Cloud Network Security Operations Engineer

California Department of Public Health
Sacramento County, CA, United States
4 days ago
Apply on www.calcareers.ca.gov
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$114,084.0 - $152,880.0
Working hours
Regular working hours

Tech stack

Testing (Software) Software Applications Software System Penetration Testing Microsoft Azure Cloud Computing Security CompTIA Security+ Cyber Security Network Address Translation White-Box Testing Identity and Access Management Internet Protocol Network Security
+14 more
Network Segmentation Phishing Zero Trust Network Access Software Vulnerability Management Cloud-native Network Functions (CNF) Office365 Software Security Firewalls (Computer Science) Web Filtering GWAPT Information Technology Cloudflare Microsoft Sentinel Cisco Switches

Job description

This position is limited term for 12 months but may be extended for an additional 12 months, not to exceed 2 years. This position may become Permanent/FT pending budget approval.

Under administrative direction of the Information Technology Manager II (Chief Information Security Officer) , the Information Technology Specialist III (Cloud Network Security Operations Engineer) performs a variety of complex level tasks in relation to the responsibility of identifying, collecting, examining, and preserving digital evidence using controlled and documented analytical and investigative techniques. This position will support and or maintain cloud security, network security and security operational activities to include secure cloud infrastructure, network controls, network firewalls, incident response, end point protection, penetration testing, vulnerability management, anti-phishing, security awareness training and technical security governance risk and compliance initiatives. This position is a senior subject matter expert and will serve as a liaison between LCI and third-party providers. The incumbent will communicate and actively maintain working relationships with customers for various security controls, security governance and operational information technology security troubleshooting purposes., The Governor’s Office of Land Use and Climate Innovation (LCI) serves the Governor and his Cabinet as staff for long-range planning and research and constitutes the comprehensive state planning agency. LCI assists the Governor and the Administration in planning, research, policy development, and legislative analysis. LCI formulates long- range state goals and policies to address land use, climate change, population growth and distribution, urban expansion, infrastructure development, groundwater sustainability and drought response, and resource protection. LCI’s budget programs include State Planning and Policy Development, Strategic Growth Council, and Racial Equity Commission. LCI is a fast-paced, creative work environment that requires staff to have strong collaboration skills, an ability to quickly respond to changing policy needs, and a positive attitude and sense of humor. Proven commitment to creating a work environment that celebrates diverse backgrounds, cultures, and personal experiences.

Telework

This position is eligible for hybrid work in accordance with the Governor’s Executive Order N-22-25 and at the sole discretion of LCI under California Government Code Section 14200. The incumbent is required to report in-person and site-based four days per week. All telework schedules are subject to change and may be re-evaluated at any time. The incumbent will be expected to report for in office work and attend work related in-person events as deemed operationally necessary. Telework does not change the terms and conditions of employment, the essential functions of job duties, or required compliance with LCI policies., The Statement of Qualifications must be typed, no more than two pages, using Arial 12-point font, and must include the applicant’s name in the header. Do not submit a cover letter in place of the Statement of Qualifications. Please respond to the following:

  1. Describe your approach to designing a Zero Trust network architecture, including network segmentation, identity and access management, least-privilege access, and continuous verification. What technologies or security strategies have you implemented in practice?
  2. Describe your experience using a secure-by-design approach to cloud security to meet enterprise security baselines. What specific controls did you prioritize and why?
  3. Describe your experience responding to a security incident. Explain your process, prioritization, use of security tools, and communication throughout the stages of the incident. Explain your role in the steps that were taken during the incident, as well as what was done after the incident.

Additional Application Instructions Using the online application system as specified in the announcement is the preferred method of applying for civil service job opportunities; however, applicants may instead apply by way of U.S. mail, parcel delivery or courier service, or in person, as set forth in this announcement. All information regarding your employment history must be included on the State Employment Application STD. 678. Applications that are submitted blank or with “see resume” in place of duties performed or applications received without the following information for each job entry will be considered incomplete and will not be accepted:

  • “To” and “from” dates (month/day/year)
  • Hours worked per week
  • Private sector job titles
  • Supervisor name and phone number
  • Job duties performed
  • State employees must list the specific departments for which they worked and indicate the specific civil service classification titles held (not working titles). Transcripts If you are meeting minimum qualifications with education, you must include your unofficial transcripts for verification. Foreign transcripts must include official verification of U.S. equivalency prior to appointment by an organization found here. Personal Identifying Information Please do not include your Social Security Number, date of birth, veteran status, personal photos, LEAP information, or any other personally identifying information on any documents in your application package.

