strategic planning and budget decisions. Similarly, cross-functional teams that include HR, legal, and emergency management staff can ensure that cyber policies align with operational realities. This approach not only enhances incident response but also makes cybersecurity a shared value across departments.

Low-Cost Strategies for Aligning with Regional Cybersecurity Programs

Cities do not need massive capital outlays to participate in regional cybersecurity initiatives. Many benefits can be achieved through memoranda of understanding (MOUs), shared service agreements, and cooperative procurement contracts. For instance, the North Carolina Local Government Information Systems Association (NCLGISA) offers a cybersecurity advisory service that cities can join for a modest fee, gaining access to regional experts and shared threat intelligence^5. These types of consortia provide a cost-effective way to access resources that would otherwise be out of reach.

Additionally, cities can participate in federal programs like the Department of Homeland Security's State and Local Cybersecurity Grant Program, which funds regional planning and capability-building efforts^6. By working with their state’s Chief Risk Officer or cybersecurity coordinator, city leaders can tap into these resources without duplicating efforts. Simple steps such as joining regional working groups, attending cyber roundtables, or designating a cyber liaison can position a city to benefit from broader initiatives.

Governance Structures for Safe and Sustainable Cyber Tool Adoption

As cities adopt new technologies, governance becomes critical to ensuring that innovations are implemented securely and sustainably. Without clear policies, even well-intentioned deployments can introduce vulnerabilities. Establishing a cybersecurity governance framework allows city leaders to evaluate tools based on risk, compliance, and operational impact. For example, New York City’s Cyber Command has developed governance standards that require every new digital service to undergo a cybersecurity review before launch^7.

Effective governance also includes setting up incident response protocols, data classification policies, and vendor risk assessments. Cities can use standards such as the NIST Cybersecurity Framework to define these controls in a structured way^8. Importantly, governance should be a collaborative process. Including representatives from IT, legal, procurement, and departmental leadership ensures that policies are both technically sound and operationally realistic. This approach builds trust across departments and ensures that cybersecurity is not viewed as a barrier but as an enabler of innovation.

Next Steps for City Leaders

City agencies should begin by assessing whether their cybersecurity posture is rooted in partnerships or isolation. A simple Cyber Readiness Checklist can help identify gaps in regional collaboration, workforce skills, and governance maturity. For instance, does the city participate in a regional threat intelligence exchange? Are non-IT staff required to complete cyber awareness training? Are there formal agreements in place with local universities or research institutions? These questions help frame a path forward.

Leaders are encouraged to engage with regional roundtables focused on cyber governance and workforce modernization. These forums provide practical exposure to peer strategies, vendor solutions, and academic research. By taking part in these conversations, city officials can stay current with evolving threats while shaping the future of their own digital infrastructure. The goal is not just to defend against cyber risks, but to operationalize resilience through connection, talent, and shared strategy.

Bibliography

  1. Center for Internet Security. “MS-ISAC Services.” Accessed March 5, 2024. https://www.cisecurity.org/ms-isac/services.

  2. National Security Agency. “National Centers of Academic Excellence in Cybersecurity.” Last modified February 2024. https://www.nsa.gov/Academics/Centers-of-Academic-Excellence.

  3. Cybersecurity Manufacturing Innovation Institute. “Partnerships.” Accessed March 6, 2024. https://cybermi.org/partners.

  4. City of Los Angeles Cyber Intrusion Command Center. “Cybersecurity Strategy.” Accessed March 6, 2024. https://lacity.gov/cyberstrategy.

  5. North Carolina Local Government Information Systems Association. “Cybersecurity Services.” Accessed March 6, 2024. https://www.nclgisa.org/cybersecurity.

  6. Cybersecurity and Infrastructure Security Agency. “State and Local Cybersecurity Grant Program.” Last updated February 2024. https://www.cisa.gov/slcgp.

  7. New York City Cyber Command. “NYC Cybersecurity Policies and Standards.” Accessed March 5, 2024. https://www.nyc.gov/assets/cybercommand/downloads/pdf/nyc-cyber-policy.pdf.

  8. National Institute of Standards and Technology. “Framework for Improving Critical Infrastructure Cybersecurity.” Version 1.1, April 2018. https://www.nist.gov/cyberframework.

