INFORMATION TECHNOLOGY SPECIALIST II

CA High Speed Rail Authority
Vineyard, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 139K

Job location

Remote
Vineyard, United States of America

Tech stack

Microsoft Active Directory
Artificial Intelligence
Amazon Web Services (AWS)
Application Firewall
Azure
Bash
Cloud Computing
Cloud Computing Security
Configuration Management
Software Documentation
CompTIA Security+
Computer Security
Computer Networks
Databases
Linux
Information Security Management
IT Management
Intrusion Detection and Prevention
Information Systems Security Architecture Professional
Python
Microsoft Security Essentials
Windows Server
Powershell
Security Information and Event Management
Single In-Line Memory Module (SIMM)
Network Routers
Office365
Firewalls (Computer Science)
Web Content
Information Technology
CIS Benchmarks
Network Server
GPT
Qualys
Vulnerability Analysis

Job description

Under the general direction of the Security Operations Manager, an Information Technology (IT) Manager I of the California High-Speed Rail Authority (Authority), the IT Specialist II (Information Security Specialist) serves as a lead for the Enterprise Governance, Risk, and Compliance (GRC) section. The incumbent works independently and collaboratively to plan, implement, maintain, and oversee the Authority's enterprise-wide GRC activities, with a strong focus on identifying, assessing, and managing information security risks. As a technical specialist within the Authority's Information Security Program, the incumbent provides leadership in the development, documentation, and maintenance of information security policies, standards, and procedures; ensures effective configuration management practices; and coordinates enterprise reporting on governance, risk posture, privacy, and compliance performance. The incumbent leads efforts to establish and maintain a consistent, repeatable risk management framework; ensures alignment with statewide and federal requirements; and drives integration of risk-based decision-making across IT and business units. Through expert-level guidance and oversight of risk identification, evaluation, mitigation, and monitoring activities, the incumbent strengthens the Authority's security governance and elevates organizational risk awareness and accountability. These efforts enhance the Authority's ability to manage enterprise security risk effectively and support the protection of critical assets in alignment with mission objectives. You will find additional information about the job in the Duty Statement., New to State candidates will be hired into the minimum salary of the classification or minimum of alternate range when applicable. # of Positions: 1 Work Location: Sacramento County Telework: Hybrid Job Type: Permanent, Full Time Department Information Are you looking for a different type of state government job? Something with a little more excitement and a more fast-paced and fluid environment? How about an opportunity to be part of one of the most remarkable transportation projects in California's history? The California High-Speed Rail Authority is a small and dynamic state agency that is looking for employees who are interested in a challenging and rewarding job opportunity. Please let us know how you heard about our position by taking this brief survey. Completing this survey is not required to be considered for this vacancy. https://www.surveymonkey.com/r/HCM6SCC Department Website: https://hsr.ca.gov/jobs/ Special Requirements A Statement of Qualifications (SOQ) is required for this position. The SOQ must be no more than three (3) pages, single-spaced, with one-inch margins, in 12-point font, organized and numbered as reflected below. The SOQ must discuss the applicant's applicable experience as it pertains to each item below. Applicants who do not follow these requirements may be disqualified from the hiring process. A resume is required but does not take the place of the SOQ. Letters and other materials will not be considered in the place of the SOQ. You must respond to all the following items:

  1. Describe your experience drafting and maintaining IT or information security documents, such as policies, procedures, configuration guides, or security baselines. Provide specific examples.
  2. Explain your familiarity with information security policies, standards, and frameworks such as SAM, SIMM, NIST SP 800-53/171, CIS Benchmarks, DISA, STIGs and how you have applied them in practice.
  3. Provide an example of when you assisted with or prepared documentation for an audit, assessment, or compliance review. Explain your role and how your work contributed to the outcome.
  4. Describe how you have communicated complex technical information to non-technical staff or stakeholders. What strategies did you use to ensure clarity and adoption?
  5. Describe your experience conducting risk assessments and developing risk treatment plans. Include examples that demonstrate how you identified, analyzed, prioritized, or mitigated risks. NOTE: Artificial intelligence (AI) tools such as ChatGPT, website searches, and third-party reviewers can be helpful in researching responses to the SOQ; however, by submitting your application for this position, you understand and acknowledge the SOQ you submit is your own work, in your own words, and accurately reflects your knowledge, skills, abilities, and experiences. Submitting an SOQ that is not your own may be cause for disqualification from the hiring process. Application Instructions Completed applications and all required documents must be received or postmarked by the Final Filing Date in order to be considered. Dates printed on Mobile Bar Codes, such as the Quick Response (QR) Codes available at the USPS, are not considered Postmark dates for the purpose of determining timely filing of an application. Final Filing Date: 8/11/2026 Who May Apply Individuals who are currently in the classification, eligible for lateral transfer, eligible for reinstatement, have list or LEAP eligibility, are in the process of obtaining list eligibility, or have SROA and/or Surplus eligibility (please attach your letter, if available). SROA and Surplus candidates are given priority; therefore, individuals with other eligibility may be considered in the event no SROA or Surplus candidates apply.

