Enterprise Principal Technology Analyst (Cybersecurity Operations Manager)
Manager
Senior
Cybersecurity Tools
Data Security
Edr And Xdr
Endpoint Security
Facilities Management
Identity and Access Management
Incident Response
Information Security
InfoSec
Management
Project Management
Risk Governance
Risk Management
Security
Security Compliance
Security Engineering
Security Information And Event Management
Security Monitoring
Security Operations
Security Standards
Security Testing
Threat Intelligence
Zero Trust Architecture
Job Description
San Jose Police Department seeks an Enterprise Principal Technology Analyst (Cybersecurity Operations Manager) for an onsite, hands-on leadership role across enterprise cybersecurity operations.
Responsibilities
- Provide hands-on technical leadership, mentoring, prioritization, and quality assurance while coordinating with infrastructure, network, endpoint, cloud, application, identity, and service desk teams to reduce enterprise cybersecurity risk.
- Collect, analyze, and operationalize cyber-threat intelligence to identify emerging threats, vulnerabilities, attacker techniques, and indicators of compromise.
- Convert intelligence into actionable defenses, including detections, hunting queries, blocking rules, advisories, and risk-based recommendations supporting incident response, vulnerability management, security engineering, and leadership reporting.
- Lead cybersecurity emergency response for suspected or confirmed incidents: triage, containment, eradication, recovery, root-cause analysis, and post-incident improvement.
- Provide technical direction during high-pressure events involving phishing, malware, credential compromise, unauthorized access, data exposure, endpoint compromise, cloud compromise, network intrusion, or advanced threats.
- Build and maintain security operations standards, including process flows, incident response playbooks, escalation procedures, evidence-handling practices, and clear incident documentation.
- Lead cybersecurity projects and operational initiatives by defining scope, milestones, deliverables, dependencies, risks, and success criteria; coordinate cross-functional teams, vendors, and stakeholders; track progress, resolve blockers, communicate status, and ensure measurable security/operational outcomes.
- Design, implement, tune, and continuously improve enterprise security controls across network, endpoint, cloud, identity, email, data protection, remote access, logging, monitoring, and automation environments.
- Ensure security tools are properly configured, integrated, monitored, and generating actionable outcomes; partner with technical teams on proposed changes, identify risks, recommend compensating controls, and embed security into enterprise solutions.
- Oversee detection engineering across SIEM, EDR/XDR, network, identity, cloud, and email; lead threat hunting for suspicious behavior, control gaps, misconfigurations, compromised accounts, lateral movement, persistence, and other attacker indicators; improve coverage, reduce false positives, and measure operational effectiveness.
- Independently lead cybersecurity risk reviews of complex technology implementations, including vendor and out-of-the-box solutions, cloud platforms, SaaS applications, infrastructure services, endpoint tools, network technologies, IoT, and desktop environments; evaluate default configurations, architecture decisions, access models, logging/data protection, integration points, and operational impacts; identify gaps and risk exposure; develop practical risk-reduction recommendations.
- Support audit, compliance, and risk-management activities with technical evidence, control validation, and remediation support.
Requirements
- Bachelor’s Degree from an accredited college or university in a relevant field AND five (5) years of increasingly responsible professional-level experience in computer applications, systems, networks, or telecommunications work.
- At least two (2) years must include responsibility in development, implementation, and maintenance of electronic business systems/solutions or application development and/or support.
- Additional directly related experience may substitute for education on a year-for-year basis up to two (2) years.
- A Master’s Degree in a relevant field may substitute for one year of the required two (2) years of experience in electronic business systems/solutions or application development/support.
Technologies / Frameworks
- NIST Cybersecurity Framework, NIST 800-53, CIS Controls, MITRE ATT&CK, CJIS, PCI DSS, ISO 27001
- SIEM, EDR/XDR
- Active Directory, Entra ID/Azure AD, MFA, privileged access, conditional access, zero trust
- VPN, DNS, web filtering
Required Technical Strength (Must Demonstrate)
- Network security: firewalls, segmentation, routing, VPN, DNS, web filtering, secure remote access, network traffic analysis.
- Endpoint security: EDR/XDR, malware analysis concepts, host-based investigation, endpoint hardening, containment strategies.
- Identity security: Active Directory, Entra ID/Azure AD, MFA, privileged access, conditional access, account compromise investigation, identity-based attack paths.
- Cloud security: cloud logging, identity integration, access control, workload protection, SaaS security, cloud misconfiguration risk.
- Security monitoring: SIEM use cases, detection logic, log source onboarding, alert tuning, threat hunting, incident investigation.
- Incident response: triage, containment, eradication, recovery, root-cause analysis, evidence preservation, after-action reporting.
- Threat intelligence: attacker behavior analysis, indicators of compromise, tactics, techniques, procedures, and operationalizing intelligence into controls.
- Security architecture: defense-in-depth, zero trust principles, least privilege, secure design reviews, compensating controls, and enterprise risk reduction.
Salary
- USD 163,035.60 – 198,525.60 per year
- Approximate 5% ongoing non-pensionable compensation pay in addition to starting salary for the EPTA classification
Desirable Competencies
- Experience in public sector, critical infrastructure, large enterprise, healthcare, financial services, or other highly regulated environments.
- Experience leading complex cybersecurity projects or operational initiatives involving cross-functional technical teams, vendors, and stakeholders (project planning, risk/dependency management, progress tracking, issue resolution, executive communication, delivery of measurable improvements).
- Ability to evaluate, administer, tune, and integrate security tools to improve visibility, control effectiveness, and response capabilities.
- Experience building or maturing a cybersecurity operations function.
- Experience with frameworks and standards including NIST Cybersecurity Framework, NIST 800-53, CIS Controls, MITRE ATT&CK, CJIS, PCI DSS, and/or ISO 27001.
- Proven ability to independently evaluate complex technology implementations for cybersecurity risk across vendor/out-of-the-box, cloud, SaaS, network, endpoint, server, IoT, and desktop solutions, including architecture, identity/access controls, logging/monitoring, data protection, exposure, configuration baselines, integration risks, and operational dependencies, to identify gaps and develop risk-reduction outcomes.
Additional Workforce Expectations
- Leadership skills: leads by example with high ethical standards; remains visible and approachable; promotes cooperative work environment; provides motivational support and direction.
- Analytical thinking, problem solving, communication, multi-tasking, reliability, teamwork/interpersonal skills, and project management capabilities.
- Building trust: communicates shared interests/goals, demonstrates honesty, keeps commitments, and behaves appropriately.
- Vision/strategic thinking: supports alignment with organizational vision/values and translates vision to action.
Additional Information
- Federal law requires verification of eligibility to work in the country.
- The City of San Jose will NOT sponsor, represent, or sign documents related to visa applications/transfers for H1-B or other visa types requiring an employer application.
- Applications are not accepted through CalOpps or other third-party job boards.
- This recruitment may be used to fill multiple positions in this or other divisions/departments.
- After submitting an online application, candidates receive an automatic confirmation email; if not received, email [email protected].
- Candidates are encouraged to use AI responsibly as support, but application responses and interview answers must reflect personal knowledge, skills, and experiences.