More from Cybersecurity

Explore related articles on similar topics

Top Paying Jobs in Cybersecurity

Highest paying opportunities related to this article

FULL TIME
Principal Information Systems Engineer - Applications Specialty - City and County of San Francisco - Multiple Departments Citywide - 1044
Tech Hire Program

About the Role This is the highest level in the Engineer series for the City and County of San Francisco. Under general supervision, you will analyze, plan, implement, maintain, troubleshoot, and enhance large complex systems or networks. You may function as a supervisor, expert, or project leader, serving as a lead assistant technical architect and systems integrator for large-scale enterprise networking backbones. Key Responsibilities - Conceptualize, plan, and ensure the maintenance, design, implementation, and enhancement of commercial software, internally developed applications, and web services. - Oversee the customization of new features to software packages and internal applications according to end-user requests. - Oversee the day-to-day operations of various applications and the development of new applications based on customer requirements. - Design and write test plans, ensure application performance, lead the implementation of fixes, and lead product launches. - Provide leadership for technical support and lead the troubleshooting of application-related problems. - Lead and guide the writing of technical documentation and develop best practices for version control and testing. - Oversee software upgrades, track software licensing, and manage vendor relationships including scoping services and reviewing deliverables. Minimum Qualifications - Education: Possession of an associate degree in computer science, computer engineering, information systems, or a closely-related field from an accredited college or university. Equivalent course credits require at least 60 semester or 90 quarter units, with a minimum of 20 semester or 30 quarter units in the specified fields. - Experience: Five years of experience analyzing, installing, configuring, enhancing, and/or maintaining the components of an enterprise network. - Substitutions: Additional qualifying experience may substitute for the required degree on a year-for-year basis up to a maximum of two years. Completion of the 1010 Information Systems Trainee Program may also substitute for the degree. Special Requirements - Must complete a Supplemental Questionnaire to self-certify qualifications during the application process. - Must have access to a computer and reliable internet connection to take the online exam. - Department-specific requirements may apply based on placement: - San Francisco Airport: Requires TSA Security Clearance and Customs Access Seal. - Sheriff's Department: Requires security clearance issued by the Sheriff's Department. - Port Commission: Requires a Transportation Worker Identification Credential and insurability under the Port automobile liability policy. Selection Process 1. Supplemental Questionnaire: Candidates must complete this during the online application to self-certify qualifications. 2. Tech Engineer - Applications Core Exam (100% weight): An online, computer-administered test consisting of 25 questions to be completed within 60 minutes. It measures technical abilities such as web app development, troubleshooting, analytical thinking, and database knowledge. 3. Score Banking: Passing scores are banked for three years and can be applied to future related announcements. 4. Eligible List: Candidates who pass are placed on an eligible list for 12 months for certification and hiring purposes. How to Apply - Applications are accepted online only at https://careers.sf.gov/interest/tech/. - Select the Apply Now button at the top of the job ad and follow the on-screen instructions. - Ensure your registered email address is accurate and that emails from CCSF domains are not blocked by spam filters. Employment Details - Employer: City and County of San Francisco - Application Opening: May 25, 2022 (Reposted November 6, 2023) - Application Deadline: Continuous - Equal Opportunity: The city encourages women, minorities, and persons with disabilities to apply and considers all applicants regardless of protected categories.

San Francisco, California
$167,804.00 - $238,862.00
TechnologyCybersecurityInfrastructure
about 2 months ago
Apply
FULL TIME
Principal Information Systems Engineer - Security Specialty - City and County of San Francisco - Multiple Departments Citywide – 1044
Tech Hire Program

