Cybersecurity Engineer Level 4 - PAM
Description
JOB TITLE: | Cybersecurity Engineer Level 4 |
SALARY RANGE: | $105,843 - $143,948 |
DEPT/DIV: | Information Technology |
SUPERVISOR: | CybSecOffMgr AccesMgmtIdentSec |
LOCATION: | 2 Broadway, New York, NY 10004 |
HOURS OF WORK: | 9:00 am - 5:30 pm (7.5 hours/day) or as required |
This position is eligible for teleworking, which is currently one day per week. New hires are eligible to apply 30 days after their effective date of hire.
Opening:
The Metropolitan Transportation Authority is North America's largest transportation network, serving a population of 15.3 million people across a 5,000-square-mile travel area surrounding New York City, Long Island, southeastern New York State, and Connecticut. The MTA network comprises the nation’s largest bus fleet and more subway and commuter rail cars than all other U.S. transit systems combined. MTA strives to provide a safe and reliable commute, excellent customer service, and rewarding opportunities.
Job Summary:
The purpose of this position is to provide technical expertise in managing and analyzing cybersecurity risks. Cybersecurity Engineer will be responsible for designing, building, and maintaining infrastructure and applications technology to support a secure cybersecurity posture. These include systems that support cybersecurity directly and/or the business operations for Information and Operational Technology disciplines. Secure building and configuration of systems (applications, infrastructure, wireless, carrier systems, cloud, operational technology, IOT, etc.) from the outset reduces risk to MTA. Specialized and focused skill sets in various technology domains assist with the overall risk reduction for the MTA. The configuration, hardening, guidance, response, and analysis of these systems aid in the reduction and containment of Cyber Security risk. Risk assessments, data analytics tools, operational process reviews, and collaboration with security engineers, architects, developers, vendors, and business units to constantly improve the overall security of the MTA.
Critical Skills:
- Hands-on PAM platform engineering: privileged account vaulting, session management, credential rotation, and access request workflow configuration
- Experience with Privileged Identity Management (PIM) and Just-in-Time (JIT) access design and implementation, including approval workflows and time-bound elevation
- Tiered administration models (Tier 0–5): designing and enforcing privileged access controls, admin account separation, and secure administrative paths
- Knowledge of service account and non-human identity security: discovery, vaulting, rotation, and remediation coordination
- Strong experience with endpoint privilege management: least-privilege enforcement, elevation controls, and local admin removal
- Knowledge of operational support and troubleshooting of privileged access issues, including escalations and platform break/fix
Integration of PAM with directory, MFA, SSO, and ITSM platforms - Experience with infrastructure, OT, and application teams on remediation, while maintaining PAM ownership boundaries
Responsibilities:
- Researching emerging threats and vulnerabilities to aid in the identification of network incidents, and supporting the creation of new architecture, policies, standards, and guidance to address them
- Knowledge and practical implementation of secure system configuration and hardening standards
- Design, configure, and integrate secure solutions in the technology domains assigned
- Provide incident response support, including mitigating actions to contain activity and facilitating forensic analysis, system hardening, and recovery when necessary
- Provides installation, system configuration, hardening, and optimization for infrastructure, application, and security components and systems such as servers, workstations, mobile devices, directory services, operating systems, middleware, IOT, web and next-generation firewalls, machine and human behavior learning tools, host-based security system, security event and incident monitoring systems, virtual, physical, and cloud platforms.
- Identifies configuration gaps independently and/or with vendors to reduce cybersecurity risks
- Reviews alerts and data from sensors and documents formal, technical incident reports
- Performs other duties as assigned
- Complies with all policies and standards
- May be required to work hours outside regular work hours, as applicable
- Observes the work performed by contractors, as applicable
- Reviews invoices and approves them if the work has contractual standards, as applicable
- Addresses performance issues with the contractor when possible, as applicable
- Escalates issues to other parties when needed, as applicable
Qualifications:
- Bachelor’s Degree in Arts/Sciences (BA/BS) and minimum 3 years of relevant experience required. An equivalent combination of education and experience may be considered in lieu of a degree.
- Bachelor’s Degree in Arts/Sciences (BA/BS) in Computer Science or related fields preferred.
- Certified in Oracle Cloud Infrastructure. At least one certification in technology subdomains preferred upon hire but not required (ie., Cloud, Applications, Infrastructure, Security Technology, etc.)
- Current CISSP or other advanced security-related certification preferred upon hire but not required.
Knowledge, Skills, and Abilities:
- Proven ability to independently evaluate and resolve most problems within an area of infrastructure, applications within a security domain context.
- Proven ability to analyze and/or conduct a security risk assessment.
- Advanced understanding of TCP/IP (OSI Layers 1– 4) and Internet and Intranet technologies required (OSI Layers 5-7).
- Some scripting or programming skills (PERL, Python, PowerShell, etc.) preferred as needed.
Competencies:
Core Competency | Proficiency Level | Competency Definition |
Communicates Effectively | Adept | Developing and delivering multi-mode communications that convey a clear understanding of the unique needs of different audiences |
Values Diversity | Adept | Recognizing the value that different perspectives and cultures bring to an organization |
Collaborates | Adept | Building partnerships and working collaboratively with others to meet shared objectives |
Cultivates Innovation | Capable | Creating new and better ways for the organization to be successful |
Customer Focus | Capable | Building strong customer relationships and delivering customer-centric solutions |
Tech Savvy | Capable | Anticipating and adopting innovations in business-building digital and technology applications |
Technical Skills | Capable | Specialized knowledge and expertise on tools, programs, domains, platforms, and products used for specific tasks |
Other Information:
Pursuant to the New York State Public Officers Law & the MTA Code of Ethics, all employees who hold a policymaking position must file an Annual Statement of Financial Disclosure (FDS) with the NYS Commission on Ethics and Lobbying in Government (the “Commission”).
Equal Employment Opportunity:
MTA and its subsidiary and affiliated agencies are Equal Opportunity Employers, including with respect to veteran status and individuals with disabilities.
The MTA encourages qualified applicants from diverse backgrounds, experiences, and abilities, including military service members, to apply.