- Salary
- $163k – $199k/yr
- Location
- San Jose, CA, US
- Type
- Full-time
- Department
- IT
- Seniority
- Lead
- Education
- Master
- Source
- GovernmentJobs
Description
The City of San José innovates to provide exceptional civic services using advanced technologies to help our community thrive.
As one of the largest cities in the nation, the City manages a large set of services and assets and operates on a budget of $6.2 billion, with approximately 7,000 employees, serving about 1 million residents and 80,000 businesses in the heart of Silicon Valley.
The Information Technology Department’s (ITD) mission is to enrich the quality of life in San José through innovation, collaboration, and engagement. ITD enables that mission through business and infrastructure systems, cybersecurity, data management and analysis, responsible use of Artificial Intelligence (AI), productivity and collaboration tools, the San José 311 resident experience platform, data equity and privacy programs, and strategic planning. San José is powered by truly great people, a robust technology environment, and a strong sense of purpose.
The IT department is a leader in innovation, embracing cutting-edge technologies and pioneering solutions to enhance efficiency and quality of life in San José. As part of this effort, the City leads a national initiative for AI through the GovAI Coalition, which was established to give local governments a voice in shaping the future of AI, ensuring it is developed responsibly and for the public good.
Promoting the City’s commitment to equity and inclusion, we believe that all members of the community, regardless of background, have access to the tools and resources needed to thrive in the digital age. San José is in the heart of Silicon Valley, which boasts a rich history in technology, education, and agriculture. Over half of San José residents speak a language other than English at home, highlighting the importance of language accessibility in all City services. By fostering inclusivity, promoting digital literacy, and building accessible platforms, we are advancing technology while creating a more equitable future for everyone.
At the City of San José, we promote work-life alignment and a focus on growth to bring out the best in our people. Come join us in making San José the most vibrant, equitable, sustainable, and innovative city in the nation! Visit the Information Technology Department’s website to learn about our culture, vision, leadership, and innovative initiatives.
NOTE – The first review of applications will be on September 28,2026. Please submit your application by 11:59 p.m. (PST), if you would like your application to be included in the first review.
This is a highly technical, hands-on leadership role responsible for managing a small team that protects the organization from cyber threats through cyber-threat intelligence, cybersecurity emergency response, security engineering, threat detection, and defensive security architecture.
This position requires a technically credible leader who can both manage people and directly contribute to complex cybersecurity engineering, design, configuration and implementation. The successful candidate must have expert-level technical and operational knowledge of enterprise security operations, network security, endpoint security, identity security, cloud security, security monitoring, incident response, threat hunting, and defensive architecture. This is not a purely administrative management position; the Cybersecurity Operations Manager must be capable of providing direct technical contributions, provide guidance, make sound risk-based decisions under pressure, and actively participating in complex investigations, engineering efforts, architecture reviews, detection improvements, and operational response activities.
The role is responsible for ensuring that cybersecurity tools, processes, controls, and response capabilities are effective, integrated, measurable, and aligned with organizational risk, operational priorities, and cybersecurity best practices. The ideal candidate will lead by example, set clear technical and operational expectations, improve the maturity of the security operations function, and partner closely with infrastructure, network, endpoint, cloud, application, identity, and business teams to reduce risk across the enterprise.
The ideal candidate is a strong technical leader who can operate at both the strategic and tactical levels; translating cyber threats into actionable defenses, guiding the team through high-pressure incidents, strengthening the organization’s defensive posture, and continuously improve the organization’s ability to prevent, detect, respond to, and recover from cyber threats.
Key duties include but are not limited to:
- Provide hands-on technical leadership, mentoring, prioritization, and quality assurance while coordinating with infrastructure, network, endpoint, cloud, application, identity, and service desk teams to reduce enterprise cybersecurity risk.
- Lead the collection, analysis, and operational use of cyber-threat intelligence to identify emerging threats, vulnerabilities, attacker techniques, and indicators of compromise.