About the Role The Principal Security Engineer is the highest level in the Engineer series, involving the analysis, planning, implementation, and enhancement of large complex systems or networks. The role may function as a supervisor, expert, or project leader, serving as a lead technical architect and systems integrator focused on securing vulnerabilities and reducing risk. Key Responsibilities - Architect, design, implement, maintain, and operate information system security controls and countermeasures. - Analyze and recommend security controls in the acquisition, development, and change management lifecycle of information systems. - Monitor information systems for security incidents and vulnerabilities, developing monitoring capabilities. - Oversee the response to security incidents, including investigation, countermeasures, and recovery from attacks. - Oversee the administration of authentication and access controls for user and system accounts. - Analyze trends in the threat and compliance environment, advising management on risk mitigation. - Oversee the development of information security governance, policies, procedures, and standards. - Oversee the development and administration of information security training and awareness programs. Minimum Qualifications - Education: An associate degree in computer science, computer engineering, information systems, or a closely-related field from an accredited college or university, requiring at least 60 semester or 90 quarter credits, with a minimum of 20 semester or 30 quarter credits in the specified fields. - Experience: Five years of experience analyzing, installing, configuring, enhancing, and/or maintaining the components of an enterprise network. - Substitution: Additional qualifying experience may substitute for the required degree on a year-for-year basis up to a maximum of two years. Completion of the 1010 Information Systems Trainee Program may also substitute for the degree. Special Requirements - San Francisco Airport positions require a TSA Security Clearance and a Customs Access Seal. - Sheriff's Department positions require a security clearance issued by the Sheriff's Department. - Port Commission positions require a Transportation Worker Identification Credential certificate and insurability under the Port's automobile liability insurance policy. Selection Process 1. Application submission and completion of a Supplemental Questionnaire to self-certify qualifications. 2. Tech Engineer - Security Core Exam: An online test measuring knowledge in security operations, engineering, network security, asset security, identity and access management, mobile security, and security assessment. 3. Placement on a confidential eligible list for 12 months upon passing the exam. How to Apply - Apply online only by visiting https://careers.sf.gov/interest/tech/. - Select Apply Now at the top of the job ad and follow the screen instructions. - Ensure your registered email address is accurate and unblocked to receive messages from SF government domains. - Retain the confirmation email received after successful submission. Employment Details - Employer: City and County of San Francisco. - Position Type: Continuous application deadline with Rule of the List certification. - Equal Employment Opportunity: The City encourages women, minorities, and persons with disabilities to apply, considering all applicants regardless of protected categories under the law.

San Francisco, California
$167,804.00 - $238,862.00
CybersecurityTechnologyInfrastructure
about 2 months ago
Apply
FULL TIME
Principal Information Systems Engineer - Systems Specialty - City and County of San Francisco - Multiple Departments Citywide – 1044
Multiple Departments

About the Role - Assists in analyzing, planning, implementing, maintaining, troubleshooting, and enhancing large complex systems or networks. - The 1044 Principal Systems Engineer is the highest level in the Engineer series. - May function as a supervisor, expert, or project leader. - Serves as a lead technical architect and systems integrator for large complex systems or networks. Key Responsibilities 1. Oversees day-to-day operational support for server, storage, or network infrastructures. 2. Oversees building, patching, testing, and deployment of systems and platforms. 3. Oversees, plans, and implements changes to infrastructure to enhance performance. 4. Oversees storage and server data backup, data migration, and disaster recovery operations. 5. Oversees software and operating system upgrades and tracks system licensing. 6. Oversees configuration of security settings or access permissions. 7. Documents complex procedures and troubleshooting procedures related to systems and networks. 8. Configures, monitors, maintains, and oversees office and production software and utility software. 9. Evaluates and recommends new technologies, optimizes operational efficiency, and troubleshoots problems. 10. Participates in deployment of overall enterprise disaster recovery strategy. Minimum Qualifications - Education: Associate degree in computer science, computer engineering, information systems, or a closely-related field. - Experience: Five years of experience analyzing, installing, configuring, enhancing, and maintaining components of an enterprise network. - Substitution: Additional experience may substitute for the required degree on a year-for-year basis up to a maximum of two years. Completion of the 1010 Information Systems Trainee Program may also substitute for the degree. Special Requirements - Must complete a Supplemental Questionnaire as part of the online application process. - Must have access to a computer and reliable internet connection to take the online core exam. - San Francisco Airport positions require TSA Security Clearance and Customs Clearance. - Sheriff's Department positions require security clearance issued by the Sheriff's Department. - Port positions require a Transportation Worker Identification Credential and insurability under the automobile liability policy. Selection Process 1. Application Review: Candidates must complete the Supplemental Questionnaire and self-certify minimum qualifications. 2. Core Exam: Candidates take the online Tech Engineer - Systems Core Exam, which consists of 25 questions to be completed within 60 minutes. 3. Score Banking: Exam scores are banked for three years from the date of the examination. 4. Eligible List: Passing candidates are placed on an eligible list for 12 months under the Rule of the List certification rule. How to Apply - Submit an online application and Supplemental Questionnaire at the City career website. - Ensure your registered email address is accurate and not blocked by spam filters. - Retain the confirmation email received as proof of submission. Employment Details - Employer: City and County of San Francisco. - Recruitment: Continuous recruitment with no closing date. - Equal Opportunity: Encourages applications from women, minorities, and persons with disabilities. - Disaster Service Worker: All City employees are designated as Disaster Service Workers.

