IT Cyber Security Systems Engineer (Senior Position)

Coast Community College District

California (MO)

On-site

USD 103,000 - 126,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

22 paid holidays
12 paid vacation days
12 sick days
1 floating holiday

Job summary

Coast Community College District is seeking an IT Cyber Security Systems Engineer (Senior) to lead security initiatives across Coastline, Golden West, and Orange Coast colleges. This on-site role focuses on risk assessments, penetration testing, and incident response to protect district systems and data.

The position offers a starting salary of $114,683.03 per year with total compensation starting at $181,339.55, inclusive of benefits.

Qualifications

  • Bachelor's degree required or equivalent combination of education and experience.
  • 8+ years of cyber security project development/implementation preferred.
  • Experience with enterprise security policy development and regulatory compliance.

Responsibilities

  • Provide technical leadership for enterprise security initiatives.
  • Lead design and engineering of security solutions and architectures.
  • Oversee cyber incident response and vulnerability management activities.
  • Develop and enforce security standards, policies, and procedures.
  • Coordinate security efforts across multiple districts and teams.

Skills

Cybersecurity
Penetration testing
Risk assessment
Incident response
Network security

Education

Bachelor's degree in computer science, cyber security, or related field

Tools

SIEM
Firewalls
Security tools suite

Job description

(ON-SITE - in-person position)
Starting Salary: $114,683.03/year
Total compensation, include salary and benefits, starts at $181,339.55

Paid Time Off (per year)
  • 22 paid holidays
  • 12 paid vacation day (accrued based on time worked)
  • 12 sick days (accrued based on time worked)
  • 1 floating holiday

Please note: The position title is IT Cyber Security Systems Engineer. The (Senior Position) listed provides insight to interested applicants on the level of expertise this role requires.

About the Team

At the Coast Community College District, IT Cyber Security and Infrastructure Team plays a vital role in supporting the success of students, faculty, and staff across Coastline College, Golden West College, and Orange Coast College. We’re looking for talented individuals who are passionate about technology and eager to contribute to our mission of fostering innovation, security, and seamless digital experiences.

Why Work with Us?
  • Innovate: Work with cutting‑edge technologies that enhance education and streamline district operations.
  • Collaborate: Partner with academic leaders and staff to deliver meaningful technology solutions.
  • Grow: Be part of a team that values continuous learning, professional development, and staying ahead of the latest industry trends.
  • Make an Impact: Your work will directly contribute to the success of our students and the efficiency of the district.
Our Focus Areas
  • Network & Infrastructure: Ensure fast, secure connectivity across campuses.
  • Enterprise Applications: Manage critical systems like student information and ERP platforms.
  • Cybersecurity: Protect the district’s digital assets and safeguard against threats.
  • User Support: Provide responsive helpdesk services and technical assistance.
  • Academic Technology: Support the latest tools for online learning and in-classroom technology.
  • Data & Analytics: Help the district make informed decisions through powerful data insights.
Our Projects
  • Digital Transformation: We’re enhancing the digital learning environment and expanding cloud-based solutions.
  • Cybersecurity Initiatives: Keeping the district secure through advanced threat detection and awareness programs.
  • Cloud Migration: Moving essential services to the cloud for greater scalability and efficiency.
About the District

Established in 1947, the Coast Community College District (CCCD) is a beacon of educational excellence in Orange County, California. As a public, multi‑campus community college district, CCCD has been transforming lives through accessible, high-quality education for over seven decades.

CCCD’s impact extends across three comprehensive colleges: Coastline Community College, Golden West College, and Orange Coast College. Together, these institutions serve over 51,000 students annually, offering a rich tapestry of academic and vocational programs, support services, and co‑curricular activities.

CCCD takes pride in fostering a supportive and inclusive environment. Our commitment to diversity, equity, and inclusion extends beyond our student body to encompass our employees and the broader community. We believe that this inclusive approach not only enriches the educational experience but also prepares our students for success in an increasingly diverse world.