Requirements

Persons appointed to this position must be reasonably expected to lift, carry, push, pull, or otherwise move objects weighing up to 30 lbs. with or without a reasonable accommodation. This position involves sitting most of the time and may involve walking or standing for brief periods of time. This position may be eligible to participate in LCI’s hybrid telework schedule. Participation in telework is subject to LCI’s guidelines. Occasional extended hours outside of normal working business hours may be required., * Ability to maintain consistent attendance

  • Ability to demonstrate punctuality, initiative, and dependability
  • Ability to work independently, while working with others in a small group environment, In addition to evaluating each candidate’s relative ability, as demonstrated by quality and breadth of experience, the following factors will provide the basis for competitively evaluating each candidate:
  • Experience writing technical documentation that includes system security plans, network flow diagrams, security standards and procedures.
  • Demonstrated problem-solving abilities to manage complex state, local and international security requirements.
  • Successful track record collaborating with technical and non-technical teams to promote ideas to support business enablement.
  • Skill in mentoring and operationally leading security team members.
  • Skill in identifying software vulnerabilities.
  • Skill in identifying, capturing, containing and reporting malware and ransomware.
  • Experience with HP Aruba ClearPass Policy Manager, Network Address Translation/Internet Protocol (NAT/IP), Cloudflare network security solutions, Cisco switches, Extreme switches, Aruba networks, firewall and demilitarized zone (DMZ) (Perimeter Network) using Palo Alto firewall and Palo Alto web filtering, Prisma SASE and or the equivalent.
  • Experience with application security.
  • Experience with Microsoft Sentinel, Defender, or other EDR solutions/SIEMs.
  • Experience in offensive security testing.
  • Experience in leading security investigations to lessons learned activities.
  • Experience in architecting and engineering MS Azure infrastructure cloud platforms that include M365, access management, Azure, Purview, eDiscovery and zero-trust principles.
  • Skill in applying white-box and black-box software testing.
  • Skill and experience in the cybersecurity kill chain to mitigate thread adversary techniques, tactics, and procedures.
  • Strong communication skills to clearly express ideas and concepts, both written and verbally.
  • Ability to perform in a support role and take responsibility for mission-critical secure infrastructure components that include network security, asset vulnerability, security assessment and end point protection risk assessments.
  • One or more certifications in cloud, network and security operations of the following: Azure: MS Cybersecurity Architect Expert, Azure Security Engineer Associate, CompTIA: Cloud+, CompTIA Security+, ISC2: CISSP, CCSP, SANS: GCIA, GMON, GPEN, GWAPT, GCTD, GCPN, GCFR, GREM and GCSA.
  • Experience writing technical documentation for workflows, plans, guidelines, policies, standards and procedures to meet business requirements for security assurance and compliance.

Benefits & conditions

There are many benefits to joining our team! We offer competitive pay, advancement opportunities, upward mobility, work-life-balance, and for many positions, flexible hours and remote work options. The State of California offers a competitive and comprehensive benefits package, subject to eligibility, such as:

  • Pension through CALPERS
  • Medical Benefits, including health, dental, and vision insurance
  • Medical benefits into retirement
  • Deferred Compensation options: 401k and 457b
  • Leave benefit options (Vacation/Sick or Annual Leave)
  • Paid Holidays
  • Life Insurance
  • ScholarShare (College Saving Account)
  • School Loan forgiveness under the federal Public Service Loan Forgiveness Program Benefit information can be found on the CalHR website and the CalPERS website.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.calcareers.ca.gov
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

2:04 min

Designing an automated phishing attack pipeline

Wolfgang Ettlinger +1 · World Congress 2023

Videos

See all

Related articles

See all