San Francisco, California
$167,804.00 - $238,862.00
TechnologyCybersecurityInfrastructure
about 2 months ago
Apply
FULL TIME
Senior Information Systems Engineer – Security Specialty – City and County of San Francisco – Multiple Departments Citywide - 1043
Tech Hire Program

About the Role This is the advanced journey level in the Engineer series for the City and County of San Francisco. Under general supervision, you will analyze, plan, implement, maintain, troubleshoot, and enhance large complex systems or networks. You will serve as a senior technical architect and systems integrator with a primary focus on securing vulnerabilities and reducing the risk of system compromises. This role requires highly specialized knowledge and the exercise of independent judgment. Key Responsibilities - Architect, design, implement, maintain, and operate information system security controls and countermeasures. - Analyze and recommend security controls in the acquisition, development, and change management lifecycles of information systems. - Monitor information systems for security incidents and vulnerabilities, develop monitoring capabilities, and report on trends. - Respond to security incidents, investigate attacks, and coordinate with third-party responders and law enforcement. - Administer authentication and access controls, including provisioning and deprovisioning of user and system accounts. - Analyze threat and compliance trends, advise management, execute mitigation plans, and perform risk assessments. - Develop information security governance, including organizational policies, procedures, standards, and guidelines. - Develop, administer, or provide oversight for information security training and awareness programs. Minimum Qualifications - Education: Possession of an associate degree in computer science, computer engineering, information systems, or a closely-related field. Equivalent course credits require at least 60 semester or 90 quarter units total, with a minimum of 20 semester or 30 quarter units in the specified fields. - Experience: Three years of experience analyzing, installing, configuring, enhancing, and/or maintaining the components of an enterprise network. - Substitutions: Additional qualifying experience may substitute for the required degree on a year-for-year basis up to a maximum of two years. Completion of the 1010 Information Systems Trainee Program may also substitute for the degree. Special Requirements - Must complete a Supplemental Questionnaire to self-certify qualifications during the application process. - Must have access to a computer and reliable internet connection to take the online exam. - Department-specific requirements may apply based on placement, including TSA Security Clearance and Customs Access Seal for the Airport Commission, Sheriff's Department security clearance, or a TWIC certificate for the Port Commission. Selection Process 1. Supplemental Questionnaire: Candidates must complete this during the online application to self-certify qualifications. 2. Tech Engineer - Security Core Exam (100% weight): An online, computer-administered test consisting of 20 questions to be completed within 50 minutes. It measures knowledge of security operations, engineering, network security, identity and access management, and security assessment. 3. Score Banking: Passing scores are banked for three years and can be applied to future related announcements. 4. Eligible List: Candidates who pass are placed on an eligible list for 12 months for certification and hiring purposes. How to Apply - Applications are accepted online only at https://careers.sf.gov/interest/tech/. - Select the Apply Now button at the top of the job ad and follow the on-screen instructions. - Ensure your registered email address is accurate and that emails from CCSF domains are not blocked by spam filters. Employment Details - Employer: City and County of San Francisco - Application Opening: May 25, 2022 (Reposted November 6, 2023) - Application Deadline: Continuous - Equal Opportunity: The city encourages women, minorities, and persons with disabilities to apply and considers all applicants regardless of protected categories.

