About the Role
The IT Operations Manager is accountable for daily IT operations, including the IT Service Desk, IT Managed Service Provider (MSP) governance, Managed Security Service Provider (MSSP) governance, and the third-party vendor security audit program. This role ensures the company meets operational and regulatory standards, maintaining stability across network, servers, cloud services, endpoints, and security platforms. Responsibilities include incident management, change control, vendor governance, asset lifecycle oversight, and adherence to IT policies and regulatory requirements.
Responsibilities
- Oversees daily Service Desk operations and ensures high-quality user support.
- Monitors ticket queues, SLAs, and escalation patterns.
- Coaches Service Desk technicians and maintains SOPs and support standards.
- Ensures documentation accuracy and knowledge base maintenance.
- Acts as the Service Desk authority for sign-off on patches, security policy pushes, and production changes proposed by the MSP or MSSP, including pilot validation and post-push rollback decisions.
- Serves as the primary liaison to the IT Managed Service Provider (MSP).
- Oversees MSP performance, uptime, patching, backups, and incident response.
- Coordinates lifecycle replacements, upgrades, and infrastructure improvements.
- Reviews MSP reports and escalates performance or compliance concerns.
- Serves as the primary internal owner of the Managed Security Service Provider (MSSP), governing 24x7 monitoring, alerting, vulnerability management, EDR/XDR, PAM, and incident response services.
- Oversees MFA governance, privileged access reviews, endpoint compliance, and security hardening.
- Runs formal MSSP governance — quarterly business reviews (QBRs), SLA scorecards, KPI tracking, and escalation of performance or compliance issues.
- Owns internal accountability for NYDFS 23 NYCRR Part 500 control operation and SOC 2 readiness, working with the vCISO and MSSP to maintain a current control inventory, evidence library, and remediation tracker.
- Owns coordination and evidence delivery for internal IT audits, NYDFS examinations, SOC 2 audits, and the annual Superintendent’s Certification (NYCRR 500.17).
- Owns HIC’s Third-Party Service Provider Security Program in accordance with NYDFS 23 NYCRR 500.11 and HIC ITSEC-09 (Vendor Risk Management).
- Maintains the in-scope third-party vendor inventory; classifies vendors by risk tier (high/medium/low) based on data access, system criticality, and PII/PHI exposure.
- Issues, collects, and adjudicates annual vendor security assessments (questionnaires, SOC 2 reports, penetration test summaries, evidence of MFA, encryption, access controls, and incident response capabilities).
- Operates a rolling quarterly review schedule, ensuring all in-scope vendors are validated at least annually with findings logged in the vendor risk register.
- Reviews vendor security clauses in contracts and renewals (e.g., breach notification, right-to-audit, data return/destruction) and partners with Legal and the vCISO on remediation of identified gaps.
- Reports vendor risk posture quarterly to the CIO and (as required) the IT Steering Committee, including high-risk findings, remediation status, and contracts with unresolved security exceptions.
- Leads IT incident, problem, and change management processes.
- Maintains IT asset lifecycle, inventory accuracy, and onboarding/offboarding workflows.
- Oversees configuration documentation, runbooks, and operational procedures.
- Works with business units to prepare for upgrades and technology changes.
- Supports infrastructure modernization, cloud adoption, and security projects.
- Manages IT vendor relationships, renewals, and performance reviews.
- Ensures alignment with architectural standards, compliance, and budget constraints.
- Ensures adherence to IT policies, procedures, and cybersecurity controls.
- Provides operational reporting on risks, performance, and service metrics.
- Performs other related duties and special projects as assigned.
- Working manager and gets involved when required to help with technical issues.
Requirements
- Bachelor’s degree in IT, Computer Science, or related field.
- Five+ years of IT operations, infrastructure management, or service desk leadership experience.
- Experience governing IT MSPs and/or MSSPs, including QBRs, SLA scorecards, and escalation management.
- Demonstrated experience operating a third-party vendor security risk program (intake, tiering, annual reviews, SOC 2 review, vendor risk register).
- Strong understanding of networks, servers, cloud platforms, and endpoint management.
- Familiarity with cybersecurity concepts, vulnerability management, and compliance.
- Strong communication, leadership, and vendor management skills.
- Basic understanding of network concepts and security principles.
- Hands-on experience supporting NYDFS 23 NYCRR 500 and/or SOC 2 audits, including evidence collection, control mapping, and third-party service provider security assessments (NYCRR 500.11).
- Experience in regulated environments such as insurance or financial services.
- Experience with ticketing systems, asset tools, and monitoring platforms.
Skills
- IT Service Desk Operations
- Managed Service Provider (MSP) Governance
- Managed Security Service Provider (MSSP) Governance
- Third-Party Vendor Security Audit Program Management
- NYDFS 23 NYCRR 500 Compliance
- Incident Management
- Change Control
- Vendor Governance
- Asset Lifecycle Management
- IT Policies and Regulatory Compliance
- Network Operations
- Server Management
- Cloud Services Management
- Endpoint Management
- Security Operations
- Service Delivery Management
- SLA Monitoring
- Escalation Management
- Team Coaching
- SOP Maintenance
- Knowledge Base Management
- Patch Management
- Security Policy Enforcement
- Pilot Validation
- Rollback Decisions
- MSP Performance Oversight
- Uptime Monitoring
- Backup Management
- Incident Response Coordination
- Infrastructure Upgrades
- Infrastructure Improvements
- MSP Report Review
- MSSP Governance
- 24x7 Monitoring
- Vulnerability Management
- EDR/XDR
- PAM (Privileged Access Management)
- MFA Governance
- Privileged Access Reviews
- Endpoint Compliance
- Security Hardening
- Quarterly Business Reviews (QBRs)
- SLA Scorecards
- KPI Tracking
- NYDFS 23 NYCRR Part 500 Control Operation
- SOC 2 Readiness
- Control Inventory Management
- Evidence Library Management
- Remediation Tracking
- IT Audit Coordination
- NYDFS Examination Support
- SOC 2 Audit Support
- Superintendent’s Certification (NYCRR 500.17)
- Third-Party Service Provider Security Program
- Vendor Risk Management
- Vendor Inventory Management
- Risk Tier Classification
- Vendor Security Assessments
- Vendor Risk Register Maintenance
- Contract Review (Security Clauses)
- Vendor Relationship Management
- Problem Management
- Configuration Documentation
- Runbook Development
- Operational Procedure Development
- Business Unit Coordination
- Infrastructure Modernization Support
- Cloud Adoption Support
- Security Project Support
- Vendor Renewal Management
- Performance Review
- Architectural Standards Alignment
- Budget Management
- Cybersecurity Control Adherence
- Operational Reporting
- Risk Reporting
- Service Metrics Reporting
- Technical Issue Resolution
Location
- In office position
Work Type
- Full-time
- Hybrid
Experience Level
- 5+ years of IT operations, infrastructure management, or service desk leadership experience.
Education Level
- Bachelor’s degree in IT, Computer Science, or related field.
About the Company
- HIC meets the operational and regulatory standards expected of a NYDFS-regulated insurer.
