> Markdown version of [/jobs/ext/2946374-information-technology-specialist-ii](https://www.wearedevelopers.com/jobs/ext/2946374-information-technology-specialist-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # INFORMATION TECHNOLOGY SPECIALIST II - **Company:** California Department of Tax & Fee Administration - **Location:** Sacramento, CA, United States (Remote available) - **Salary:** $103,500.0 - $138,684.0 - **Contract:** Permanent contract - **Skills:** Software Applications, Cyber Security, Information Systems, Data Security, Information Management, Internet Security, Information Systems Security Architecture Professional, Network Architecture, Single In-Line Memory Module (SIMM), Software Engineering, Virtual Machines, Software Vulnerability Management, Privacy Controls, Information Technology, Tenable Nessus, Nessus, Plan of Action and Milestones - **Published:** September 16, 2026 - **Apply:** https://www.careerbuilder.com/job-details/information-technology-specialist-ii-sacramento-ca--1d2422fb-bc83-4226-8117-19adf78209e7 ## About the Role Individuals who are currently in the classification, eligible for lateral transfer, eligible for reinstatement, have list or LEAP eligibility, are in the process of obtaining list eligibility, or have SROA and/or Surplus eligibility (please attach your letter, if available). SROA and Surplus candidates are given priority; therefore, individuals with other eligibility may be considered in the event no SROA or Surplus candidates apply. Individuals who are eligible for a Training and Development assignment may also be considered for this position(s)., In addition to evaluating each candidate's relative ability, as demonstrated by quality and breadth of experience, the following factors will provide the basis for competitively evaluating each candidate: * Knowledge managing and leading an enterprise risk register, conducting technical risk assessments and tracking remediation of risks via a Plan of Action and Milestones (POAM). * Experience performing System Security Plans (SSPs), Privacy Threshold Assessments (PTAs) and Privacy Impact Assessments (PIAs). * Experience with managing or leading an enterprise privacy program. * Strong foundational knowledge of network architecture, system administration, software development and secure system and application design. * Extensive knowledge of Information Security Policies, Standards, Procedures and Guidelines. * Experience with cyber security tools and IT administration tools. * Experience and working knowledge with National Institute of Standards and Technology (NIST), IRS Publication 1075, State Administrative Manual (SAM), and the Statewide Information Management Manual (SIMM). * Experience managing and leading large Information Technology (IT) projects. * Ability to analyze issues, define opportunities, and recommend effective solutions. * Ability to develop and maintain strong working relationships, and deliver excellent customer service. * Ability to work collaboratively with multi-disciplined work groups. * Ability to multi-task and work under pressure. * Outstanding written skills for preparing reports and briefings for audience at all levels of organization. * Outstanding analytical and problem-solving abilities, prioritization and time management skills. * Experience leading, mentoring and developing a team while fostering a culture of accountability and continuous improvement. * Ability to align technical, governance and compliance initiatives with organizational goals and drive continuous improvement and program maturity. * Certified Information Systems Security Professional (CISSP), CRISC (Certified in Risk and Information Systems Control) and Certified Information Security Manager (CISM) certifications are a plus. * Experience in managing a vulnerability management program and prioritizing remediation based on risk. * Experience in utilizing vulnerability management platforms such as Rapid7 Insight VM and Tenable Nessus. * Experience managing and leading incident response activities related to security and privacy incidents., Accounting, Administrator Documentation, Analysis Skills, Budgeting, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, California Public Employees Retirement System (CalPERS), Career Development, Computer Security, Continuous Improvement, Cross-Functional, Customer Support/Service, Diversity, Establish Priorities, Federal Government, ISO (International Organization for Standardization), Incident Response, Information Systems/Technology IS/IT Administration, Information Technology & Information Systems, Information/Data Security (InfoSec), Internet Security, Leadership, Maintain Compliance, Management of Information Systems/Technology (MIS), Mentoring, Multitasking, Nessus, Network Architecture/Engineering, Office Equipment, PC (Personal Computer) Systems, Privacy Controls, Privacy Impact Assessment (PIA), Problem Solving Skills, Process Improvement, Public Transport, Publications, Reporting Skills, Risk, Risk Analysis, Risk Management, Sales Tax, Software Design, Software Development, Staff Development, State