San Francisco, California
$156,000.00 - $196,300.00
CybersecurityTechnologyInfrastructure
about 2 months ago
Apply
FULL TIME
Senior Information Systems Engineer – Systems Specialty – City and County of San Francisco – Multiple Departments Citywide - 1043
Tech Hire Program

About the Role - Assists in analyzing, planning, implementing, maintaining, troubleshooting, and enhancing large complex systems or networks. - The 1044 Principal Systems Engineer is the highest level in the Engineer series. - May function as a supervisor, expert, or project leader. - Serves as a lead technical architect and systems integrator for large complex systems or networks. Key Responsibilities 1. Oversees day-to-day operational support for server, storage, or network infrastructures. 2. Oversees building, patching, testing, and deployment of systems and platforms. 3. Oversees, plans, and implements changes to infrastructure to enhance performance. 4. Oversees storage and server data backup, data migration, and disaster recovery operations. 5. Oversees software and operating system upgrades and tracks system licensing. 6. Oversees configuration of security settings or access permissions. 7. Documents complex procedures and troubleshooting procedures related to systems and networks. 8. Configures, monitors, maintains, and oversees office and production software and utility software. 9. Evaluates and recommends new technologies, optimizes operational efficiency, and troubleshoots problems. 10. Participates in deployment of overall enterprise disaster recovery strategy. Minimum Qualifications - Education: Associate degree in computer science, computer engineering, information systems, or a closely-related field. - Experience: Five years of experience analyzing, installing, configuring, enhancing, and maintaining components of an enterprise network. - Substitution: Additional experience may substitute for the required degree on a year-for-year basis up to a maximum of two years. Completion of the 1010 Information Systems Trainee Program may also substitute for the degree. Special Requirements - Must complete a Supplemental Questionnaire as part of the online application process. - Must have access to a computer and reliable internet connection to take the online core exam. - San Francisco Airport positions require TSA Security Clearance and Customs Clearance. - Sheriff's Department positions require security clearance issued by the Sheriff's Department. - Port positions require a Transportation Worker Identification Credential and insurability under the automobile liability policy. Selection Process 1. Application Review: Candidates must complete the Supplemental Questionnaire and self-certify minimum qualifications. 2. Core Exam: Candidates take the online Tech Engineer - Systems Core Exam, which consists of 25 questions to be completed within 60 minutes. 3. Score Banking: Exam scores are banked for three years from the date of the examination. 4. Eligible List: Passing candidates are placed on an eligible list for 12 months under the Rule of the List certification rule. How to Apply - Submit an online application and Supplemental Questionnaire at the City career website. - Ensure your registered email address is accurate and not blocked by spam filters. - Retain the confirmation email received as proof of submission. Employment Details - Employer: City and County of San Francisco. - Recruitment: Continuous recruitment with no closing date. - Equal Opportunity: Encourages applications from women, minorities, and persons with disabilities. - Disaster Service Worker: All City employees are designated as Disaster Service Workers.

San Francisco, California
$156,000.00 - $196,300.00
TechnologyCybersecurityInfrastructure
about 2 months ago
Apply
FULL TIME
Attorney Advisor (Privacy)
District of Columbia Health Benefit Exchange Authority (DCHBX)

