> Markdown version of [/jobs/ext/1488584-senior-cyber-defense-forensics-analyst](https://www.wearedevelopers.com/jobs/ext/1488584-senior-cyber-defense-forensics-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cyber Defense Forensics Analyst - **Company:** California Department of Public Health - **Location:** Sacramento County, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $114,084.0 - $152,880.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, User Authentication, Cyber Security, Computer Networks, Digital Forensics, Hard Disk Drives, Identity and Access Management, Intrusion Detection Systems, Traceroute, Microsoft Security Essentials, Nslookup, Traffic Analysis, Software Vulnerability Management, EndPointSecurity, Diagnostic Tools, Reliability of Systems, Malware, Information Technology, Cybercrime, Cyber Warfare, Vulnerability Analysis - **Published:** July 29, 2026 - **Apply:** https://www.calcareers.ca.gov/CalHrPublic/Jobs/JobPosting.aspx?JobControlId=526526 ## About the Role * Significant experience in cyber incident response, digital forensics, or related cybersecurity functions. * Advanced knowledge of cybersecurity principles, threat analysis, and forensic methodologies. * Strong analytical, communication, and problem-solving skills. * Ability to lead complex investigations and collaborate across multiple agencies and organizations. * A commitment to protecting California's critical infrastructure and public interests., DMV Pull Program: Participation in the DMV Pull Program is required. The position(s) require(s) a valid Driver's License (DL). You must answer the questions addressing your DL on your application. Ensure you provide your DL number, class, expiration date, and any endorsements and/or restrictions., Individuals who are currently in the classification, eligible for lateral transfer, eligible for reinstatement, have list or LEAP eligibility, are in the process of obtaining list eligibility, or have SROA and/or Surplus eligibility (please attach your letter, if available). SROA and Surplus candidates are given priority; therefore, individuals with other eligibility may be considered in the event no SROA or Surplus candidates apply. Individuals who are eligible for a Training and Development assignment may also be considered for this position(s)., In addition to evaluating each candidate's relative ability, as demonstrated by quality and breadth of experience, the following factors will provide the basis for competitively evaluating each candidate: * Ability to analyze advanced malware, threats, and complex vulnerabilities. * Ability to lead vulnerability assessments, interpret scan results, and recommend remediation strategies. * Ability to analyze network traffic and packet data using diagnostic tools such as ping, traceroute, nslookup, and protocol analyzers. * Ability to detect, assess, and coordinate response to host and network intrusions using IDS/IPS technologies. * Ability to apply cybersecurity, privacy, and risk principles to enterprise requirements. * Ability to document, validate, and source intelligence and assessment data accurately and completely. * Skill in developing and deploying signatures, countermeasures, and incident response methods. * Skill in evaluating security architecture, control effectiveness, and system resilience. * Skill in identifying vulnerabilities, attack patterns, and adversarial techniques. * Skill in assessing security designs and controls using recognized standards and frameworks. * Skill in performing advanced traffic, packet, and trend analysis. * Skill in advising on cyber defense reporting, escalation, and coordination processes. * Knowledge of enterprise networking, protocols, and security architecture. * Knowledge of cyber threats, vulnerability management, and incident response. * Knowledge of authentication, access control, identity management, and cryptography. * Knowledge of operating systems, hardening methods, and system security testing. * Knowledge of applicable cybersecurity laws, policies, and data protection standards. * Knowledge of penetration testing, vulnerability tools, and emerging cyber defense technologies. * Highly desired: GIAC Security Essentials (GSEC) or equivalent industry-recognized certification, such as ISC2 SSCP. * Additional desirable certifications: GIAC Certified Enterprise Defender (GCED), GIAC Certified Intrusion Analyst (GCIA), and GIAC Continuous Monitoring (GMON), or equivalent. ## Description Secure California's Future, Join the Cybersecurity Frontlines: Become a Senior Cyber Defense Forensics Analyst at the California Governor's Office of Emergency Services (Cal OES). From wildfires to major cyber incidents, California depends on skilled professionals to protect its critical infrastructure and public safety systems. At Cal OES, we are seeking experienced cybersecurity professionals to help defend the state's digital environment and support California's cyber resilience. The California Cybersecurity Integration Center's (Cal-CSIC) primary mission is to reduce the likelihood and severity of cyber incidents that could damage California's economy, critical infrastructure, or public and private sector networks. Cal-CSIC serves as the central organizing hub of state government's cybersecurity activities and coordinates information sharing with local, state, and federal agencies, tribal governments, utilities, service providers, academic institutions, and nongovernmental organizations. Within Cal-CSIC, the Cyber Operations Branch program includes incident response, rapid response, threat identification, threat containment, threat eradication, security assessments, network perimeter vulnerability scanning, dark web review, net flow traffic analysis, endpoint detection and remediation support, and digital forensics services such as hard disk, memory, network, and malware analysis. In this role as an Information Technology Specialist III (ITS III), Senior Cyber Defense Forensics Analyst, you will lead complex cyber incident response, digital forensic analysis, threat intelligence support, and multi-agency coordination efforts in support of Cal-CSIC's mission. This position provides expert technical guidance to partner agencies and external organizations, develops after-action reviews and recommendations, delivers specialized training and briefings, and supports advanced cyber defense strategies and solutions., * Leading cyber incident response and forensic investigations for partner agencies and external organizations. * Providing expert technical guidance and support to multi-agency incident response teams. * Preparing after-action reviews, forensic reports, and recommendations for stakeholders. * Delivering training, briefings, and technical consultation to cybersecurity professionals and partner organizations. * Supporting the development and implementation of advanced cyber defense tools, monitoring strategies, and response capabilities. * Coordinating with state, local, tribal, federal, and private-sector partners to strengthen cyber defense and resilience., In the event of an emergency, employees may be contacted and requested to report to work in the event of an emergency. This contact may be outside of your normal working hours (evenings/nights, weekends, and holidays). This service may require irregular work hours, work locations other than the official duty location, and may include duties other than those specified in your official position description. Travel requirements in support of emergency operations may be extensive in nature (weeks to months), with little advance notice, and you may be required to relocate to emergency sites. More information may be found here: Homeland Security | California Governor's Office of Emergency Services Department Website: http://www.caloes.ca.gov, The following items are required to be submitted with your application. Applicants who do not submit the required items timely may not be considered for this job: * Current version of the State Examination/Employment Application STD Form 678 (when not applying electronically), or the Electronic State Employment Application through your Applicant Account at www.CalCareers.ca.gov. All Experience and Education relating to the Minimum Qualifications listed on the Classification Specification should be included to demonstrate how you meet the Minimum Qualifications for the position. * Resume is required and must be included. * Statement of Qualifications - Please refer to the Statement of Qualifications (SOQ) section at the bottom of this job bulletin for the filing instructions and the SOQ Question(s). Applications submitted without the SOQ may not be considered. Applicants requiring reasonable accommodations for the hiring interview process must request the necessary accommodations if scheduled for a hiring interview. The request should be made at the time of contact to schedule the interview. Questions regarding reasonable accommodations may be directed to the EEO contact listed on this job posting., Please respond to the following prompts, providing detailed examples and explanations where appropriate. * Provide an example of a time when you performed or identified a cybersecurity issue and remediated the issue. * Provide an example of the incident response lifecycle with regards to a cybersecurity incident you were involved in. * Of all the trainings available for cybersecurity incident response which do you find most beneficial and why? Looking for guidance on navigating the state's job board or need assistance with uploading your documents or SOQ? Check out helpful how-to videos here: Work4CA: How to Get a State Job Series - YouTube to make your job search easier and more effective! ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)