Join us in shaping the future of education in Orange County. At CCCD, you’ll be part of a dynamic team dedicated to making a lasting impact on our students and community.

Summary

Leads, plans, designs, and implements processes and procedures for risk assessments, vulnerability analyses, and penetration testing to prevent, detect, and respond to cyber security attacks. Identifies threats and vulnerabilities in systems and software and provides high‑tech solutions to cyber security team to contain, remediate, and document circumstances around confirmed security issues. Provides guidance to and informs cyber security administrators on user security policies, procedures, and practices that defend against hacking, malware, ransomware, insider threats, and cybercrimes.

Distinguishing Career Features

The Cyber Security Systems Engineer is a senior‑level professional position with advanced technical knowledge and analytical skills to identify, develop, and implement effective cyber security program policies, procedures, and processes. The Cyber Security Systems Engineer monitors malware trends and applies in‑depth understanding of cyber security threats in collaboration with cyber security administrators to develop and implement cyber defense strategies. The Cyber Security Systems Engineer is responsible for cyber security requirements for related legal and regulatory compliance.

Essential Duties and Responsibilities
  • Provides subject matter expertise in the strategic planning processes, providing technical input into enterprise security initiatives.
  • Oversees and leads research and planning of leading‑edge technologies for cyber security.
  • Leads the design and engineering of security solutions.
  • Recommends strategic security standards and policies to the Cyber Security Administrator.
  • Provides strategic guidance and subject matter expertise to Cyber Security Administrators, as well as guidance to all levels of the Cyber Security Team.
  • Provides operational and project team leadership for multiple, simultaneous enterprise‑wide cyber security initiatives.
  • Leads and provides process enhancement for risk assessments, vulnerability analyses, and penetration testing.
  • Oversees and responds to security incidents and vulnerabilities.
  • Coordinates the design and engineering of security solutions; participates in planning for future cyber security technology.
  • Performs complex forensic preservation tasks as required.
  • Provides technical expertise to internal and external entities, including internal investigators and external law enforcement and intelligence/government agencies.
  • Develops processes, procedures, and security standards to promote operational efficiency.
  • Designs and integrates new architectural features; provides complex architectural and engineering analyses.
  • Embeds advanced cyber defense techniques for incident response.
  • Leads the tactical execution of Cyber Incident Responses.
  • Develops and delivers cyber security training material.
  • Composes enterprise‑wide security solutions and analyses to internal and external stakeholders.
  • Provides input and support to the development of communications addressing system and network security principles and technology solutions.
  • Applies project management principles and methods to the leadership of security tasks or projects.
  • (NICE‑T0028) Conducts and/or supports authorized penetration testing on enterprise network assets.
  • (NICE‑T0047) Correlates incident data to identify specific vulnerabilities and makes recommendations that enable expeditious remediation.
  • (NICE‑T0051) Define appropriate levels of system availability based on critical system functions and ensure that system requirements identify appropriate disaster recovery and continuity of operations requirements to include any appropriate fail‑over/alternate site requirements, backup requirements, and material supportability requirements for system recover/restoration.
  • (NICE‑T0090) Ensure that acquired or developed system(s) and architecture(s) are consistent with organization’s cybersecurity architecture guidelines.
  • (NICE‑T0119) Identifies, assesses, and recommends cybersecurity or cybersecurity‑enabled products for use within a system and ensure that recommended products follow organization’s evaluation and validation requirements.
  • (NICE‑T0155) Documents and escalates incidents (including event’s history, status, and potential impact for further action) that may cause ongoing and immediate impact to the environment.
  • (NICE‑T0161) Performs analysis of log files from a variety of sources (e.g., individual host logs, network traffic logs, security system logs, and intrusion detection system [IDS] logs) to identify threats to network security.
