Cybersecurity Manager
Manager
Cloud Platforms
Cloud Security
Cyber Security
Cybersecurity Tools
Data Security
Endpoint Security
Incident Management
Incident Response
Information Security
Information Technology (IT)
InfoSec
Management
Risk Management
Security
Security Automation
Security Information And Event Management
Security Monitoring
Security Operations
Security Standards
SOAR
Web Application Firewall
Zero Trust
Zero Trust Architecture
Job Description
The State Bar of California is seeking a Cybersecurity Manager to lead and strengthen the organization’s cybersecurity program. In this onsite role in San Francisco, CA, you will provide both strategic direction and hands-on technical leadership to protect a hybrid technology environment that includes infrastructure services and multi-cloud solutions.
Reporting into senior leadership, this position focuses on risk-based security planning, incident readiness, continuous monitoring, and the execution of security controls across people, process, and technology.
Key Responsibilities
- Execute the organization’s risk-based cybersecurity strategy to protect systems, data, and operations.
- Establish, enforce, and continuously improve security policies, standards, and procedures aligned with organizational goals.
- Serve as the hands-on technical lead for security incident response, directing triage, investigation, containment, and recovery, including log, endpoint, and network analysis and digital forensics; coordinate vendors and partners during events.
- Develop, test, and maintain the incident response plan, and run tabletop and recovery exercises for technical teams and leadership.
- Collaborate with internal teams and external partners to integrate security across operations.
- Improve cybersecurity visibility by building dashboards that provide actionable insights for executives and IT teams.
- Oversee the design and implementation of secure IT architectures in collaboration with technical teams.
- Automate security monitoring and incident response workflows using SOAR frameworks.
- Oversee security monitoring and analytics capabilities using SIEM and threat-hunting tools.
- Conduct risk and vulnerability assessments and implement remediation strategies.
- Ensure compliance with applicable regulatory and industry security and privacy standards relevant to the State Bar.
- Oversee encryption solutions and help ensure timely security patching and updates in coordination with infrastructure teams.
- Develop, test, and maintain the incident response plan and investigate and remediate security incidents.
- Conduct security awareness training to support a security-first culture.
- Research, evaluate, and implement advanced security tools and emerging technologies to enhance security posture and resilience.
- Maintain detailed documentation of security policies, procedures, and incidents.
- Execute cloud security strategy supporting Hybrid and Multi-Cloud solutions across various providers.
- Provide actionable reports to senior management on cybersecurity risks, status, and improvement initiatives.
- Oversee assigned infrastructure services to ensure they are secure, reliable, and well maintained.
- Supervise, coach, and develop technical staff, ensuring they have tools, training, and direction for continuous growth.
Technologies and Tools
- Next-Generation Firewalls (NGFWs)
- Extended Detection and Response (XDR)
- Endpoint Detection and Response (EDR)
- Web Application Firewall (WAF)
- Security Information and Event Management (SIEM)
- Zero Trust Architecture (ZTA)
- Defense in Depth
- Microsoft Defender for Cloud
- Microsoft Sentinel
- CIS Cloud Controls
- SOAR
- SIEM
Minimum Qualifications
- Minimum five (5) years of experience in IT security, including three (3) years of supervisory or team-lead experience.
- Experience with IT infrastructure operations is highly desirable.
- Professional certifications such as CISSP or equivalent are a plus but not required.
Required Education
- Bachelor’s degree in computer science, cybersecurity, or a related field (or equivalent experience).
Knowledge and Skills
- Cybersecurity tools and technologies, including NGFWs, XDR, EDR, WAF, and SIEM systems.
- Secure system and network design principles, including Zero Trust Architecture (ZTA) and Defense in Depth.
- Cloud security frameworks and tools (including Microsoft Defender for Cloud, Microsoft Sentinel, and CIS Cloud Controls).
- Encryption technologies and secure data handling practices across data at rest, in transit, and during processing.
- Systems hardening principles and practices.
- Compliance frameworks and regulatory security and privacy standards, including FedRAMP, NIST, ISO 27001, GDPR, HIPAA, and PCI DSS.
- Incident response frameworks; risk assessment and vulnerability assessment methods; penetration testing and threat intelligence.
- Security training and awareness best practices.
- Documentation and reporting methods for policies, procedures, and incident records.
- Principles of supervision, staff development, and performance management.
- Ability to oversee security technology implementation and assigned infrastructure operations.
- Ability to interpret and apply compliance frameworks and regulatory standards.
- Ability to analyze and resolve security incidents proactively, and to communicate complex security concepts to technical and non-technical audiences.
- Ability to collaborate with stakeholders, adapt to changing priorities, and present strategies clearly.
- Ability to maintain confidentiality and professionalism with sensitive information.
Compensation
Annual salary range (IT Manager II): $135,696 to $180,902.