✨ Fill and validate PDF forms with InstaFill AI. Save an average of 34 minutes on each form, reducing mistakes by 90% and ensuring accuracy. Learn more

Cybersecurity Analyst, Information Technology Department

City of San Jose San Jose, CA, CA
cybersecurity analyst information technology management security cybersecurity tools threat analyst technical people identification scanning
December 21, 2022
City of San Jose
San Jose, CA, CA
OTHER
$128528.4-156614.64/YEAR

About the Department



The City of San José is a place where we use civic technology to help our community thrive. 



As the 10th largest city in the nation, the City manages a large set of services and assets. The City operates on a budget of $5 billion, with 7,000 employees serving 1+ million residents and 80,000 businesses in the heart of Silicon Valley. 



Information Technology’s (IT) mission: Put powerful tools and information in the hands of people to unleash their brilliance in service to our community. IT enables that mission through business and infrastructure systems, cybersecurity, data management and analysis, productivity and collaboration tools, the San Jose 311 resident experience platform, data equity and privacy programs, and strategic planning. San Jose is powered by truly great people, a robust technology environment, and a strong sense of purpose. 



We promote work-life integration and a focus on growth to bring out the best in our people. Come join us in making San Jose the most vibrant, equitable, sustainable, and innovative city in America!



 



Positions & Duties



Please note that applications are currently not accepted through CalOpps or any other third party job board application system. To apply, please complete an application via the City of San Jose’s website at www.sanjoseca.gov/citycareers.



The actual salary shall be determined by the final candidate’s qualifications and experience. In addition to the starting salary, employees in the Enterprise Supervising Technology Analyst (ESTA) classification shall also receive an approximate five percent (5%) ongoing non-pensionable compensation pay.



The City of San José Information Technology Department (ITD) seeks a Cybersecurity Analyst (Enterprise Supervising Technology Analyst) to support new and existing initiatives in the Cybersecurity Office. The position will focus on threat and vulnerability management with exposure and support on all aspects of the Cybersecurity practice including cross-support for depth.



The ideal candidate will be part of one of the largest, most innovative communities in the nation. Led by the City Information Security Officer (CISO), the Cybersecurity Analyst   will implement and manage information and system security programs across the City that keep municipal services secure and resilient. The Cybersecurity Analysts will support the City Information Security Officer and the City by administering risk identification, protection and compliance, threat detection, incident response, and recovery services for all City departments to achieve business resilience.



The City of San José requires the Cybersecurity Analysts to be highly skilled to deal with emerging challenges and adapt quickly. The candidate must be able to apply expertise in all aspects of security, interface with vendors, keep their skills current, as well as provide security services to City departments with strong outcomes.



Primary duties for the Cybersecurity Analyst consist of providing support to the City and CISO in the following areas:




  • Building and managing a strong vulnerability management program. The ideal candidate will have hands-on experience with vulnerability management tools and strong technical understanding and experience assessing vulnerabilities and identifying weaknesses in multiple operating system platforms, database, and application servers.

    • Daily assessment of vulnerabilities identified by scanning tool.

    • Evaluate, rate and perform vulnerability risk assessments on assets.

    • Prioritize vulnerabilities discovered along with remediation timeline(s).

    • Send and receive notifications to the owners of assets containing vulnerabilities.

    • Maintain knowledge of the threat landscape.

    • Provide vulnerability analysis and produce reports for management.

    • Participate collecting, assessing, and cataloging threat indicators.



  • Building and managing a strong IT asset management program. The ideal candidate will have strong background in maintaining IT asset inventories, software, hardware, and logical inventory of systems.

    • Develop procedures to manage accurate IT inventory.

    • Conduct yearly inventory audits.

    • Integrate inventory with Network Access Control system.

    • Review, troubleshoot and improve inventory management procedures to ensure IT inventory is complete, accurate and actionable.

    • Integrate and consolidate existing distributed inventory systems into a central repository.

    • Ensure Cybersecurity Incident or Audit, all hardware, software, and logical systems can be traced, located, along with other appropriate attributes.

    • Procure a technology solution that integrates with other existing solutions or promote one of the existing solutions as the Enterprise solution.



  • Identifying and mitigating threats utilizing existing technologies. Working with other teams to mitigate identified vulnerabilities from identification to closure. Tracking and reporting mitigation efforts.

  • Working with other teams preparing, detecting, eradicating, and restoring operations in the event of incidents.

  • Working with relevant teams to ensure the restoration of systems and technologies in accordance to policy and based on business group needs.

  • Interfacing with the Virtual Security Operations Center (V-SOC) and using deployed tools and services to ensure monitoring of systems and networks are taking place in accordance with defined service levels, contracts, and established standards.

  • This role requires flexibility and adaptability to meet the Security needs of the ITD. The individual must be able to support other areas of expertise within the security domain such as but not limited to NIST Cybersecurity Framework implementation, Risk Management & Compliance, Risk Assessments, Training, Audit Support, and others. 



