The Information Security Office's mission is to safeguard the confidentiality, integrity, and availability of Department's information assets. The primary responsibilities of the Information Security Office are to:
- Develop and implement department-wide information security policies and procedures to address risks from rapidly changing technology.
- Investigate information security incidents and breaches, recommend corrective actions, report incidents to executive management, and comply with all applicable New York State reporting requirements.
- Develop, deliver, and manage the department’s security awareness training program.
- Develop and maintain the Department's Disaster Recovery / Business Continuity Plan.
- Review data security practices for New York State educational agencies and provide recommendations to strengthen their security posture.
- Configure and manage agency vulnerability scanning to identify, assess, and support the remediation of vulnerabilities.
- Perform digital forensics investigations to collect, preserve, analyze, and document evidence related to information security incidents and breaches.
- Participate on project teams that design new applications or make major system changes to ensure auditability and security are built in from inception through implementation.
Interns will receive a variety of assignments, which may include assisting with policy and training development, incident response, vulnerability management, digital forensics, risk management, data classification, and disaster recovery.
Working with С槼ºÖ±²¥â€™s Information Security Office, interns will gain a well-rounded understanding of how an information security department operates within a state government agency. Interns will gain exposure to daily department operations and learn the importance of standards, policies, and procedures in protecting institutional data. Interns will also learn to think strategically about information security, gain hands-on experience developing enterprise-level professional documentation, and work as part of a team to ensure that documentation meets the needs of the entire agency.
Background with an understanding of cybersecurity, policy, programming, computer science, or project management. Experience or interest in risk assessment is a plus.
Interns may work up to 20 hours each week between 8a-5p, Monday through Friday. Schedules will be made directly with the supervisor.
This is an unpaid internship. We are happy to work with student to help them earn academic credit for their internship with our Department.
To apply for this position, please send your resume, cover letter, transcript (unofficial is acceptable), and signed application to Internships@nysed.gov with the code OMS-FA26-1 in your subject line. Failure to send complete applications or follow the instructions will result in your removal from consideration for this position.
Marlowe Cochran

