Information Security Architect
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+46 more
Job description
Under the administrative direction of the Information Technology Manager II (IT Mgr II), the Information Technology Specialist III (IT Spec III) serves as the Office of Information Security’s (OIS) Lead Data Architect for the Security Operations Center (SOC). The IT Spec III is responsible for the architecture, design, development, integration, and management of the large-scale security data platform that supports the agency’s threat detection, incident response, and cyber defense mission. The IT Spec III leads data architecture and data modeling efforts to establish efficient, secure, and scalable methods for collecting, storing, correlating, and reporting high-volume security telemetry across a multi-tenant environment, and designs the data lake/lake house foundation that enables advanced analytics, machine learning, and AI-enabled and agentic automation for security operations. This is accomplished through the delivery of services across IT domains including Software Engineering, System Engineering, Information Security Engineering, and IT Project Management, and through the IT Spec III’s leadership of the on-premises AI compute platform used to fine-tune, evaluate, and serve the machine learning and large language models supporting Tier 1 security operations. The IT Spec III works independently or collaboratively, and acts in a lead capacity to plan and coordinate technology solutions addressing the agency’s most complex security problems, including the expansion of SOC services to additional state, local, and critical-infrastructure partners, and the engineering of AI-assisted detection, triage, and threat-hunting capabilities. Additionally, the IT Spec III solicits and considers internal and external customer input when completing work assignments in the Security Solutions Operations Unit, and maintains ongoing contact with technical, administrative, and managerial staff across CDT and customer organizations. The technologies supporting these functions include Microsoft Azure (Microsoft Sentinel, Log Analytics, Azure Data Lake Storage); Databricks, Delta Lake, and Apache Spark; Kusto Query Language (KQL); Microsoft Defender XDR; MS SQL Server and T-SQL; Python (including PySpark); data pipeline/ELT tooling; REST and GraphQL web services and APIs; JSON and XML; Power BI, Power Apps, and Power Automate; containerization (Docker) and version control (GitHub); large language model (LLM) and agentic AI frameworks; and Red Hat Linux and Windows Server.
Telework This position is eligible for a hybrid work schedule within California based on departmental policy and operational needs. The telework policy is subject to change depending on business needs, and/or reporting to the work site may be required with minimal notification given. Pursuant to Executive Order, effective July 1, 2025, employees in this position will be required to report to the work site a minimum of two (2) days per week, increasing to four (4) days per week effective July 1, 2026. The specific on-site days will be determined by the department based on operational requirements. Visa Sponsorship Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time., The California Department of Technology (CDT) is the guardian of public data, a leader in information technology (IT) services and solutions and has broad responsibility and authority over all aspects of technology in California state government, including policy formation, interagency coordination, IT project oversight, information security, technology service delivery, and advocacy. As an industry leader, we are committed to partnering with state and local government and educational entities to deliver digital services, develop innovative and responsive solutions for business needs, and provide quality assurance for state government IT projects and services. Our success and legacy of service is reliant upon our highly talented, dedicated, and diverse workforce, for it is our individual cultural diversity, backgrounds, experiences, perspectives, and unique identities that spark our collaborative strength and innovative approach to serving the State of California.
Effective July 1, 2025, State employees are subject to a salary reduction of three percent in exchange for five hours per month of the Personal Leave. Personal Leave Program: Effective July 1, 2025, state employees are subject to temporary wage reductions in exchange for Personal Leave Program (PLP) accruals. The specific rate and hours earned were negotiated and agreed upon by each bargaining unit. The actual monetary impact of these temporary reductions can vary based on your bargaining unit and/or federal and state tax withholdings. For additional information please visit Human Resources Manual - CalHR Department Website: https://cdt.ca.gov/career-opportunities/job-openings, The SOQ serves as a key component of the examination and hiring process and will be used to evaluate your qualifications, as well as your written communication skills. The SOQ is considered a writing sample and must clearly reflect your own knowledge, skills, abilities, and experience. While tools such as artificial intelligence (AI) (e.g., ChatGPT), internet resources, or third-party reviewers may assist with research or preparation, by submitting your application you certify that your SOQ is your original work, written in your own words, and accurately represents your background and qualifications. Failure to submit an SOQ that is your own work, including the use of AI-generated or substantially AI-assisted responses that misrepresent your abilities, may result in disqualification from the examination or hiring process. If such misrepresentation is discovered after appointment, it may constitute dishonesty and could result in adverse action, up to and including dismissal from State service.
- Describe your experience designing, building, or operating on-premises or cloud-based AI/ML infrastructure used to fine-tune, evaluate, and serve models in a production environment. Describe how you have kept sensitive data in-state or in-environment while meeting generative AI risk and data-handling requirements.
- Describe your experience serving as the accountable lead for data architecture standards on a security platform, including reviewing or approving system design specifications such as entity relationship diagrams, data models, or database/lakehouse schemas. What was your process for ensuring design consistency across a team or organization?
- Describe your experience applying AI or machine learning capabilities to a security operation or threat detection workflow (e.g., automated alert triage, anomaly detection, analyst-assist tooling). What risks or limitations did you have to account for when introducing AI into that workflow, and how did you address them.
Requirements
In addition to evaluating each candidate’s relative ability, as demonstrated by quality and breadth of experience, the following factors will provide the basis for competitively evaluating each candidate: In addition to evaluating each candidate’s relative ability, as demonstrated by quality and breadth of experience, the following factors will provide the basis for competitively evaluating each candidate:
- Experience designing or supporting large-scale security data platforms, including multi-tenant or enterprise environments
- Experience understanding of SIEM concepts, security telemetry, log management, and data correlation strategies
- Experience using query languages or search engines to analyze high-volume security data (such as proficiency in KQL, SQL, or equivalent technologies)
- Experience building or maintaining data pipelines, streaming ingestion frameworks, or ELT/ETL processes
- Experience architecting data lake or lake house environments, including schema design and optimization
- Experience applying machine learning or automation concepts within security operations workflows
- Experience planning, implementing, or supporting on-premises or cloud-based AI/ML infrastructure
- Experience integrating data from diverse security platforms such as endpoint protection, identity systems, network detection tools, or SIEM/SOAR technologies
- Ability to translate complex technical data concepts to non-technical audiences
- Experience leading technical teams or providing subject matter guidance in data architecture or security engineering
- Analytical skills, including the ability to identify patterns, detect anomalies, and evaluate data quality issues
- Experience developing or maintaining data governance frameworks, including access controls, auditing, and compliance documentation
- Ability to manage competing priorities across multiple complex projects
- Experience with scripting or programming languages commonly used for data processing (such as Python, R, or equivalent)
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Highest Paying Tech Companies for Developers
Best Paying Jobs in Technology
Top-Paying Tech Jobs (with Salaries)