Security Manager - Security Architecture & Data Protection

California Statewide Automated Welfare System
Gold River, CA, United States
15 days ago
Apply on careersingovernment.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$116,209.0 - $184,500.0
Working hours
Regular working hours

Tech stack

Amazon Web Services User Authentication Cloud Computing Security Cyber Security Information Systems Data Discovery Data Security Java Persistence API Network Security Role-Based Access Control Software Engineering Data Streaming
+4 more
Software Vulnerability Management Enterprise Data Management Data Logging Information Technology

Job description

We’re looking for an experienced Security Manager- Security Architecture & Data Protection to shift security left and shape how security is designed across applications, cloud, integrations, and data. Do you have the technical expertise to evaluate cloud architecture, application designs, integrations, data flows, and emerging technologies while translating complex security risks into practical recommendations? Are you ready to help CalSAWS strengthen enterprise security and protect sensitive data across one of the nation’s largest public-sector technology environments?, The Security Manager - Security Architecture & Data Protection reports to the Chief Information Security Officer (CISO) and plays a critical role in strengthening the CalSAWS enterprise security program by ensuring security is incorporated into technology, applications, data, and business processes from the start.

This position leads security architecture reviews for new and changing technologies, evaluates security risks and design decisions, and establishes effective controls to protect sensitive information. The Security Manager partners closely with innovation, application, infrastructure, security, and business teams to advance secure-by-design practices and strengthen CalSAWS’ enterprise data protection capabilities.

Requirements

  • Be an experienced security professional who can operate comfortably at both the architectural and enterprise governance levels.
  • Have hands-on experience conducting security architecture and design reviews for complex enterprise systems.
  • Be comfortable reviewing cloud architecture, challenging application designs, evaluating identity and integration patterns, and discussing data flows with engineers.
  • Bring strong expertise in enterprise data protection, including DSPM, DLP, Insider Risk, data discovery, and classification.
  • Possess a strong understanding of authentication and authorization, encryption, key and secret management, network security, least privilege, logging and monitoring, vulnerability management, and secure software development.
  • Understand privacy-by-design principles, including data minimization, appropriate use, retention, transparency, and sharing constraints.
  • Effectively translate complex security risks and technical findings into clear, practical recommendations for leadership and business partners.
  • Demonstrate strong judgment when balancing security requirements with operational, technical, and delivery considerations.
  • Be highly organized and capable of managing multiple concurrent reviews, requests, risks, and stakeholder relationships.
  • Communicate clearly and concisely through decision logs, technical summaries, recommendations, and audit- or client-ready documentation.
  • Thrive in a collaborative environment requiring partnership across security, technology, procurement, compliance, and business teams.
  • Be motivated by creating a culture in which security and data protection are incorporated into technology decisions from the start.

Preferred certifications may include:

  • CISSP, CISM, CRISC, CCSP, CDPSE, CIPM, or equivalent security certifications
  • GIAC certifications
  • Security+ or equivalent
  • Cloud security certifications
  • AWS Security Architect or equivalent

All positions may be subject to some short-term travel in order to conduct project business with the state and counties. The CalSAWS project office is currently located in Gold River, California., * Graduation from an accredited college with a bachelor’s degree in information security, computer science, information systems, cybersecurity, or a related field. A master’s degree is preferred.

  • Six (6) years of progressively responsible, full-time, paid experience in security architecture, information security, data protection, privacy, data security, or a similar operational role, with demonstrated depth in DSPM, DLP, and Insider Risk disciplines in a multi-cloud environment. At least two (2) years of experience must have been in a supervisory capacity.

Candidates should also demonstrate:

  • Hands-on experience performing security architecture and design reviews for complex enterprise systems
  • Experience with data protection-by-design, AI/ML systems, input/output monitoring, data residency enforcement, and access controls
  • Strong knowledge of authentication and authorization controls, encryption, key management, secret management, network security, classification, retention, least privilege, logging and monitoring, vulnerability management, and secure software development
  • Working knowledge of privacy-by-design principles
  • Working knowledge of data security and security architecture reviews
  • Experience supporting vendor onboarding, system and security reviews, procurement/third-party risk management processes, and data inventories
  • Experience managing structured workflows involving intake, triage, documentation tracking, and closure across multiple stakeholders

Experience working in large-scale enterprise or public-sector environments is strongly preferred.

Benefits & conditions

SALARY: $9,684.12 - $15,375.00 monthly depending on experience.

About the company

The California Statewide Automated Welfare System (CalSAWS) is the largest county-based human services system in the nation. In June 2019, all 58 California counties formed the CalSAWS Consortium as a Joint Powers Authority (JPA) to govern system operations and represent the collective interests of every county.

As of October 2023, CalSAWS successfully unified all counties into a single statewide system. CalSAWS is now in its Maintenance and Operations (M&O) phase, ensuring reliable, secure, and efficient system functionality for millions of Californians.

This role represents a critical opportunity to improve enterprise alignment upstream of delivery, helping CalSAWS reduce downstream friction, improve coordination, and support more cohesive customer and workforce experiences statewide., Regional Government Services Authority (RGS) is a Joint Powers Authority (JPA) serving the needs of cities, counties, special districts, joint powers authorities, and other governmental entities since 2002. RGS works exclusively for the benefit of public agencies, providing a ready source of support and consulting services to meet the needs of its partner agencies in a broad range of disciplines and to help local governments meet three challenges:

  1. Decreasing revenues
  2. Increasing demands (and costs) for services, and
  3. Loss of experienced staff.

Local government leaders knew that these challenges were likely to continue, so agencies would have to work together - uniting not only their voices but their resources to advocate and become more efficient. The idea behind the creation of RGS was to form an agency that would help local governments share expertise and improve efficiencies. This was an emerging need. It did not require that each agency hire full-time staff. With the creation of this JPA, agencies could, in effect, share expertise through a third-party., Today, RGS is governed by several member agencies, all with the common goal expressed in the JPA’s MISSION STATEMENT: To provide quality, innovative, cost-effective services exclusively to public agencies. In November 2020, the 5-year Strategic Plan was adopted. Current member agency representation can be found on the Board of Directors page of this website.

RGS developed a highly flexible platform of administrative support, benefit plans and programs that could serve the diverse needs of cities, special districts, counties and other joint powers authorities. Flexibility was vital because the needs of partner agencies varied and because RGS services were 100 percent fee-based. Thus, RGS costs have always been able to ramp up or down quickly, as demand changed.

To further understand RGS main service lines, please see the RGS Services Brochure or the Services area of the website.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on careersingovernment.com
Prepare application

Good distractions

Loading talks and stories from around this role…