Cybersecurity Officer Manager Identity Operations
MTA Headquarters · New York, NY
$148,784–$196,730from the description
Jul 2, 2026
New York, NY
Jul 21, 2026
What this job asks for AI summary
A management role within a large public transit authority's cybersecurity program, focused on identity and access operations. The position leads a team of technical staff responsible for planning, building, and maintaining cybersecurity tools and controls across multiple domains — including identity management, privileged access, and cloud security. It suits an experienced cybersecurity professional with both hands-on technical depth and a track record of managing staff, vendors, and program budgets.
Senior level · 4+ years · New York-Newark-Jersey City, NY-NJ-PA · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 180 people in the New York-Newark-Jersey City, NY-NJ-PA area plausibly meet what this posting asks for (computer and information systems managers). range 75–260
Applicant volume Light — Few people clear these requirements, so an application that does clear them gets looked at. Worth applying to even if you miss a nice-to-have.
Rare in this occupation — lead with these, and say what you built with them.
What the occupation pays Median $220,035 (middle half $175,731–$291,850). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The title 'Cybersecurity Officer Manager' and the posting's framing ('Manager') signal a people-management role with direct reports, hiring authority, and budget ownership — hence 11-3021 (Computer and Information Systems Managers) is the primary code. However, the role also carries substantial hands-on cybersecurity domain expertise requirements, making 15-1212 (Information Security Analysts) a credible runner-up.
The degree requirement states 'Bachelor's degree required' but immediately follows with 'An equivalent combination of education and experience may be considered in lieu of a degree,' so the degree requirement is set to None.
The minimum experience requirement of '4 years' is stated in the Required Qualifications section. Given the breadth of management responsibilities (staff, contracts, budget, architecture), the actual scope supports a Senior-level classification despite the relatively low stated minimum.
The role is listed as eligible for teleworking one day per week (hybrid), not fully remote.
Azure and AWS appear in the cybersecurity domains list rather than in a hard-requirements section; they are marked preferred accordingly.
Scripting/programming skills (Python, PowerShell, Perl) are explicitly labeled 'preferred as needed' in the competencies section.
The long list of cybersecurity domains (Active Directory, IAM, PAM, Cloud Security, PKI, MFA, OT, PCI, etc.) represents areas of potential domain expertise rather than hard gates on every item; only the most clearly required domains (IAM, Active Directory, TCP/IP, Office 365, Cloud Security) are marked required based on explicit language in the competencies section.
Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Privileged Access Management, Risk Management.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.