  • (NICE‑T0163) Performs cyber defense incident triage, to include determining scope, urgency, and potential impact, identifying the specific vulnerability, and making recommendations that enable expeditious remediation.
  • (NICE‑T0175) Performs real‑time cyber defense incident handling (e.g., forensic collections, intrusion correlation and tracking, threat analysis, and direct system remediation) tasks to support deployable Incident Response Teams (IRTs).
  • (NICE‑T0181) Performs risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change.
  • (NICE‑T0196) Provides advice on project costs, design concepts, or design changes.
  • (NICE‑T0205) Provides input to the Risk Management Framework process activities and related documentation (e.g., system life‑cycle support plans, concept of operations, operational procedures, and maintenance training materials).
  • (NICE‑T0248) Promotes awareness of security issues among management and ensures sound security principles are reflected in the organization’s vision and goals.
  • (NICE‑T0258) Provides timely detection, identification, and alerting of attacks/intrusions, anomalous activities, and misuse activities and distinguishes these incidents and events from benign activities.
  • (NICE‑T0259) Uses cyber defense tools for continual monitoring and analysis of system activity to identify malicious activity.
  • (NICE‑T0260) Analyzes identified malicious activity to determine weaknesses exploited, exploitation methods, effects on system and information.
  • (NICE‑T0284) Designs and develops new tools/technologies as related to cybersecurity.
  • (NICE‑T0338) Writes detailed functional specifications that document the architecture development process.
  • (NICE‑T0380) Plans instructional strategies such as lectures, demonstrations, interactive exercises, multimedia presentations, video courses, web‑based courses for the most effective learning environment in conjunction with educators and trainers.
  • (NICE‑T0427) Analyzes user needs and requirements to plan architecture.
  • (NICE‑T0503) Monitors external data sources (e.g., cyber defense vendor sites, Computer Emergency Response Teams, Security Focus) to maintain currency of cyber defense threat condition and determines which security issues may have an impact on the enterprise.
  • (NICE‑T0517) Integrates results regarding the identification of gaps in security architecture.
  • (NICE‑T0518) Performs security reviews and identifies security gaps in architecture.
  • (NICE‑T0542) Translates proposed capabilities into technical requirements.
  • (NICE‑T0548) Provides advice and input for Disaster Recovery, Contingency, and Continuity of Operations Plans.
  • (NICE‑T0549) Performs technical (evaluation of technology) and non‑technical (evaluation of people and operations) risk and vulnerability assessments of relevant technology focus areas (e.g., local computing environment, network and infrastructure, enclave boundary, supporting infrastructure, and applications).
  • (NICE‑T0550) Makes recommendations regarding the selection of cost‑effective security controls to mitigate risk (e.g., protection of information, systems and processes).
  • (NICE‑T0555) Documents how the implementation of a new system or new interface between systems impacts the current and target environment including but not limited to security posture.
  • (NICE‑T0557) Integrates key management functions as related to cyberspace.
  • (NICE‑T0926) Develops or assists with the development of privacy training materials and other communications to increase employee understanding of company privacy policies, data handling practices and procedures and legal obligations.
  • Performs other related duties as assigned that support the objective of the position.
  • Required to abide by all District policies and procedures including Board Policy 3050 – Code of Professional Ethics.

Note: NICE reference the Task Number as assigned by the National Institute of Standards and Technology (NIST) National Initiative for Cybersecurity Education / Cyber Workforce Framework (SP800-181). This framework provides guidance to employers and colleges/training for describing the task, knowledge, skills, and abilities for CyberWork.

Qualifications

The position requires a bachelor’s degree in computer science, cyber security or related technical field and 8 years’ experience in cyber security project development and implementation, and on‑going administration of integrated networks. Or any combination of education and experience which would provide the required equivalent qualifications for the position.

AND

Demonstrated evidence of responsiveness to and understanding of the racial, ethnic, disability, gender identity, sexual orientation, socioeconomic, academic, and cultural diversity within the community college student population, including students with different ability statuses (e.g., physical and/or learning) as these factors relate to the need for equity‑minded practice within the classroom.