ABOUT THE ROLE This position is within the Legal Services Division of the District of Columbia Health Benefit Exchange Authority (DCHBX). The incumbent provides legal consultation to the HBX Board of Directors, Senior Management, and staff. The role specifically oversees the agency's privacy and security processes, ensures compliance with District and federal laws, and advises leadership on the adoption, governance, and implementation of Artificial Intelligence (AI) tools. KEY RESPONSIBILITIES - Serve as a key advisor to the General Counsel, Deputy General Counsel, and Executive Director on privacy, security, AI, and other policy matters. - Act as lead agency counsel on privacy and security, developing policies, monitoring legal changes, overseeing incident protocols, and delivering training. - Serve as staff lead for the agency AI governance committee, supporting the development and maintenance of AI governance frameworks, policies, and controls. - Advise on AI risk identification, mitigation strategies, human oversight, testing protocols, and review proposed AI use cases for bias and risks. - Research and prepare responses to sensitive inquiries from Congress, the Mayor, Council members, media, and the public. - Prepare testimony for senior management for public hearings before the Council of the District of Columbia and congressional committees. - Prepare legal documents, summary analyses, and policy recommendations on complex and urgent matters. MINIMUM QUALIFICATIONS - Juris Doctor (J.D.) from an accredited law school. - Active membership in the District of Columbia Bar. - At least one year of specialized experience equivalent to the next lower grade level in the normal line of progression for the occupation. SPECIAL REQUIREMENTS - Tour of Duty: Monday through Friday, 8:15 a.m. to 4:45 p.m. - Pay Plan, Series, Grade: LA-0905-15. - Security Sensitive: Subject to enhanced suitability screening, requiring successful passage of a criminal background and consumer credit check, with periodic checks during tenure. - Residency Requirement: Applicants claiming Residency Preference must maintain residency in the District of Columbia for a minimum of seven years. SELECTION PROCESS - Area of Consideration: Open to the Public. - Candidates will be evaluated based on specialized experience and alignment with the required qualifications. - Final selection is contingent upon successfully passing enhanced suitability screening, including criminal background and consumer credit checks. HOW TO APPLY 1. Submit an application through the official District of Columbia government job portal. 2. Ensure all required documentation reflecting specialized experience and qualifications is accurately detailed. 3. Apply before the closing date of August 22, 2026. EMPLOYMENT DETAILS - Employer: District of Columbia Health Benefit Exchange Authority (DCHBX) - Location: 1225 I Street, NW, Washington, DC - Job Type: Full-Time, Regular, Legal Service - Regular Appointment - Job ID: 33004 - Grade: 15 - Bargaining Unit: Not part of a collective bargaining unit - Opening Date: 07/24/2026 - Closing Date: 08/22/2026

District of Columbia, Washington
$151,503.00-$193,382.00
Artificial IntelligenceCybersecurityPublic Policy
3 days ago
Apply
FULL TIME
Network Team Supervisor (IT Service Management and Operations Supervisor) - (260004PR)
Massachusetts Department of Transportation

About The Role The Network Team Supervisor leads the strategy, operations, and continuous improvement of MassDOT’s enterprise network infrastructure environment. This role oversees the implementation, support, security, and lifecycle management of core networking technologies across on-premises and cloud environments. The Supervisor manages a team of engineers and administrators to ensure reliability, performance, availability, security, compliance, and disaster recovery readiness. This position drives operational excellence through automation, standardization, and proactive service management while serving as a technical lead for small to mid-sized infrastructure projects. Key Responsibilities - Lead day-to-day operations of the enterprise network infrastructure team supporting switches, routers, firewalls, load balancers, and related technologies - Establish operational priorities, allocate resources, and manage workloads to align with organizational goals - Provide leadership, coaching, mentoring, and professional development to technical staff - Foster a collaborative, accountable, and customer-focused team culture promoting knowledge sharing and cross-training - Ensure compliance with MassDOT and EOTSS cybersecurity, operational, and governance standards - Oversee vulnerability remediation, patch management, audit response activities, and regulatory compliance initiatives - Develop and enforce network security standards, policies, and operational procedures - Ensure network infrastructure is monitored, documented, backed up, and recoverable per business continuity requirements - Implement monitoring, alerting, automation, and configuration management solutions to improve efficiency - Track, analyze, and report on operational metrics, service availability, and SLA performance - Manage relationships with network service providers and vendors - Lead incident response and escalation management to minimize downtime and service disruption - Identify modernization opportunities through automation, cloud integration, and process optimization - Collaborate with cybersecurity, cloud, systems, application, and vendor teams to resolve complex technical issues - Develop and review network architecture designs, implementation plans, technical standards, and documentation - Serve as project manager or technical lead for small to mid-sized projects including planning, execution, and risk management - Participate in budgeting, forecasting, vendor coordination, and strategic technology planning - Provide 24x7 operational leadership support for critical infrastructure incidents and emergency response as needed - Perform hands-on administration of network equipment when necessary Minimum Qualifications - At least three years of full-time or equivalent part-time professional experience in IT service management operations - Substitutions: Associate’s degree substitutes for one year; Bachelor’s degree substitutes for two years; Master’s degree substitutes for all required experience - All applications must be submitted online through MassCareers - Current MassDOT employees must use their internal MassCareers account Special Requirements - Preferred experience with cloud networking and infrastructure technologies including AWS - Preferred experience with network automation and Infrastructure as Code (IaC) tools - Familiarity with zero trust architecture, SD-WAN, and modern network security frameworks - ITIL certification or equivalent IT service management experience preferred - Relevant industry certifications such as CCNP, Fortinet NSE, or AWS preferred - Potentially eligible for a hybrid work schedule - Must be available for 24x7 operational leadership support during critical incidents Selection Process First consideration will be given to applicants who apply within the first 14 days. The requisition remains open until filled. Applicants must submit a complete, accurate, and current resume/application via MassCareers to determine if minimum entrance requirements are met. For questions regarding the posting, email talentacquisition@dot.state.ma.us. For general inquiries, call HR at 857-368-4722. For disability-related accommodations, contact ADA Coordinator Lucy Bayard at 857-274-1935 or Diversity Officer Derrick Mann at 857-368-8541. How To Apply Submit a complete application and resume online through MassCareers. Current MassDOT employees must apply via their internal MassCareers account. Applications are reviewed to verify minimum entrance requirements. Employment Details - Agency: Massachusetts Department of Transportation - Official Title: IT Service Mgmt & Ops Supv - Primary Location: 10 Park Plaza, Boston, Massachusetts - Schedule: Full-time, Day Shift - Bargaining Unit: DOT - Number of Openings: 1 - Confidential: No - Equal Opportunity/Affirmative Action Employer encouraging females, minorities, veterans, and persons with disabilities to apply

