Senior Cyber Defense Forensics Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+9 more
Job description
Secure Californiaās Future, Join the Cybersecurity Frontlines: Become a Senior Cyber Defense Forensics Analyst at the California Governorās Office of Emergency Services (Cal OES). From wildfires to major cyber incidents, California depends on skilled professionals to protect its critical infrastructure and public safety systems. At Cal OES, we are seeking experienced cybersecurity professionals to help defend the stateās digital environment and support Californiaās cyber resilience.
The California Cybersecurity Integration Centerās (Cal-CSIC) primary mission is to reduce the likelihood and severity of cyber incidents that could damage Californiaās economy, critical infrastructure, or public and private sector networks. Cal-CSIC serves as the central organizing hub of state governmentās cybersecurity activities and coordinates information sharing with local, state, and federal agencies, tribal governments, utilities, service providers, academic institutions, and nongovernmental organizations. Within Cal-CSIC, the Cyber Operations Branch program includes incident response, rapid response, threat identification, threat containment, threat eradication, security assessments, network perimeter vulnerability scanning, dark web review, net flow traffic analysis, endpoint detection and remediation support, and digital forensics services such as hard disk, memory, network, and malware analysis.
In this role as an Information Technology Specialist III (ITS III), Senior Cyber Defense Forensics Analyst, you will lead complex cyber incident response, digital forensic analysis, threat intelligence support, and multi-agency coordination efforts in support of Cal-CSICās mission. This position provides expert technical guidance to partner agencies and external organizations, develops after-action reviews and recommendations, delivers specialized training and briefings, and supports advanced cyber defense strategies and solutions., * Leading cyber incident response and forensic investigations for partner agencies and external organizations.
- Providing expert technical guidance and support to multi-agency incident response teams.
- Preparing after-action reviews, forensic reports, and recommendations for stakeholders.
- Delivering training, briefings, and technical consultation to cybersecurity professionals and partner organizations.
- Supporting the development and implementation of advanced cyber defense tools, monitoring strategies, and response capabilities.
-
Coordinating with state, local, tribal, federal, and private-sector partners to strengthen cyber defense and resilience., In the event of an emergency, employees may be contacted and requested to report to work in the event of an emergency. This contact may be outside of your normal working hours (evenings/nights, weekends, and holidays). This service may require irregular work hours, work locations other than the official duty location, and may include duties other than those specified in your official position description. Travel requirements in support of emergency operations may be extensive in nature (weeks to months), with little advance notice, and you may be required to relocate to emergency sites. More information may be found here: Homeland Security | California Governorās Office of Emergency Services Department Website: http://www.caloes.ca.gov, The following items are required to be submitted with your application. Applicants who do not submit the required items timely may not be considered for this job:
- Current version of the State Examination/Employment Application STD Form 678 (when not applying electronically), or the Electronic State Employment Application through your Applicant Account at www.CalCareers.ca.gov. All Experience and Education relating to the Minimum Qualifications listed on the Classification Specification should be included to demonstrate how you meet the Minimum Qualifications for the position.
- Resume is required and must be included.
- Statement of Qualifications - Please refer to the Statement of Qualifications (SOQ) section at the bottom of this job bulletin for the filing instructions and the SOQ Question(s). Applications submitted without the SOQ may not be considered.
Applicants requiring reasonable accommodations for the hiring interview process must request the necessary accommodations if scheduled for a hiring interview. The request should be made at the time of contact to schedule the interview. Questions regarding reasonable accommodations may be directed to the EEO contact listed on this job posting., Please respond to the following prompts, providing detailed examples and explanations where appropriate.
- Provide an example of a time when you performed or identified a cybersecurity issue and remediated the issue.
- Provide an example of the incident response lifecycle with regards to a cybersecurity incident you were involved in.
- Of all the trainings available for cybersecurity incident response which do you find most beneficial and why?
Looking for guidance on navigating the stateās job board or need assistance with uploading your documents or SOQ? Check out helpful how-to videos here: Work4CA: How to Get a State Job Series - YouTube to make your job search easier and more effective!
Requirements
- Significant experience in cyber incident response, digital forensics, or related cybersecurity functions.
- Advanced knowledge of cybersecurity principles, threat analysis, and forensic methodologies.
- Strong analytical, communication, and problem-solving skills.
- Ability to lead complex investigations and collaborate across multiple agencies and organizations.