Licenses and Certificates

Required: CISSP or CISM. Preferred: PMP, CCNA, OSCP, any GIAC certification. May require a driver license.

Desirable Qualifications
  • Certifications - MS 500, AZ 500
  • Enrolled or completed training in Identity and Access Administration Associate (SC300)
Knowledge and Skills
  • (NICE‑K0001) Knowledge of computer networking concepts and protocols, and network security methodologies.
  • (NICE‑K0002) Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
  • (NICE‑K0003) Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • (NICE‑K0004) Knowledge of cybersecurity and privacy principles.
  • (NICE‑K0005) Knowledge of cyber threats and vulnerabilities.
  • (NICE‑K0006) Knowledge of specific operational impacts of cybersecurity lapses.
  • (NICE‑K0021) Knowledge of data backup and recovery.
  • (NICE‑K0026) Knowledge of business continuity and disaster recovery continuity of operations plans.
  • (NICE‑K0033) Knowledge of host/network access control mechanisms (e.g., access control list, capabilities list).
  • (NICE‑K0034) Knowledge of network services and protocols interactions that provide network communications.
  • (NICE‑K0041) Knowledge of incident categories, incident responses, and timelines for responses.
  • (NICE‑K0042) Knowledge of incident response and handling methodologies.
  • (NICE‑K0046) Knowledge of intrusion detection methodologies and techniques for detecting host and network‑based intrusions.
  • (NICE‑K0056) Knowledge of network access, identity, and access management (e.g., public key infrastructure, Oauth, OpenID, SAML, SPML).
  • (NICE‑K0058) Knowledge of network traffic analysis methods.
  • (NICE‑K0061) Knowledge of how traffic flows across the network (e.g., Transmission Control Protocol [TCP] and Internet Protocol [IP], Open System Interconnection Model [OSI], Information Technology Infrastructure Library, current version [ITIL]).
  • (NICE‑K0062) Knowledge of packet‑level analysis.
  • (NICE‑K0063) Knowledge of parallel and distributed computing concepts.
  • (NICE‑K0070) Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross‑site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return‑oriented attacks, malicious code).
  • (NICE‑K0074) Knowledge of key concepts in security management (e.g., Release Management, Patch Management).
  • (NICE‑K0075) Knowledge of security system design tools, methods, and techniques.
  • (NICE‑K0106) Knowledge of what constitutes a network attack and a network attack’s relationship to both threats and vulnerabilities.
  • (NICE‑K0157) Knowledge of cyber defense and information security policies, procedures, and regulations.
  • (NICE‑K0161) Knowledge of different classes of attacks (e.g., passive, active, insider, close‑in, distribution attacks).
  • (NICE‑K0162) Knowledge of cyber attackers (e.g., script kiddies, insider threat, non‑nation state sponsored, and nation sponsored).
  • (NICE‑K0167) Knowledge of system administration, network, and operating system hardening techniques.
  • (NICE‑K0214) Knowledge of the Risk Management Framework Assessment Methodology.
  • (NICE‑K0211) Knowledge of confidentiality, integrity, and availability requirements.
  • (NICE‑K0221) Knowledge of OSI model and underlying network protocols (e.g., TCP/IP).
  • (NICE‑K0255) Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense‑in‑depth).
  • (NICE‑K0259) Knowledge of malware analysis concepts and methodologies.
  • (NICE‑K0287) Knowledge of an organization’s information classification program and procedures for information compromise.
  • (NICE‑K0326) Knowledge of demilitarized zones.
  • (NICE‑K0452) Knowledge of implementing Unix and Windows systems that provide radius authentication and logging, DNS, mail, web service, FTP server, DHCP, security system, and SNMP.
  • (NICE‑K0487) Knowledge of network security (e.g., encryption, firewalls, authentication, honey pots, perimeter protection).
  • (NICE‑K0516) Knowledge of physical and logical network devices and infrastructure to include hubs, switches, routers, firewalls, etc.
