San Jose Police Department seeks an Enterprise Principal Technology Analyst (Cybersecurity Operations Manager) for an onsite, hands-on leadership role across enterprise cybersecurity operations.
Responsibilities
- Provide hands‑on technical leadership, mentoring, prioritization, and quality assurance while coordinating with infrastructure, network, endpoint, cloud, application, identity, and service desk teams to reduce enterprise cybersecurity risk.
- Collect, analyze, and operationalize cyber‑threat intelligence to identify emerging threats, vulnerabilities, attacker techniques, and indicators of compromise.
- Convert intelligence into actionable defenses, including detections, hunting queries, blocking rules, advisories, and risk‑based recommendations supporting incident response, vulnerability management, security engineering, and leadership reporting.
- Lead cybersecurity emergency response for suspected or confirmed incidents: triage, containment, eradication, recovery, root‑cause analysis, and post‑incident improvement.
- Provide technical direction during high‑pressure events involving phishing, malware, credential compromise, unauthorized access, data exposure, endpoint compromise, cloud compromise, network intrusion, or advanced threats.
- Build and maintain security operations standards, including process flows, incident response playbooks, escalation procedures, evidence‑handling practices, and clear incident documentation.
- Lead cybersecurity projects and operational initiatives by defining scope, milestones, deliverables, dependencies, risks, and success criteria; coordinate cross‑functional teams, vendors, and stakeholders; track progress, resolve blockers, communicate status, and ensure measurable security/operational outcomes.
- Design, implement, tune, and continuously improve enterprise security controls across network, endpoint, cloud, identity, email, data protection, remote access, logging, monitoring, and automation environments.
- Ensure security tools are properly configured, integrated, monitored, and generating actionable outcomes; partner with technical teams on proposed changes, identify risks, recommend compensating controls, and embed security into enterprise solutions.
- Oversee detection engineering across SIEM, EDR/XDR, network, identity, cloud, and email; lead threat hunting for suspicious behavior, control gaps, misconfigurations, compromised accounts, lateral movement, persistence, and other attacker indicators; improve coverage, reduce false positives, and measure operational effectiveness.
- Independently lead cybersecurity risk reviews of complex technology implementations, including vendor and out‑of‑the‑box solutions, cloud platforms, SaaS applications, infrastructure services, endpoint tools, network technologies, IoT, and desktop environments; evaluate default configurations, architecture decisions, access models, logging/data protection, integration points, and operational impacts; identify gaps and risk exposure; develop practical risk‑reduction recommendations.
- Support audit, compliance, and risk‑management activities with technical evidence, control validation, and remediation support.
Requirements
- Bachelor’s Degree from an accredited college or university in a relevant field AND five (5) years of increasingly responsible professional‑level experience in computer applications, systems, networks, or telecommunications work.
- At least two (2) years must include responsibility in development, implementation, and maintenance of electronic business systems/solutions or application development and/or support.
- Additional directly related experience may substitute for education on a year-for-year basis up to two (2) years.
- A Master’s Degree in a relevant field may substitute for one year of the required two (2) years of experience in electronic business systems/solutions or application development/support.
Technologies / Frameworks
- NIST Cybersecurity Framework, NIST 800-53, CIS Controls, MITRE ATT&CK, CJIS, PCI DSS, ISO 27001
- SIEM, EDR/XDR
- Active Directory, Entra ID/Azure AD, MFA, privileged access, conditional access, zero trust
- VPN, DNS, web filtering
Required Technical Strength (Must Demonstrate)
- Network security: firewalls, segmentation, routing, VPN, DNS, web filtering, secure remote access, network traffic analysis.
- Endpoint security: EDR/XDR, malware analysis concepts, host‑based investigation, endpoint hardening, containment strategies.
- Identity security: Active Directory, Entra ID/Azure AD, MFA, privileged access, conditional access, account compromise investigation, identity‑based attack paths.
- Cloud security: cloud logging, identity integration, access control, workload protection, SaaS security, cloud misconfiguration risk.
- Security monitoring: SIEM use cases, detection logic, log source onboarding, alert tuning, threat hunting, incident investigation.
- Incident response: triage, containment, eradication, recovery, root‑cause analysis, evidence preservation, after‑action reporting.
- Threat intelligence: attacker behavior analysis, indicators of compromise, tactics, techniques, procedures, and operationalizing intelligence into controls.
- Security architecture: defense‑in‑depth, zero trust principles, least privilege, secure design reviews, compensating controls, and enterprise risk reduction.
Salary
- USD 163,035.60 – 198,525.60 per year
- Approximate 5% ongoing non‑pensionable compensation pay in addition to starting salary for the EPTA classification
Desirable Competencies
- Experience in public sector, critical infrastructure, large enterprise, healthcare, financial services, or other highly regulated environments.
- Experience leading complex cybersecurity projects or operational initiatives involving cross‑functional technical teams, vendors, and stakeholders (project planning, risk/dependency management, progress tracking, issue resolution, executive communication, delivery of measurable improvements).
- Ability to evaluate, administer, tune, and integrate security tools to improve visibility, control effectiveness, and response capabilities.
- Experience building or maturing a cybersecurity operations function.
- Experience with frameworks and standards including NIST Cybersecurity Framework, NIST 800-53, CIS Controls, MITRE ATT&CK, CJIS, PCI DSS, and/or ISO 27001.
- Proven ability to independently evaluate complex technology implementations for cybersecurity risk across vendor/out-of-the-box, cloud, SaaS, network, endpoint, server, IoT, and desktop solutions, including architecture, identity/access controls, logging/monitoring, data protection, exposure, configuration baselines, integration risks, and operational dependencies, to identify gaps and develop risk‑reduction outcomes.
Additional Workforce Expectations
- Leadership skills: leads by example with high ethical standards; remains visible and approachable; promotes cooperative work environment; provides motivational support and direction.
- Analytical thinking, problem solving, communication, multi‑tasking, reliability, teamwork/interpersonal skills, and project management capabilities.
- Building trust: communicates shared interests/goals, demonstrates honesty, keeps commitments, and behaves appropriately.
- Vision/strategic thinking: supports alignment with organizational vision/values and translates vision to action.
Additional Information
- Federal law requires verification of eligibility to work in the country.
- The City of San Jose will NOT sponsor, represent, or sign documents related to visa applications/transfers for H1-B or other visa types requiring an employer application.
- Applications are not accepted through CalOpps or other third‑party job boards.
- This recruitment may be used to fill multiple positions in this or other divisions/departments.
- After submitting an online application, candidates receive an automatic confirmation email; if not received, email CityCareers@sanjoseca.gov.
- Candidates are encouraged to use AI responsibly as support, but application responses and interview answers must reflect personal knowledge, skills, and experiences.