- A commitment to protecting Californiaās critical infrastructure and public interests., DMV Pull Program: Participation in the DMV Pull Program is required. The position(s) require(s) a valid Driverās License (DL). You must answer the questions addressing your DL on your application. Ensure you provide your DL number, class, expiration date, and any endorsements and/or restrictions., Individuals who are currently in the classification, eligible for lateral transfer, eligible for reinstatement, have list or LEAP eligibility, are in the process of obtaining list eligibility, or have SROA and/or Surplus eligibility (please attach your letter, if available). SROA and Surplus candidates are given priority; therefore, individuals with other eligibility may be considered in the event no SROA or Surplus candidates apply. Individuals who are eligible for a Training and Development assignment may also be considered for this position(s)., In addition to evaluating each candidateās relative ability, as demonstrated by quality and breadth of experience, the following factors will provide the basis for competitively evaluating each candidate:
- Ability to analyze advanced malware, threats, and complex vulnerabilities.
- Ability to lead vulnerability assessments, interpret scan results, and recommend remediation strategies.
- Ability to analyze network traffic and packet data using diagnostic tools such as ping, traceroute, nslookup, and protocol analyzers.
- Ability to detect, assess, and coordinate response to host and network intrusions using IDS/IPS technologies.
- Ability to apply cybersecurity, privacy, and risk principles to enterprise requirements.
- Ability to document, validate, and source intelligence and assessment data accurately and completely.
- Skill in developing and deploying signatures, countermeasures, and incident response methods.
- Skill in evaluating security architecture, control effectiveness, and system resilience.
- Skill in identifying vulnerabilities, attack patterns, and adversarial techniques.
- Skill in assessing security designs and controls using recognized standards and frameworks.
- Skill in performing advanced traffic, packet, and trend analysis.
- Skill in advising on cyber defense reporting, escalation, and coordination processes.
- Knowledge of enterprise networking, protocols, and security architecture.
- Knowledge of cyber threats, vulnerability management, and incident response.
- Knowledge of authentication, access control, identity management, and cryptography.
- Knowledge of operating systems, hardening methods, and system security testing.
- Knowledge of applicable cybersecurity laws, policies, and data protection standards.
- Knowledge of penetration testing, vulnerability tools, and emerging cyber defense technologies.
- Highly desired: GIAC Security Essentials (GSEC) or equivalent industry-recognized certification, such as ISC2 SSCP.
- Additional desirable certifications: GIAC Certified Enterprise Defender (GCED), GIAC Certified Intrusion Analyst (GCIA), and GIAC Continuous Monitoring (GMON), or equivalent.
Benefits & conditions
- Provide the āFromā and āToā dates with the month, day and year, the āHours Per Weekā that you worked and the Total Worked (Years/Months). You may include overtime hours.
- You must complete the āDUTIES PERFORMEDā on the State Application (do not note āsee attached resumeā in this section). Failure to comply and your application is considered incomplete.
- SROA and Surplus are encouraged to apply and must submit a copy of their letter.
- Please note consideration shall be given to work experience gained in a part-time or full-time job, regardless of whether the job was a paid or a volunteer position or was within, or outside of, state service.
If using education to qualify please submit a copy of your transcripts. If selected, official transcripts will be required. Foreign education must obtain and submit verification of United States course/degree equivalency., Cal OES employees are eligible for a number of benefits and working for us is a great opportunity to join a committed team. Benefits include but are not limited to the following:
- Free Parking
- On-site Gym and Locker room
- Electric Carport
- Excellent CalPERS state pension plan
- 401(k) and 457(b) Plans
- Flexible Schedules
- Generous paid time off
- Health, dental & vision insurance for the employee or the employeeās family
- Investment in careers development
- Located near many local eateries, financial institutions, and the Light Rail Station
About the company
Joining Cal OES means working alongside dedicated professionals at the forefront of cybersecurity while contributing to the safety and security of Californians.
This position is located at our Mather Campus and is eligible for a hybrid work schedule which may include up to one day of remote work per week. Additional in-office days may be required based on business needs., The California Governorās Office of Emergency Services (Cal OES) is committed to fostering a diverse and inclusive culture by hiring and retaining individuals from a variety of backgrounds and personal experiences. Our employees are empowered with the tools and resources necessary to meet our mission, while continuing to expand equity and inclusion efforts at all levels of the organization. We are committed to the spirit and work required to ensure the safety and resilience of every community in California. Cal OES is an emergency response, homeland security, and disaster recovery agency and as a result, is a dynamic and exciting place to work in a team-oriented environment. Cal OES provides training to enhance the understanding of emergency and incident management to all employees.
Homeland Security is the coordinated effort to ensure we are prepared to prevent, protect against, mitigate, respond to and recover from threats and acts of terrorism, plus other man-made or natural disasters or catastrophes. It requires a risk management process in order to ensure California has the right capabilities in place to manage those hazards that pose the greatest risk to the State, its people, and its critical infrastructure and key resources.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.calcareers.ca.govGood distractions
Talks and stories from around this role ā technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
The Overflow: Security and Privacy
Dev Digest 191: Malware interviews, EU ā¤ļø Open Source and Skilled Agents
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.