CybersecurityJobs.io
← Back to all jobs

Job Description

San Jose Police Department seeks an Enterprise Principal Technology Analyst (Cybersecurity Operations Manager) for an onsite, hands-on leadership role across enterprise cybersecurity operations.

Responsibilities

  • Provide hands-on technical leadership, mentoring, prioritization, and quality assurance while coordinating with infrastructure, network, endpoint, cloud, application, identity, and service desk teams to reduce enterprise cybersecurity risk.
  • Collect, analyze, and operationalize cyber-threat intelligence to identify emerging threats, vulnerabilities, attacker techniques, and indicators of compromise.
  • Convert intelligence into actionable defenses, including detections, hunting queries, blocking rules, advisories, and risk-based recommendations supporting incident response, vulnerability management, security engineering, and leadership reporting.
  • Lead cybersecurity emergency response for suspected or confirmed incidents: triage, containment, eradication, recovery, root-cause analysis, and post-incident improvement.
  • Provide technical direction during high-pressure events involving phishing, malware, credential compromise, unauthorized access, data exposure, endpoint compromise, cloud compromise, network intrusion, or advanced threats.
  • Build and maintain security operations standards, including process flows, incident response playbooks, escalation procedures, evidence-handling practices, and clear incident documentation.
  • Lead cybersecurity projects and operational initiatives by defining scope, milestones, deliverables, dependencies, risks, and success criteria; coordinate cross-functional teams, vendors, and stakeholders; track progress, resolve blockers, communicate status, and ensure measurable security/operational outcomes.
  • Design, implement, tune, and continuously improve enterprise security controls across network, endpoint, cloud, identity, email, data protection, remote access, logging, monitoring, and automation environments.
  • Ensure security tools are properly configured, integrated, monitored, and generating actionable outcomes; partner with technical teams on proposed changes, identify risks, recommend compensating controls, and embed security into enterprise solutions.
  • Oversee detection engineering across SIEM, EDR/XDR, network, identity, cloud, and email; lead threat hunting for suspicious behavior, control gaps, misconfigurations, compromised accounts, lateral movement, persistence, and other attacker indicators; improve coverage, reduce false positives, and measure operational effectiveness.
  • Independently lead cybersecurity risk reviews of complex technology implementations, including vendor and out-of-the-box solutions, cloud platforms, SaaS applications, infrastructure services, endpoint tools, network technologies, IoT, and desktop environments; evaluate default configurations, architecture decisions, access models, logging/data protection, integration points, and operational impacts; identify gaps and risk exposure; develop practical risk-reduction recommendations.
  • Support audit, compliance, and risk-management activities with technical evidence, control validation, and remediation support.

Requirements

  • Bachelor’s Degree from an accredited college or university in a relevant field AND five (5) years of increasingly responsible professional-level experience in computer applications, systems, networks, or telecommunications work.
  • At least two (2) years must include responsibility in development, implementation, and maintenance of electronic business systems/solutions or application development and/or support.
  • Additional directly related experience may substitute for education on a year-for-year basis up to two (2) years.
  • A Master’s Degree in a relevant field may substitute for one year of the required two (2) years of experience in electronic business systems/solutions or application development/support.

Technologies / Frameworks

  • NIST Cybersecurity Framework, NIST 800-53, CIS Controls, MITRE ATT&CK, CJIS, PCI DSS, ISO 27001
  • SIEM, EDR/XDR
  • Active Directory, Entra ID/Azure AD, MFA, privileged access, conditional access, zero trust
  • VPN, DNS, web filtering

Required Technical Strength (Must Demonstrate)

  • Network security: firewalls, segmentation, routing, VPN, DNS, web filtering, secure remote access, network traffic analysis.
  • Endpoint security: EDR/XDR, malware analysis concepts, host-based investigation, endpoint hardening, containment strategies.
  • Identity security: Active Directory, Entra ID/Azure AD, MFA, privileged access, conditional access, account compromise investigation, identity-based attack paths.
  • Cloud security: cloud logging, identity integration, access control, workload protection, SaaS security, cloud misconfiguration risk.
  • Security monitoring: SIEM use cases, detection logic, log source onboarding, alert tuning, threat hunting, incident investigation.
  • Incident response: triage, containment, eradication, recovery, root-cause analysis, evidence preservation, after-action reporting.
  • Threat intelligence: attacker behavior analysis, indicators of compromise, tactics, techniques, procedures, and operationalizing intelligence into controls.
  • Security architecture: defense-in-depth, zero trust principles, least privilege, secure design reviews, compensating controls, and enterprise risk reduction.

Salary

  • USD 163,035.60 – 198,525.60 per year
  • Approximate 5% ongoing non-pensionable compensation pay in addition to starting salary for the EPTA classification

Desirable Competencies

  • Experience in public sector, critical infrastructure, large enterprise, healthcare, financial services, or other highly regulated environments.
  • Experience leading complex cybersecurity projects or operational initiatives involving cross-functional technical teams, vendors, and stakeholders (project planning, risk/dependency management, progress tracking, issue resolution, executive communication, delivery of measurable improvements).
  • Ability to evaluate, administer, tune, and integrate security tools to improve visibility, control effectiveness, and response capabilities.
  • Experience building or maturing a cybersecurity operations function.
  • Experience with frameworks and standards including NIST Cybersecurity Framework, NIST 800-53, CIS Controls, MITRE ATT&CK, CJIS, PCI DSS, and/or ISO 27001.
  • Proven ability to independently evaluate complex technology implementations for cybersecurity risk across vendor/out-of-the-box, cloud, SaaS, network, endpoint, server, IoT, and desktop solutions, including architecture, identity/access controls, logging/monitoring, data protection, exposure, configuration baselines, integration risks, and operational dependencies, to identify gaps and develop risk-reduction outcomes.

Additional Workforce Expectations

  • Leadership skills: leads by example with high ethical standards; remains visible and approachable; promotes cooperative work environment; provides motivational support and direction.
  • Analytical thinking, problem solving, communication, multi-tasking, reliability, teamwork/interpersonal skills, and project management capabilities.
  • Building trust: communicates shared interests/goals, demonstrates honesty, keeps commitments, and behaves appropriately.
  • Vision/strategic thinking: supports alignment with organizational vision/values and translates vision to action.

Additional Information

  • Federal law requires verification of eligibility to work in the country.
  • The City of San Jose will NOT sponsor, represent, or sign documents related to visa applications/transfers for H1-B or other visa types requiring an employer application.
  • Applications are not accepted through CalOpps or other third-party job boards.
  • This recruitment may be used to fill multiple positions in this or other divisions/departments.
  • After submitting an online application, candidates receive an automatic confirmation email; if not received, email [email protected].
  • Candidates are encouraged to use AI responsibly as support, but application responses and interview answers must reflect personal knowledge, skills, and experiences.

Similar Jobs