Requirements

Part-time telework is available for this position for California residents based on the requirements of the position and may be discussed during the interview process. Hiring interviews may be available virtually, using teleconferencing or video conferencing options. While working on-site, the incumbent works in a professional office environment, in a climate-controlled area which may fluctuate in temperature and is under artificial light. The incumbent will be required to use a computer, mouse, and keyboard, and will be required to sit for long periods of time at a computer screen. The incumbent must be able to focus for long periods of time, multi-task, adapt to changes in priorities, and complete tasks or projects with short notice. The incumbent must develop and maintain cooperative working relationships and display professionalism and respect for others in all contact opportunities., In addition to evaluating each candidate's relative ability, as demonstrated by quality and breadth of experience, the following factors will provide the basis for competitively evaluating each candidate:

  • Associate or bachelor's degree in an IT-related field of study.
  • 5 years of related experience in information security or an equivalent combination of education and experience.
  • Possession of one or more of the following active certifications is desirable:
  • CompTIA Security+
  • CompTIA Cybersecurity Analyst+ (CySA+)
  • Certified Cloud Security Professional (CCSP)
  • Certified Information Security Auditor (CISA)
  • Certified Information Systems Security Professional (CISSP)
  • GIAC Continuous Monitoring Certification (GMON)
  • Microsoft Security Operations Analyst
  • AWS/Azure Security Engineer Associate
  • Strong technical writing skills with the ability to produce security baselines, configuration guides, system documentation, and reports.
  • Experience with system hardening and compliance frameworks such as CIS Benchmarks, DISA, STIGs, and NIST SP 800-53/171.
  • Familiarity with enterprise IT environments including Windows Server, Linux, Active Directory, databases, and cloud platforms (Azure, AWS, M365).
  • Hands-on experience working with IT infrastructure including routers, witches, servers, databases, and endpoint management.
  • Hands-on experience with information security tools such as Security Information and Event Management (SIEM), vulnerability scanners (e.g., Tenable, Qualys), EDR platforms, and log management solutions.
  • Knowledge of security devices such as network firewalls, web application firewalls, web content filters, and intrusion prevention/detection systems.
  • Knowledge of networking concepts and practices.
  • Knowledge of cybersecurity frameworks, governance risk assessments and compliance in the IT field.
  • Ability to analyze documents to provide feedback and inform management of appropriate information.
  • Understanding of scripting or automation (e.g., PowerShell, Python, or Bash) to assist with policy enforcement and evidence gathering.
  • Experience authoring security policies, procedures, and other reference materials.
  • Ability to adapt quickly to new tools, platforms, and security frameworks as technology and compliance requirements evolve.
  • Ability to establish and maintain cooperative working relationships with all levels of staff and management; communicate effectively with peers, other technical teams, external partners, vendors, and others.
  • Ability to manage multiple-high priority initiatives in a fast-paced achievement-oriented environment and work under pressure to meet deadlines.
  • Ability to maintain confidentiality of sensitive tasks, assignments, and information.
  • Willingness to work excess hours to achieve business results.
  • Display enthusiasm for continous learning.

Benefits & conditions

Pulled from the full job description

  • Health insurance
  • Vision insurance
  • Dental insurance, The State of California offers a comprehensive benefits package that includes health, vision, dental, a retirement pension, a telework stipend if applicable, and an array of other options.

Apply for this position