Information Security Analyst II

San Bernardino County

San Bernardino (CA)

On-site

USD 90,000 - 130,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Paid time off
Health and wellness
Professional development
Tax savings plan
Work-life balance
Retirement

Job summary

San Bernardino County's Innovation and Technology Department seeks an Information Security Analyst II to monitor, analyze, and respond to cybersecurity incidents across county systems. The ISA II will work with departments, IT teams, and partners to identify threats and implement mitigations.

The role leads security awareness, vulnerability assessments, and coordination of incident response, while ensuring compliance with policies and regulatory requirements.

Qualifications

  • Three (3) years of experience assisting with the implementation, management, and monitoring of IT security solutions and programs.
  • 60 semester units of completed courses from an accredited college or university in information security, information systems, programming, computer science, software engineering, or a closely related field.
  • Master’s degree in information systems, information security, information technology, computer science, or a closely related field.
  • Information security related training or certifications such as CEH, CSA, or CISSP.

Responsibilities

  • Monitor computer networks for security issues and suspicious activities.
  • Investigate cybersecurity incidents and lead response efforts with IT teams, vendors, and partners.
  • Coordinate cybersecurity incidents with county departments and outside agencies as needed.
  • Educate team members and leadership on security measures, policies, and best practices.
  • Lead or coordinate vulnerability assessments and threat intelligence efforts.
  • Collaborate on network security design enhancements.
  • Lead security awareness training and phishing simulation programs.
  • Review contracts and licensing for cybersecurity, privacy, and compliance risks.
  • Participate in on-call rotation and after-hours maintenance.

Skills

Analytical skills
Cloud infrastructure
Risk assessment
Network security
Penetration testing tools

Education

Master’s degree (information security / IT / CS)
60 semester units in relevant field
Bachelor’s degree substitution: 1 year experience
Certifications: CEH / CSA / CISSP

Tools

Penetration testing tools
MITRE Kill Chain framework

Job description

The Innovation and Technology Department is seeking motivated and passionate professionals for the role of Information Security Analyst II (ISA II). The analyst will be responsible for monitoring, analyzing, and collaborating on security incidents and events to safeguard the security operations of the Countywide Information Security Program, that provides protection, governance, risk, and compliance.

The ISA II monitors, analyzes, investigates, and responds to cybersecurity events and incidents that may affect County systems, applications, networks, and information assets. The analyst will work collaboratively with experienced cybersecurity team members, County departments with diverse business and regulatory requirements, and various technology teams to identify potential threats, evaluate security concerns and issues, and support efficient and effective response including identifying appropriate mitigation and remediation activities. They will respond to, defend against, consult on, and resolve enterprise and departmental security concerns, events, issues, and incidents related to cyber, operational, and information security.

Key Responsibilities
  • Monitoring computer networks for security issues and suspicious activities.
  • Performs as an incident responder and investigates cybersecurity incidents.
  • Lead response efforts in collaboration with other IT teams, vendors, and cyber intelligence partners to analyze and remediate the issue.
  • May lead or coordinate cybersecurity incidents and investigations with Human Resources, County departments, outside agencies (e.g. regulatory agencies) including law enforcement.
  • Educates team members; and recommends security measures including protocols, policies, and standard practice to leadership.
  • May lead, facilitate, coordinate, or conduct vulnerability assessments with a proactive focus on threat intelligence and the mitigation and prevention of cyber attacks.
  • Collaborate with colleagues for network security design enhancements.
  • Leads the coordinating and facilitating the Countywide Security Awareness Training Program
  • Leads the coordinating and facilitating the Countywide Phishing Simulation Program.
  • Leads the conducting, coordinating, and facilitating cybersecurity or information security tabletop exercises.
  • Reviews and coordinating contracts, procurement documents, and software or service licensing agreements to identify and assess cybersecurity, privacy, and compliance risks, and provides recommendations to ensure adherence to organizational security policies and regulatory requirements.
  • Participate in on-call rotation and after-hours maintenance as needed.

For more detailed information, refer to the
Information Security Analyst II
job description.

Benefits
  • Paid time off, health and wellness, professional development, tax savings plan, work-life balance, and retirement.
Conditions of Employment

Pre-Employment Process: Applicants must successfully pass a background check and a job-related physical exam, including a drug test, prior to employment.