Boston, Massachusetts
106,638.68 - 156,601.78 Yearly
TechnologyCybersecurityManagement and Finance
22 days ago
Apply
FULL TIME
Senior Information Security Specialist, Office of the Chief Security Officer
Port Authority of New York and New Jersey’s Office of the Chief Security Officer (OCSO)

ABOUT THE ROLE Reporting to the Manager of Information Security Programs within the Security Technology and Programs Department, this role plays a key part in adopting and maturing the agency's Information Security Program. The specialist will own policy, training, risk, and governance frameworks, partnering with Departmental Information Security Officers to ensure consistent implementation. Additionally, the role involves researching, developing, and managing an Artificial Intelligence security program for the Office of the Chief Security Officer across a large, complex, and operationally intensive environment. KEY RESPONSIBILITIES - Build and mature the Information Security Program through strong governance, automation, and continuous improvement - Elevate Information Security awareness and strengthen relationships with Departmental Information Security Officers and Security Information Managers - Review agency presentations, drawings, and documents to ensure protected information is not exposed before external distribution - Develop agency-wide training for the Information Security Handbook - Manage AI and cybersecurity risks by anticipating threats, assessing controls, and driving practical mitigations - Evaluate and pilot emerging technologies alongside agency innovation initiatives - Assist with Insider Risk, SAFETY Act applications, security governance, and business continuity programs MINIMUM QUALIFICATIONS - Bachelor's degree in Criminal Justice, Technology, Law, Public Administration, Cybersecurity, or a related field - At least 3 years of experience in information security, technology, risk management, or program management - Demonstrated experience in information security, risk analysis, or security governance within a large or complex organization - Demonstrated experience collaborating with diverse technical, operational, and external stakeholders - Strong ownership mindset, proactive problem-solving skills, and the ability to drive initiatives across multiple departments SPECIAL REQUIREMENTS - Must undergo and clear a background investigation conducted by the Port Authority Police Department - Remote work is permitted a maximum of one day per week; regular in-office or team collaboration days are required based on business needs - Location flexibility: Can be based in New York or New Jersey depending on the selected candidate's preference SELECTION PROCESS - Initial phone interview for qualified candidates - In-depth interview(s) and/or assessment(s) - Conditional job offer followed by a mandatory background check HOW TO APPLY - Submit a resume through the official Port Authority of New York and New Jersey careers portal by clicking the "Apply Now" button - Only applicants under consideration will be contacted EMPLOYMENT DETAILS - Job ID: 64371 - Department: Security Technology & Programs - Employer: Port Authority of New York and New Jersey - Work Location: Jersey City, NJ (or New York, based on candidate preference) - Telework: Hybrid (Maximum one day per week remote) - Job Type: Full-Time

Jersey City, New Jersey
Minimum: $97,162 Midpoint: $126,326 Maximum: $155,480​
CybersecurityArtificial IntelligenceTechnology
14 days ago
Apply