Tax, Systems Administration/Management, Team Player, Technical Leadership, Time Management, Training/Teaching, U.S. National Institute of Standards and Technology (NIST), Use Tax, Virtual Machine (VM), Writing Skills ## Description Are you interested in making life better for Californians? Are you looking for a career and not just a job? Do you want to create a meaningful impact in your community? If you answered yes to any of these questions, then the California Department of Tax and Fee Administration (CDTFA) has a career opportunity waiting for you! California not only needs you, it wants you as part of the growing workforce. New employees, new ideas, and new creative perspectives are needed in all areas at the CDTFA. We value staff and are dedicated to employee career development. Our agency supports the development of staff by offering training to flourish in their position and programs to promote and explore upward mobility. To learn more about us, please see CDTFA Gateway to New Opportunities video Under direction of the Deputy Chief Information Security & Privacy officer (IT Manager I), the Information Technology Specialist II (IT Spec II) serves as the lead of the Security Governance and Assurance Team (SGA) in the Information Security Office (ISO). The IT Specialist II leads efforts to establish and maintain a consistent and efficient risk management program, privacy program and a vulnerability management program while ensuring alignment and compliance with statewide and federal requirements and integration of risk-based decision-making across IT and business units. How did you hear about this opportunity? Tell us in this brief survey. Here is the link to the Information Technology Specialist II examination bulletin. Here is the link to the Information Technology Specialist II (LEAP) examination bulletin. Under Government Code 14200, this position may be eligible for partial telework for eligible candidates residing in California. All telework/hybrid schedules require staff to report to the office a minimum number of days per week. Schedules are subject to change. Currently, per the California Budget Act of 2025, all California Department of Tax and Fee Administration salaries are subject to the provisions of the State of California's Personal Leave Program., The following items are required to be submitted with your application. Applicants who do not submit the required items timely may not be considered for this job: * Current version of the State Examination/Employment Application STD Form 678 (when not applying electronically), or the Electronic State Employment Application through your Applicant Account at www.CalCareers.ca.gov. All Experience and Education relating to the Minimum Qualifications listed on the Classification Specification should be included to demonstrate how you meet the Minimum Qualifications for the position. * Resume is required and must be included. * Other - A completed Supplemental Questionnaire (SQ) must be submitted with your STD. 678 in order to be considered for this position. Please see the Supplemental Questionnaire Requirement section of this job posting for additional information. Applicants requiring reasonable accommodations for the hiring interview process must request the necessary accommodations if scheduled for a hiring interview. The request should be made at the time of contact to schedule the interview. Questions regarding reasonable accommodations may be directed to the EEO contact listed on this job posting., Applicants must include a Supplemental Questionnaire (SQ) for this recruitment. Applications without an SQ or include an SQ that does not directly answer all the items below will not be considered. Resumes do not take the place of the SQ. SQ Requirements: * Name on SQ. * Job Control number on SQ. * SQ must be no more than two pages in length, double-spaced. Respond directly to the following SQ question(s): Describe how you addressed a security concern within an organization or enterprise. * What steps, tools, processes or frameworks did you use? * How did you get approval from management or system owners to fix the issue and what was the outcome? You must provide specific information in your response(s) which demonstrates how your knowledge, skills, and training meet the needs of this position. Additional Instructions for Applicants Using the online application system as specified in the announcement is the preferred method of applying for civil service job opportunities; however, applicants may instead apply by way of U.S. mail, parcel delivery or courier service, or in person, as set forth in this announcement. Paper applications must include a signature. Dates printed on envelopes by mobile barcodes or equivalent mobile print technology are not acceptable proof of the date the application and any other required documents or materials were filed. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Web-based Information Visualization](https://www.wearedevelopers.com/videos/84-web-based-information-visualization) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)