- Translate intelligence into actionable defenses, including detections, hunting queries, blocking rules, advisories, and risk-based recommendations that support incident response, vulnerability management, security engineering, and leadership reporting.
- Lead cybersecurity emergency response for suspected or confirmed security incidents, including triage, containment, eradication, recovery, root-cause analysis, and post-incident improvement.
- Provide technical direction during high-pressure events involving phishing, malware, credential compromise, unauthorized access, data exposure, endpoint compromise, cloud compromise, network intrusion, or advanced threats.
- Build and maintain security operations standards, process flows, incident response playbooks, escalation procedures, evidence-handling practices, and clear incident documentation.
- Lead cybersecurity projects and operational initiatives by defining scope, milestones, deliverables, dependencies, risks, and success criteria; coordinating cross-functional technical teams, vendors, and stakeholders; tracking progress; resolving blockers; communicating status; and ensuring timely delivery of measurable security and operational outcomes.
- Lead the design, implementation, tuning, and continuous improvement of enterprise security controls across network, endpoint, cloud, identity, email, data protection, remote access, logging, monitoring, and automation environments.
- Ensure security tools are properly configured, integrated, monitored, and producing actionable outcomes. Partner with technical teams to review proposed changes, identify risks, recommend compensating controls, and embed security into enterprise solutions.
- Oversee the development, validation, tuning, and continuous improvement of detection logic across SIEM, EDR/XDR, network, identity, cloud, and email security platforms. Lead threat-hunting activities to identify suspicious behavior, control gaps, misconfigurations, compromised accounts, lateral movement, persistence, and other indicators of attacker activity. Improve detection coverage, reduce false positives, and measure operational effectiveness.
- Independently lead comprehensive cybersecurity risk reviews of complex technology implementations, including out-of-the-box vendor solutions, cloud platforms, SaaS applications, infrastructure services, endpoint tools, network technologies, IoT systems, and desktop environments. Evaluate default configurations, architecture decisions, access models, logging, data protection, integration points, and operational impacts; identifies security gaps and risk exposure; and develops practical risk-reduction strategies, compensating controls, secure configuration requirements, and implementation guidance to ensure solutions are securely deployed and operated.
- Support audit, compliance, and risk-management activities with technical evidence, control validation, and remediation support.
The successful candidate must demonstrate strong technical expertise and experience in the following areas:
- Network security, including firewalls, segmentation, routing, VPN, DNS, web filtering, secure remote access, and network traffic analysis.
- Endpoint security, including EDR/XDR, malware analysis concepts, host-based investigation, endpoint hardening, and containment strategies.
- Identity security, including Active Directory, Entra ID/Azure AD, MFA, privileged access, conditional access, account compromise investigation, and identity-based attack paths.
- Cloud security, including cloud logging, identity integration, access control, workload protection, SaaS security, and cloud misconfiguration risk.
- Security monitoring, including SIEM use cases, detection logic, log source onboarding, alert tuning, threat hunting, and incident investigation.
- Incident response, including triage, containment, eradication, recovery, root-cause analysis, evidence preservation, and after-action reporting.
- Threat intelligence, including analysis of attacker behavior, indicators of compromise, tactics, techniques, procedures, and operationalizing intelligence into controls.
- Security architecture, including defense-in-depth, zero trust principles, least privilege, secure design reviews, compensating controls, and enterprise risk reduction.
Please note that the Cybersecurity Operations Manager position is currently eligible for a hybrid telework schedule. The schedule for working remotely and onsite is subject to change.
Salary Information: The final candidate’s qualifications and experience shall determine the actual salary. In addition to the starting salary, employees in the Enterprise Principal Technology Analyst (EPTA) classification shall also receive an approximate five percent (5%) ongoing non-pensionable compensation pay.
- Salary Range $163,035.60 – $198,525.60
Education and Experience: A Bachelor’s Degree from an accredited college or university in a relevant field AND five (5) years of increasingly responsible professional/ level experience in computer applications, systems, networks, or telecommunications work, of which at least two (2) years include responsibility in the development, implementation, and maintenance of electronic business systems/solutions, or application development and/or support.