  • (NICE‑K0565) Knowledge of the common networking and routing protocols (e.g., TCP/IP), services (e.g., web, mail, DNS), and how they interact to provide network communications.
  • (NICE‑K0624) Knowledge of Application Security Risks (e.g., Open Web Application Security Project Top 10 list).
  • Knowledge of cyber‑attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).
  • Knowledge of cloud service models and how those models can limit incident response.
  • (NICE‑S0003) Skill of identifying, capturing, containing, and reporting malware.
  • (NICE‑S0005) Skill in applying and incorporating information technologies into proposed solutions.
  • (NICE‑S0027) Skill in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.
  • (NICE‑S0047) Skill in preserving evidence integrity according to standard operating procedures or national standards.
  • (NICE‑S0077) Skill in securing network communications.
  • (NICE‑S0078) Skill in recognizing and categorizing types of vulnerabilities and associated attacks.
  • (NICE‑S0079) Skill in protecting a network against malware. (e.g., NIPS, anti‑malware, restrict/prevent external devices, spam filters).
  • (NICE‑S0080) Skill in performing damage assessments.
  • (NICE‑S0122) Skill in the use of design methods.
  • (NICE‑S0173) Skill in using security event correlation tools/.
  • (NICE‑S0365) Skill to design incident response for cloud service models.
  • (NICE‑S0367) Skill to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non‑repudiation).
  • (NICE‑S0374) Skill to identify cybersecurity and privacy issues that stem from connections with internal and external customers and partner organizations.
Abilities
  • Requires the ability to perform the essential responsibilities and functions of the position.
  • (NICE‑A0001) Ability to identify systemic security issues based on the analysis of vulnerability and configuration data.
  • (NICE‑A0006) Ability to prepare and deliver education and awareness briefings to ensure that systems, network, and data users are aware of and adhere to systems security policies and procedures.
  • (NICE‑A0010) Ability to analyze malware.
  • (NICE‑A0015) Ability to conduct vulnerability scans and recognize vulnerabilities in security systems.
  • (NICE‑A0027) Ability to apply an organization’s goals and objectives to develop and maintain architecture.
  • (NICE‑A0038) Ability to optimize systems to meet enterprise performance requirements.
  • (NICE‑A0044) Ability to apply programming language structures (e.g., source code review) and logic.
  • (NICE‑A0066) Ability to accurately and completely source all data used in intelligence, assessment, and/or planning products.
  • (NICE‑A0120) Ability to share meaningful insights about the context of an organization’s threat environment that improve its risk management posture.
  • (NICE‑A0121) Ability to design incident response for cloud service models.
  • (NICE‑A0123) Ability to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non‑repudiation).
  • (NICE‑A0128) Ability to apply techniques for detecting host and network‑based intrusions using intrusion detection technologies.
  • (NICE‑A0159) Ability to interpret the information collected by network tools (e.g., nslookup, ping, and traceroute).
  • (NICE‑A0172) Ability to set up a physical or logical sub‑networks that separates an internal local area network (LAN) from other untrusted networks.
Physical Abilities
  • The general physical demands, working conditions, and essential job functions associated with this classification will be kept on file with the Office of Human Resources.
  • Essential functions will vary by position.
  • As defined by Title I of the Americans with Disabilities Act (“ADA”) and California’s Fair Employment and Housing Act (“FEHA”), the District shall engage in a timely, good faith interactive process with employees or employment applicants who are requesting or are in need of reasonable accommodations and, provide reasonable accommodations for employees or employment applicants who, because of their disability, are limited in or unable to perform one or more of the essential functions of their job in accordance with applicable state and federal law.
Working Conditions