This recruitment may be used to fill multiple positions in this, or other divisions or departments. If you are interested in employment in this classification, you should apply to ensure you are considered for additional opportunities that may utilize the applicants from this recruitment. 



 



Competencies



The ideal candidate will possess the following competencies, as demonstrated in past and current employment history. Desirable competencies for this position include:



Job Expertise – Demonstrates knowledge of and experience with applicable professional/technical principles and practices; and federal and state rules and regulations. 




  • Breadth of expertise to enable managing major technology services, programs, and products across multiple departmental technology environments and ensuring cross coordination between departments, including adherence with Citywide and departmental procedures/policies and federal and state rules and regulations.

  • Expertise in updating and/or optimizing the Incident Response (IR) plan on a yearly basis to ensure maximum effectiveness.

  • Mastery in handling incidents from identification to closure.  

  • Highly skilled in updating and testing the Disaster Recovery Plan (DRP) on a yearly basis.

  • Ability to update an optimize the Threat & Vulnerability Management Plan on a yearly basis.

  • Strong experience in managing vulnerabilities from identification to closure.

  • Capability in overseeing aspects of a Virtual Security Operations Center and ensure processes and procedures are followed.

  • Experience in working with patch assessment and vulnerability scanning technologies at scale.

  • Knowledge of application, network, and operating system security.

  • Hands-on experience with Linux patching.

  • Knowledge of vulnerability scoring systems (e.g. CVSSv3).

  • Experience on vulnerability scanning tools, dynamic scans, static scans, and penetration testing.

  • Experience in using monitoring tools.

  • 5+ years in a Vulnerability Management Plan is a plus. Knowing not only how to assess vulnerabilities but also prioritize and drive remediation activities.

  • Possession of a current (non-expired) Certified Information Systems Security Professional (CISSP) or equivalent certification is highly desirable.

  • Security architecture experience is a plus.



Teamwork & Interpersonal Skills – Develops effective relationships with co-workers and supervisors by helping others accomplish tasks and using collaboration and conflict resolution skills.



Project Management – Ensures support for projects and implements agency goals and strategic objectives.



Analytical Thinking – Approaches a problem or situation by using a logical, systematic, sequential approach.



Communication Skills – Effectively conveys information and expresses thoughts and facts clearly, orally and in writing; demonstrates effective use of listening skills; displays openness to other people’s ideas and thoughts.



 



Selections Process



The selection process will consist of an evaluation of the applicant's training and experience based on the application and responses to the Job Specific Questions. Only the candidates whose backgrounds best match the position will be invited to proceed in the selection process. Additional phases of the selection process will consist of one or more interviews, one of which may include a practical/writing exercise.  



You will be prompted to answer the following job-specific questions during the online application process.  Please note that there is a 4,000-character limit, including spaces, for each text response.   




  1. Please select the areas of technical competency where you have expertise in the configuration and ongoing support of (check ALL that apply):  


    • Vulnerability Scanning tools

    • IT Asset Inventory / Management

    • Governance Risk & Compliance tools

    • Incident Response and Management

    • Contingency Planning and testing

    • Threat and Vulnerability Management

    • NIST Cybersecurity Framework

    • None of the Above



  2. Please share with us a significant Vulnerability Management implementation you led or helped lead. Please describe your role, customer impacts and involvement, and scale of the implementation. What was the outcome? What would you have done differently?

  3. Please describe your experience in managing IT asset inventories. What challenges you had and how you were able to overcome those challenges? What were the lessons learned?



You must answer all job-specific questions in order to be considered for this vacancy or your application will be deemed incomplete and withheld from further consideration. In addition, please attach your resume as part of the application process. If you have questions about the duties of these positions, the selection or hiring processes, please contact Tram Nguyen at [email protected]



 



Minimum Qualifications:



Education and Experience: A Bachelor’s Degree from an accredited college or university in a relevant field, AND four (4) years of progressively responsible professional/journey level experience, of which at least two (2) years of experience include lead technical work in development, implementation and maintenance of electronic business systems/solutions, or application development and/or support.   



Acceptable Substitution:




  • Additional years of increasingly responsible directly related work experience may be substituted for education on a year-for-year basis up to two (2) years.   

  • Completion of a Master's Degree in a relevant field from an accredited college or university may be substituted for one (1) year of the required two (2) years of experience which include lead technical work in development, implementation and maintenance of electronic business systems/solutions or application development and/or support.   



Required Licensing (such as driver’s license, certifications, etc.): Possession of a valid State of California driver’s license.



Employment Eligibility: Federal law requires all employees to provide verification of their eligibility to work in this country. Please be informed that the City of San Jose will NOT sponsor, represent or sign any documents related to visa applications/transfers for H1-B or any other type of visa which requires an employer application. 



Passing a San Jose Police Department background check is a condition of employment.



Pursuant to the City’s COVID-19 Mandatory Vaccination and Testing Policy, the City of San José is requiring all new hires to provide proof of COVID-19 vaccination as a condition of employment absent a documented medical and/or religious exemption. 



Report this job

Similar jobs near me

Related articles