Skip to main content

CYBERSECURITY MANAGER

Job Details

The City of Worcester is an EEO/AA Employer. Preference is given to Worcester residents.

If you wish to apply for this position, the deadline is Open Until Filled. Please note the following application options for this position:

  • Applicants are Encouraged to Apply Online
  • By Mailing to the Department of Human Resources, ATTN: CYBERSECURITY MANAGER , 455 Main Street, Room 109, Worcester, MA 01608
    (If applying via US Mail, please include a completed Application Questionnaire & VSID)
Title:
CYBERSECURITY MANAGER
Department/Division:
Innovation and Technology
Apply Start Date:
07/24/2026
Apply End Date:
Open Until Filled
Type:
Full Time
Hours:
40 Per Week
Wage:
$100,036 - $132,137 annually
Description:

CYBERSECURITY MANAGER
DEPARTMENT OF INNOVATION AND TECHNOLOGY
CITY OF WORCESTER

The City of Worcester is seeking qualified applicants for a Cybersecurity Manager in the Department of Innovation and Technology. Under the direction of the Chief Information Officer, this position is responsible for establishing the City of Worcester’s cybersecurity strategy, overseeing daily security operations, and ensuring the protection of information systems supporting employees across a hybrid environment that includes enterprise IT, cloud platforms, and public safety operational technologies. This role requires both strategic oversight and direct, hands‑on engagement with the security team and broader organization to implement and sustain best‑practice processes, procedures, and supporting technologies.

The Cybersecurity Manager supervises the Cybersecurity Analyst and Cybersecurity Trainer. This position collaborates with City leadership, departmental stakeholders, and external partners to strengthen the City’s cybersecurity posture and maintain compliance with regulatory and policy requirements.

 

Bilingual applicants are encouraged to apply.

 

ESSENTIAL ELEMENTS:

  • Develop and maintain the City’s cybersecurity strategy in alignment with industry standards and municipal needs.
  • Serve as the City’s primary cybersecurity advisor, providing risk-based guidance to DoIT leadership and City executives.
  • Establish, update, and enforce cybersecurity policies, standards, and procedures.
  • Oversee governance activities, including risk assessments, compliance initiatives, and long-term program planning.
  • Conduct and direct cybersecurity risk assessments, threat evaluations, and gap analyses.
  • Coordinate Incident Response, Business Continuity, and Disaster Recovery planning and exercises.
  • Identify opportunities for security improvements and recommend risk mitigation strategies across applications, infrastructure, and public safety systems.
  • Manage security platforms, including but not limited to email security, SIEM, EDR, Zero Trust SSE, firewalls, DLP.
  • Supervise daily security operations and provide leadership to the Cybersecurity Analyst and Cybersecurity Trainer.
  • Ensure the confidentiality, integrity, and availability of City data, systems, networks, and critical infrastructure.
  • Lead security incident investigations and coordinate response efforts with IT, legal, public safety, and external partners.
  • Oversee vulnerability assessments, penetration testing, and audit remediation.
  • Maintain current knowledge of cybersecurity technologies, trends, and threats.
  • Evaluate, recommend, and support procurement of cybersecurity tools and services.
  • Direct integration, configuration, and optimization of cybersecurity technologies.
  • Oversee the Citywide cybersecurity awareness and training program.
  • Promote a culture of security, collaboration, and shared responsibility across departments.
  • Other duties as assigned.

REQUIRED KNOWLEDGE, SKILLS, AND ABILITIES:

  • Deep understanding of security principles, access control models, and risk management.
  • Strong knowledge of IT infrastructure, cloud computing, hybrid environments, and enterprise systems.
  • Ability to influence organizational change, build morale, and foster a strong security culture.
  • Strong leadership, team management, mentoring, and staff development skills.
  • Commitment to continuous improvement of processes, controls, and team efficiency.
  • Excellent written and verbal communication skills, including translating complex topics for non‑technical audiences.
  • Ability to prioritize and execute tasks in high‑pressure or time‑sensitive environments.
  • Strong analytical, problem‑solving, and decision‑making abilities.
  • Experience developing and maintaining security policies, standards, and procedures.
  • Experience with business continuity, disaster recovery planning, incident response, and security investigations.
  • Strong interpersonal communication, organizational, and customer‑service skills.
  • Strong communication, collaboration, and cross‑department partnership skills
  • Strong attention to detail and analytical abilities.
  • Regular onsite attendance is required.

MINIMUM REQUIREMENTS:

  • Bachelor’s degree in cybersecurity, computer science, information technology, or a related field; OR
    • Any equivalent combination of education, training and seven (7) years of experience which provide the required knowledge, skills and abilities to perform the required duties of the position will be considered in lieu of the above-mentioned requirements.
  • Five (5) years of progressive cybersecurity or information security experience, including responsibility for security operations, incident response, and risk management.
  • Two (2) years of supervisory or team‑lead experience, including managing security operations in large‑scale or complex environments.
  • Experience with Zero Trust tools (e.g., Zscaler), SIEM, EDR/XDR, IDS/IPS, Secure Service Edge, IAM, and vulnerability scanning/detection tools.
  • Strong technical skills in firewalls, VPNs, IDS/IPS, identity management, endpoint security, and Data Loss Prevention strategies.
  • Experience securing multiple operating systems (Windows Server/client, Linux, Solaris) and virtualization technologies.
  • Strong knowledge of network environments, routers, switches, network protocols (TCP/IP), and general enterprise network infrastructure.
  • Experience with enterprise security architecture, incident response, vulnerability management, and risk‑based security practices.
  • Knowledge of regulatory and compliance frameworks (PCI, HIPAA, NIST, FIPS 140‑2, GDPR, CCPA) and experience supporting compliance efforts.
  • Experience managing security in modern cloud environments (Azure, AWS, SaaS, PaaS, IaaS) and M365/Azure security administration.
  • Experience managing or supporting security audits.
  • At least one relevant certification (e.g., Security+, GSEC, MCSA: Security, CISSP or Associate).
  • Valid driver’s license and access to reliable transportation
  • Ability to obtain and maintain CJIS certification; must be CJIS‑eligible.

PREFERRED REQUIREMENTS:

  • Eight (8) years of professional cybersecurity experience with progression into leadership roles.
  • Experience with public‑sector, municipal, or regulated environments, including familiarity with CJIS, HIPAA, MA 201 CMR 17.00, or similar regulations.
  • Experience securing critical infrastructure or OT/SCADA environments.
  • Working knowledge of operating systems and commercial applications commonly used in municipal environments.
  • Experience leading cybersecurity strategy aligned with NIST, CIS, or ISO 27001.
  • Experience with MS Purview.

 

SALARY RANGE: $100,036 - $132,137 annually, full-time, exempt, with an excellent benefits package.

 

To apply, please visit: www.worcesterma.gov/employment  or send resume and cover letter to: City of Worcester, 455 Main Street, Room 109, Worcester, MA 01608. OPEN UNTIL FILLED, applications received prior to or on FRIDAY, AUGUST 7, 2026, will receive preference. Preference is given to Worcester residents. The City of Worcester is an equal opportunity, affirmative action employer. Women, minorities, people with disabilities and protected veterans are encouraged to apply. Direct inquiries to: City Hall, Human Resources, Room 109, 508-799-1030, Hiring@worcesterma.gov.