IS Manager II - Security

County of San Mateo

California (MO)

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

County of San Mateo is seeking an experienced IS Manager II – Security to lead its cybersecurity program in California. The ideal candidate will oversee a team of cybersecurity professionals, ensuring the protection of systems and data from sophisticated threats. Responsibilities include managing incident responses, collaborating across departments to strengthen security, and maintaining compliance with industry standards. A strong background in cybersecurity management and practices is required for this high-stakes role.

Qualifications

  • 5+ years managing cybersecurity-related staff and projects.
  • Experience in a rapidly changing, high-threat environment.
  • Ability to design secure system architectures.

Responsibilities

  • Lead cybersecurity operations across multiple domains.
  • Direct major incident response efforts.
  • Collaborate with teams to enhance overall security.

Skills

Management of Cybersecurity staff and projects
Advanced experience with firewalls, IDS, IDPS, SIEM, SOAR
Security compliance related to CJIS, PCI, IRS 1075
Expertise in cybersecurity operations and incident response
Knowledge of security frameworks and standards

Education

Three years of responsible experience

Tools

Palo Alto security ecosystem

Job description

We are seeking a highly experienced and adaptable IS Manager II – Security to lead a critical cybersecurity program within a fast‑paced, constantly evolving threat landscape. This role oversees a team of cybersecurity professionals and is responsible for protecting the organization’s systems, data, and infrastructure against increasingly sophisticated threats.

This position requires a leader who can operate effectively in a dynamic, high‑risk environment, where cyber threats evolve rapidly and require both proactive strategy and reactive response. You will play a key role in shaping security architecture, leading incident response efforts, and ensuring compliance with industry standards and regulatory frameworks.

The IS Manager II - Security will directly manage a supervisor and a team of four security engineers, as well as a full‑time investigative and compliance resource, providing leadership, direction, and oversight across multiple critical security domains.

Ideal Candidate
  • 5+ years of management experience over Cybersecurity related staff and projects
  • Advanced experience with firewalls, IDS, IDPS, SIEM, SOAR, host protections
  • Security compliance experience related to CJIS, PCI, and IRS 1075
  • Deep, hands‑on expertise in cybersecurity operations, architecture, and incident response
  • Proven experience managing and developing high‑performing security teams
  • Strong knowledge of security frameworks and standards, including:
    • NIST 800‑53 (Security and Privacy Controls)
    • NIST 800‑61 (Computer Security Incident Handling Guide)
    • CIS 18 Critical Security Controls
  • Experience with and deep understanding of enterprise‑level security platforms, including technologies and relevant solutions such as the Palo Alto security ecosystem
  • Demonstrated ability to operate in a rapidly changing, high‑threat environment with the proven ability to quickly pivot as conditions change during cyber events
  • Expertise in system design and security architecture, with a focus on minimizing risk while achieving operational requirements
  • Ability to design around insecure customer, vendor, and contractor new system requests to maintain a high level of security
  • Strong understanding of:
    • Security processes and governance
    • Documentation and development of standard operating procedures (SOPs)
    • Incident response planning, management and execution
  • Experience handling sensitive investigative requests, including collaboration with:
    • Human Resources
    • County Counsel/Attorney
    • District Attorney and law enforcement agencies
  • Excellent judgment, communication skills, and the ability to balance technical and organizational priorities
Responsibilities
  • Lead and manage cybersecurity operations across multiple critical security domains
  • Direct and oversee incident response efforts, including major cybersecurity events
  • Maintain numerous comprehensive incident response plans and coordinate and conduct annual response training
  • Guide the design and implementation of secure system architectures, ensuring risk is minimized
  • Establish and maintain SOPs and security processes
  • Oversee the administration and effectiveness of enterprise security tools and technologies
  • Ensure alignment with security frameworks, policies, and regulatory requirements
  • Respond to and support investigative requests (criminal and non‑criminal) in coordination with internal and external partners
  • Collaborate with cross‑functional teams to strengthen the organization’s overall security posture
  • Stay ahead of emerging threats, adapting strategies in response to evolving attack methods
Additional Duties
  • Responsible for managing the security team and security operations, associated technologies including network security, incident management, threat assessments, endpoint security, vendor reviews, and security architecture
  • Serve as the main point of contact for county‑wide security initiatives and communications working with each partner agency and core county resources
  • Remediate security as a result of cybersecurity incidents, audit findings, or agency‑related compliance reviews
  • Manage and participate in the administration and maintenance of department‑specific business applications and platforms; evaluate, participate in, and manage information technology and business process redesign; evaluate, select, and recommend departmental applications; establish support processes to ensure availability of application and database services
  • Plan, manage, and oversee the daily functions, operations, and activities of assigned information services programs
  • Participate in the development and implementation of goals, objectives, policies, and strategic and project priorities for assigned programs; recommend appropriate service and staffing levels; recommend and administer policies and procedures
  • Participate in the development, administration, and oversight of assigned budgets
  • Develop and standardize procedures and methods to improve and continuously monitor the efficiency and effectiveness of assigned programs, service delivery methods, and procedures; assess and monitor workload, administrative, and support systems, and internal reporting relationships; identify opportunities for improvement and make recommendations as needed
  • Participate in the selection of, train, motivate, and evaluate assigned personnel; work with employees to correct deficiencies; work with manager and Human Resources to recommend related disciplinary actions
  • Oversee special projects as assigned
  • Oversee the development of consultant requests for proposals and qualifications for professional services; evaluate proposals and recommend project award; develop, negotiate, and review contract terms and amendments; ensure contractor compliance with County and department standards and specifications
  • Provide highly complex staff assistance to TSD Management
  • Perform other duties as assigned
Education and Experience

Any combination of education and experience that would likely provide the required knowledge, skills and abilities is qualifying. A typical way to qualify is: Three (3) years of increasingly responsible experience in systems development or programming; including one (1) year in a project lead capacity.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Chief Information Security Officer CISO
Chief Information Security Officer CISO

Ryde Technologies, LLC • Phoenix (AZ)

On-site
USD 180,000 - 260,000
Information System Security Manager
Information System Security Manager

ATR International • Palo Alto (CA)

On-site
USD 120,000 - 180,000
Incident Manager II
Incident Manager II

Solutions³ LLC • Arlington (VA)

On-site
USD 90,000 - 130,000
Information Systems Security Engineer (ISSE) (TS/SCI with Poly Required)
Information Systems Security Engineer (ISSE) (TS/SCI with Poly Required)

GCI, Inc. • Tysons (VA)

On-site
USD 143,000 - 238,000
Security Analyst II/III
Security Analyst II/III

Gaston County Government • North Carolina

On-site
USD 70,000 - 90,000
Incident Manager II
Incident Manager II

Solutions3 LLC • Arlington (VA), Northern (KY)

Hybrid
USD 110,000 - 150,000
Information Security Manager
Information Security Manager

Confidential • Pittsburgh

Hybrid
USD 140,000 - 190,000
Information System Security Manager (Skill Level 2-3)
Information System Security Manager (Skill Level 2-3)

Strategic Analytix • Fort Meade (MD)

On-site
USD 100,000 - 140,000
Information System Security Manager
Information System Security Manager

CALIBRE • St. Louis (MO)

On-site
USD 90,000 - 120,000
Information Systems Security Engineer 2
Information Systems Security Engineer 2

axiomconsultants • Linthicum (MD)

On-site
USD 140,000 - 210,000