Availability: Incumbents may occasionally work evening and weekend hours. Some overtime, on-call, or call back work may be required.

Sponsorship: Please note San Bernardino County is not able to consider candidates who will require visa sponsorship at the time of application or in the future. Candidates must be able to present their legal right to work in the United States.

Qualifications

Candidates must meet the Experience AND Education requirement in order to qualify.

REQUIRED EXPERIENCE: Three (3) years of experience assisting with the implementation, management, and monitoring of IT security solutions and programs.

REQUIRED EDUCATION: Sixty (60) semester (90 quarter) units of completed courses from an accredited college or university in information security, information systems, programming, computer science, software engineering, or a closely related field.

  • Master’s degree in information systems, information security, information technology, computer science, or a closely related field.
  • Information security experience in higher education or state/local government.
  • Information security related training or certifications such as CEH, CSA, or CISSP.
  • Experience performing information security audits or risk assessments.
  • Ability to administer network and host-based tools for penetration testing and ethical hacking products and tools.
  • Knowledge of host compromise, and various techniques for malware injection and MITRE Kill Chain Framework.
  • Proficiency in performing risk, business impact, control, and vulnerability assessments, and in defining treatment strategies.
  • Strong analytical skills to analyze security requirements and relate them to appropriate security controls.
  • Experience with cloud infrastructure and provisioning technology.
Substitutions
  • One (1) additional year of qualifying work experience may substitute for the education requirement.
  • A Bachelor's degree in information security, information systems, information technology, programming, computer science, software engineering, or a closely related field may substitute one (1) year of the required experience.

Qualifying degrees and coursework must be conferred by institutions accredited by an accrediting body recognized by the U.S. Department of Education. Degrees earned outside the United States must be accompanied by an evaluation from a recognized credential evaluation service verifying U.S. equivalency.

Supplemental Information

Examination Procedure: There will be a competitive evaluation of qualifications based on the information provided in the Application and the Supplemental Questionnaire. You are encouraged to include detailed descriptions of your qualifying experience and skills, as only the most highly qualified applicants will be referred to the Department.

Equal Employment Opportunity (EEO) / Americans with Disabilities Act (ADA)

San Bernardino County is an Equal Employment Opportunity (EEO) and Americans with Disabilities Act (ADA) compliant employer, dedicated to ensuring equal employment opportunities for all employees and applicants.

ADA Accommodation

If you have a disability and need accommodations during the testing process, please submit the Special Testing Accommodations Request Form (Download PDF) within one week of the recruitment filing deadline.

Veterans' Preference

Eligible veterans, their spouses, or widows/widowers who are not current County employees may receive additional Veterans' Preference points. For details and instructions on how to request these points, please refer to the Veterans' Preference Policy.

For more important details, review the Applicant Information and County Employment Process.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Analyst II
Information Security Analyst II

SAN-Bernardino-Count • California (MO)

On-site
USD 85,000 - 120,000
Information Security Analyst II
Information Security Analyst II

San Bernardino County • California (MO)

On-site
USD 90,000 - 130,000
Information Security Analyst I
Information Security Analyst I

SAN-Bernardino-Count • California (MO)

On-site
USD 65,000 - 90,000
Information Security Analyst I
Information Security Analyst I

San Bernardino County • San Bernardino (CA)

On-site
USD 65,000 - 90,000
Information Security Analyst I
Information Security Analyst I

San Bernardino County • California (MO)

On-site
USD 60,000 - 90,000
Automated Systems Analyst II
Automated Systems Analyst II

San Bernardino County • California (MO)

On-site
USD 83,000 - 117,000
Excellent benefits
Automated Systems Analyst II
Automated Systems Analyst II

SAN-Bernardino-Count • California (MO)

On-site
USD 83,000 - 117,000
Excellent benefits
Information Security Analyst III
Information Security Analyst III

Sacramento County • Sacramento (CA)

On-site
USD 90,000 - 120,000
Information Security Analyst III
Information Security Analyst III

Sacramento County, CA • Sacramento (CA)

On-site
USD 120,000 - 170,000
Security Operations & Incident Response Analyst II
Security Operations & Incident Response Analyst II

San Bernardino County • San Bernardino (CA)

On-site
USD 90,000 - 130,000
Paid time off
Health and wellness
Professional development
+3