Acceptable Substitution:
- Additional years of increasingly responsible directly related work experience may be substituted for education on a year-for-year basis up to two (2) years.
- Completion of a Master's Degree in a relevant field from an accredited college or university may be substituted for one year of the required two (2) years of experience in the development, implementation, and maintenance of electronic business systems/solutions, or application development and/or support.
The ideal candidate will possess the following competencies, as demonstrated in past and current employment history. Desirable competencies for this position include:
Job Expertise – Demonstrates knowledge of and experience with applicable professional/technical principles and practices, Citywide and departmental procedures/policies, and federal and state rules and regulations.
- Experience in public sector, critical infrastructure, large enterprise, healthcare, financial services, or other highly regulated environments.
- Demonstrated experience managing complex cybersecurity projects or operational initiatives involving cross-functional technical teams, vendors, and stakeholders, with responsibility for project planning, risk and dependency management, progress tracking, issue resolution, executive communication, and delivery of measurable security or operational improvements.
- Candidate must be able to evaluate, administer, tune, and integrate security tools to improve visibility, control effectiveness, and response capabilities.
- Experience with frameworks and standards such as NIST Cybersecurity Framework, NIST 800-53, CIS Controls, MITRE ATT&CK, CJIS, PCI DSS, or ISO 27001.
- Experience building or maturing a cybersecurity operations function.
- Demonstrated experience independently evaluating complex technology implementations for cybersecurity risk, including vendor-provided, out-of-the-box, cloud, SaaS, network, endpoint, server, IoT, and desktop solutions. This includes assessing architecture, identity and access controls, logging and monitoring, data protection, endpoint and network exposure, configuration baselines, integration risks, and operational dependencies; identifying gaps or misconfigurations; and developing risk-reduction methodologies, compensating controls, secure design recommendations, and implementation requirements to reduce enterprise risk
Leadership Skills - Leads by example; demonstrates high ethical standards; remains visible and approachable and interacts with others on a regular basis; promotes a cooperative work environment, allowing others to learn from mistakes; provides motivational supports and direction.
Analytical Thinking - Approaches a problem or situation by using a logical, systematic, sequential approach.
Building Trust - Communicates an understanding of the other person's interests, needs and concerns; identifies and communicates shared interests and goals; identifies and communicates differences as appropriate; demonstrates honesty, keeps commitments, and behaves in an appropriate manner.
Project Management – Ensures support for projects and implements agency goals and strategic objectives.
Vision/ Strategic Thinking – Supports, promotes, and ensures alignment with the organization’s vision and values; understands how an organization must change in light of internal and external trends and influences; builds a shared vision with others and influences others to translate vision to action.
Problem Solving – Approaches a situation or problem by defining the problem or issue; determines the significance of problem; collects information; uses logic and intuition to arrive at decisions or solutions to problems that achieve the desired outcome.
Communication Skills – Effectively conveys information and expresses thoughts and facts clearly, orally and in writing; demonstrates effective use of listening skills; displays openness to other people’s ideas and thoughts.
Multi-Tasking - Can handle multiple projects and responsibilities simultaneously; has handled a wide variety of assignments in past and/or current position(s).
Reliability - Completes quality work assignments in a timely and efficient manner; fulfills responsibilities and maintains confidentiality as appropriate.
Teamwork & Interpersonal Skills - Develops effective relationships with co-workers and supervisors by helping others accomplish tasks and using collaboration and conflict resolution skills.
The selection process will consist of an evaluation of the applicant's training and experience based on the application and responses to all the job-specific questions. You must answer all questions to be considered, or your application may be deemed incomplete and withheld from further consideration. Only those candidates whose backgrounds best match the position will be invited to proceed in the selection process. Additional phases of the selection process will consist of one or more interviews, one of which may include a practical and/or writing exercise. If you have questions about the duties of these positions, the selection, or the hiring processes, please contact Jessica Delgado at [email protected]