Work is performed indoors where some safety considerations exist from physical labor, positioning in cramped areas, and handling of medium weight, yet awkward materials.

D.E.I.A.

Please note: To be eligible for employment, you must possess authorization to work in the United States. The District does not sponsor visas or take over any established visa sponsorship.

Eligibility & Working Hours

This is a permanent, general funded, full‑time, 12‑months per year classified position. The normal hours of work will be Monday through Friday 8:00 am to 5:00 pm, with the flexibility to occasionally work extended hours and/or weekends, if necessary, to meet the department’s needs. The effective date of employment will be arranged with the supervisor. The District provides medical, dental, and vision insurance for the employee and eligible dependents and life insurance for the employee.

Pay Philosophy

Coast Community College District, through policies, practices, and other benefit programs, delivers a fair and equitable total compensation program that promotes equal employment opportunity, inclusion, and workforce vitality. In general, it is the policy of the District to place new employees at the first step of the salary grade. All movement on the salary schedule will occur July 1 of each year for all classified employees.

Onboarding Requirements
  • Provide a Certificate of Tuberculosis Exam for initial appointment (Note: The certificate must be renewed every 4 years as a condition of continuing employment).
  • Have fingerprints taken by a Live Scan computer at the candidate’s expense (Clearance must be received prior to the first day of employment).
  • Present original documents for proof of eligibility to work in the United States including a Social Security Card; (Note: We are unable to sponsor or take over sponsorship of an employment Visa at this time.) AND
  • Participate in a new hire onboarding appointment with an Employment Services Representative.
Equal Opportunity Employer

Coast Community College District is an Equal Opportunity Employer. The Coast Community College District is committed to employing qualified administrators/managers, faculty, and staff members who are dedicated to student learning and success. The Board recognizes that diversity in the academic environment fosters awareness, promotes mutual understanding, and provides suitable role models for all students. The District does not discriminate unlawfully in providing educational or employment opportunities to any person on the basis of race, color, sex, gender identity, gender expression, religion, age, national origin, ancestry, sexual orientation, marital status, medical condition, physical or mental disability, military or veteran status, or genetic information. Coast Community College District is a multi‑college district that includes Coastline College, Golden West College, and Orange Coast College.

Title IX

Title IX & Sex Discrimination.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Financial Aid Systems Analyst (IN-HOUSE ONLY)
Financial Aid Systems Analyst (IN-HOUSE ONLY)

Coast Community College District • Huntington Beach (CA)

On-site
USD 55,000 - 75,000
Medical insurance
Dental insurance
Vision insurance
+7
Executive Director, Fiscal Services
Executive Director, Fiscal Services

Coast Community College District • California (MO)

On-site
USD 150,000 - 210,000
Medical insurance
Dental insurance
Vision insurance
+1
Student Leadership Coordinator
Student Leadership Coordinator

Association of Fundraising Professionals (AFP) Silicon Valley Chapter • Fountain Valley (CA)

On-site
USD 52,000 - 68,000
.PT Faculty POOL - Cardiovascular Technology
.PT Faculty POOL - Cardiovascular Technology

Coast Community College District • Costa Mesa (CA)

On-site
Project Coordinator
Project Coordinator

Coast Community College District • Costa Mesa (CA)

On-site
USD 55,000 - 75,000
Medical insurance access
Diversity and inclusion commitment
.PT Faculty POOL - Non-Credit ESL
.PT Faculty POOL - Non-Credit ESL

Coast Community College District • Costa Mesa (CA)

On-site
Part-Time Faculty: Flexible Teaching for Adult Learners
Part-Time Faculty: Flexible Teaching for Adult Learners

Coast Community College District • Costa Mesa (CA)

On-site
USD 69,000 - 124,000
Project Manager
Project Manager

Coast Community College District • Costa Mesa (CA)

On-site
USD 52,000 - 76,000
.PT Faculty POOL - Real Estate
.PT Faculty POOL - Real Estate

Coast Community College District • Costa Mesa (CA)

On-site
USD 69,000 - 124,000
.PT Faculty POOL - Computer Science
.PT Faculty POOL - Computer Science

Coast Community College District • Costa Mesa (CA)

On-site