Lead IT operations and information security across production infrastructure and AWS migration in a hands-on management role based in Folsom, CA.
Responsibilities
- Run IT operations and information security for infrastructure, cloud, cybersecurity, staffing, vendors, budgets, projects, and policies.
- Provide regular reporting to executive leadership on risk, operations, and AWS migration progress.
- Manage IT staffing including recruiting, supervision, scheduling, development, evaluation, and performance or disciplinary actions.
- Own IT financial management: budgeting, purchasing, vendor and contract negotiation, licensing and renewals, and AWS/cloud spend.
- Partner with Help Desk for end-user issues and coordinate communication of infrastructure and security changes.
- Own technical delivery of continued migration of infrastructure, applications, and services to AWS.
- Evaluate workloads for migration, modernization, re-platforming, or retirement.
- Design, operate, and govern secure, scalable AWS environments, covering account structure, networking, compute, storage, database services, logging, monitoring, backup, and cost optimization.
- Maintain enterprise infrastructure during the cloud transition, spanning AWS, Microsoft 365/Entra ID, networking, firewalls, telecom, datacenter or colocation, and remaining on-premises and VMware environments.
- Oversee production availability, backup, disaster recovery, patching, capacity planning, and change management with appropriate documentation.
- Own the company’s cybersecurity architecture and posture across AWS, infrastructure, endpoints, applications, and users, including IAM and least-privilege design plus AWS-native security tooling.
- Lead security operations using SIEM/SOC monitoring with Splunk Enterprise Security, including detection and alerting; manage endpoint security (EDR/XDR), vulnerability management, and email/web security and awareness training.
- Serve as primary escalation point for incident response.
- Maintain a NIST CSF-aligned cybersecurity governance program: audits, assessments, cybersecurity insurance requirements, and customer or vendor security questionnaires.
- Partner with Software Engineering to integrate security into the SDLC with penetration testing, SAST/DAST, dependency and IaC scanning, and CI/CD security controls for cloud-native AWS applications.
- Maintain security policies, standards, and procedures; track risks and remediation for leadership visibility.
Requirements
- 10+ years of progressive experience across IT infrastructure, cloud operations, and cybersecurity.
- 5+ years leading technical teams or technology functions.
- Hands-on experience architecting, operating, troubleshooting, governing, and securing production AWS, including IAM, networking, logging and monitoring, native AWS security services, and meaningful contribution to AWS migrations.
- Experience managing both enterprise IT operations and security operations, including building or operating SIEM/SOC and incident-response capabilities.
- Hands-on knowledge of Microsoft technologies: Microsoft 365, Entra ID, Windows Server, Active Directory, DNS, Exchange, and group policies.
- Enterprise networking experience: Cisco IOS, router and switch configuration, SNMP, TCP/IP, WAN/LAN, firewalls, and remote access.
- Knowledge of vulnerability management, and security across endpoints, network, identity, application, and cloud; experience with NIST CSF supporting audits and assessments.
- Experience managing highly available production infrastructure, backup, and disaster-recovery environments.
- Strong analytical skills and communication including oral, interpersonal, and technical or business writing; ability to translate complex technical and cybersecurity risk for executive and business leadership.
- Project management, vendor management, budget management, and people management skills; ability to work independently, prioritize, and handle multiple initiatives amid changing business demands.
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent work experience.
Technical Environment & Tools
- AWS Organizations, IAM, VPC, EC2, S3, RDS, ELB/ALB, Route 53
- CloudWatch, CloudTrail, GuardDuty, Security Hub, Inspector, Config, IAM Access Analyzer, KMS, WAF/Shield, Secrets Manager, AWS Backup
- Infrastructure as Code, Splunk Enterprise Security, SIEM, EDR/XDR
- Cisco Secure Endpoint, Cisco Umbrella, IDS/IPS
- Microsoft 365, Entra ID, Exchange Online, SSO, MFA, Conditional Access, Active Directory, DNS, group policies, DLP
- Penetration testing, SAST/DAST, Veracode, CI/CD security
- AWS Bedrock, Copilot, Claude, Kiro
- NIST CSF, cloud governance, incident response, risk management
- Additional infrastructure: VMware vSphere, VDI, Windows Server, Cisco firewalls and switches and routers, telecommunications
Physical Demands and Work Environment
- Hybrid role headquartered in Folsom, CA with several days on-site required during initial onboarding.
- After training, location flexibility with a requirement to travel to the Folsom office monthly for on-site team visits and attend occasional company-wide events or executive meetings.
- On-call availability required.
- Close vision and ability to communicate via speaking and listening.
- Ability to use a computer keyboard, mouse, and other devices for significant portions of the workday.
- Occasional handling of computer components, tools, cables, and moderately heavy objects such as computers and peripherals; occasional inspection of cables in floors and ceilings.
- If remote: reliable high-speed internet access and a quiet, private workspace free from distractions.
- Additional job-related physical requirements may apply as needed.
Preferred Qualifications
- AWS certifications such as AWS Certified Solutions Architect and/or AWS Certified Security – Specialty.
- CISSP, CISM, CCSP, Microsoft, VMware, Cisco, or comparable professional certifications.
- MBA or advanced degree with a technology, cybersecurity, or business leadership focus.
- Experience with Infrastructure as Code and cloud automation.
- Experience securing cloud-native applications, containers, APIs, and CI/CD environments.
- Experience in organizations with mature cybersecurity, compliance, audit, and cybersecurity insurance requirements.
Compensation: USD 170,000 - 220,000 per year.