careers

IT Security Operations Lead

Apply now Job no: 561982
Work type: Staff
Location: Chancellor's Office
Categories: Unit 9 - CSUEU - Technical Support Services, Administrative, Probationary, Full Time

Chancellor's Office Statement

Join our team at the California State University, Office of the Chancellor, and make a difference in providing access to higher education. We are currently seeking experienced candidates for the position of IT Security Operations Lead. The CSU Chancellor's Office, located on the waterfront adjacent to the Aquarium of the Pacific in downtown Long Beach, is the headquarters for the nation's largest and most diverse system of higher education. The CSU Chancellor's Office offers a premium benefit package that includes outstanding health, and dental plans; a fee waiver education program; membership in the California Public Employees Retirement System (PERS); and 15 paid holidays a year.

Salary

The anticipated salary hiring range is up to $127,332 per year, commensurate with qualifications and experience.

Work Arrangements

Flexibility to telecommute two days a week, with three days on-site at the main headquarters in Long Beach, California.

Premium Benefits

Comprehensive Health, Dental, and Vision Benefits

15 paid holidays a year

Tuition waiver education program (also applies to eligible family members)

Membership in the California Public Employees Retirement System (PERS)

More details here: Comprehensive Benefits Package

Classification

Information Security Analyst III

Compensation Notice

CSU Classification Salary Range: $87,408 - $127,332 per year (Step 1 - Step 20); Step placement will be determined based on relevant qualifications and professional experience. Step placement upon appointment is not expected to exceed Step 20 ($127,332 per year). Future increases, including step advancement, are subject to contract negotiations.

Position Information

The California State University, Office of the Chancellor, is seeking an IT Security Operations Lead to lead operational coordination of security operations capability supporting the 22 CSU campuses and the Chancellor’s Office, ensuring services meet defined expectations for quality, consistency, and responsiveness. The role operates in a federated environment where campuses maintain responsibility for local systems and operations and focuses on coordinating and aligning incident response activities across vendors and campus teams. This position leads systemwide incident coordination for high-criticality and multi-campus events while maintaining operational readiness through established workflows, escalation procedures, and continuous improvement of response practices, with the goal of enabling effective, timely response and reducing the frequency and impact of systemwide security incidents.

Responsibilities

Under the general direction of the Cyber Fusion Center Director, the IT Security Operations Lead will:

-Monitor and evaluate day-to-day vendor-delivered security operations, ensuring services meet expectations for alert handling, investigation quality, escalation, responsiveness, and consistency.

-Apply and refine incident severity criteria and escalation thresholds based on operational experience, improving the consistency of incident classification and response.

-Review vendor SOC performance and service quality, identify gaps or recurring issues, and work with the vendor and CSU stakeholders to address them.

-Serve as incident commander for high-criticality and multi-campus security incidents, leading response across vendor SOC teams, campus security personnel, and other stakeholders to support timely investigation, containment, communication, recovery, and escalation.

-Develop and maintain incident response playbooks, escalation procedures, and coordination workflows used by vendor and campus teams.

-Facilitate post-incident reviews for significant security events, identify operational and coordination gaps, and ensure agreed improvements are incorporated into processes, playbooks, or vendor operating practices.

-Support the development and use of operational metrics, reporting, and service-performance information to assess SOC effectiveness and inform CFC priorities and improvements.

-Identify and escalate risks related to incident response, coordination, and operational readiness.

-Perform additional operational and coordination duties as assigned to support evolving Cyber Fusion Center (CFC) priorities and systemwide security operations.

Qualifications

This position requires:

-Bachelor’s degree in computer science, information security, or a related field (or equivalent combination of education and experience).

-Five (5) or more years of progressively responsible experience in security operations, incident response, or closely related cybersecurity work, including at least two (2) years in a senior, lead, or equivalent role.

-Demonstrated experience leading high-severity cybersecurity incidents, including setting response priorities, coordinating technical and operational teams, and driving response actions and escalation.

-Substantive experience in Security Operations Center (SOC) operations, including detection, alert triage, investigation, escalation, incident response, and operational handoffs.

-Experience working in complex or distributed environments with multiple stakeholders (e.g., multi-entity, federated, or enterprise environments).

-Strong working knowledge of security monitoring and incident response technologies and practices, including SIEM, endpoint detection and response, alert investigation, and incident management workflows.

-Experience monitoring and evaluating a SOC, managed detection and response service, or other vendor-delivered security operation, including evaluating investigation quality, escalations, service performance, and adherence to established processes.

-Experience establishing, maintaining, or improving incident response processes, including playbooks, escalation paths, and coordination workflows.

-Strong communication and interpersonal skills, with the ability to work effectively across technical teams, leadership, and external partners.

-Ability to operate effectively in high-pressure situations and make sound decisions with incomplete information.

-Ability to work collaboratively across multiple organizations and influence outcomes without direct authority.

Preferred Qualifications

-Relevant security certifications such as CISSP, CISM, or GIAC.

-Experience in higher education or similarly distributed organizations.

-Experience serving as an incident commander, incident lead, SOC lead, or equivalent during significant cybersecurity incidents.

-Experience supporting security operations across a large, federated, or multi-entity organization.

Application Period

Priority consideration will be given to candidates who apply by October 20, 2026. Applications will be accepted until the job posting is removed.

How To Apply

Please click "Apply Now" to complete the California State University, Chancellor's Office online employment application.

Equal Employment Opportunity

Consistent with California law and federal civil rights laws, the CSU provides equal opportunity in education and employment without unlawful discrimination or preferential treatment based on race, sex, color, ethnicity, or national origin. Reasonable accommodations will be provided for qualified applicants with disabilities who self-disclose by contacting the Senior Human Resources Manager at (562) 951-4070.

Title IX

Please view the Notice of Non-Discrimination on the Basis of Gender or Sex and Contact Information for Title IX Coordinator at: https://www2.calstate.edu/titleix

E-Verify

This position requires new hire employment verification to be processed through the E-Verify program administered by the Department of Homeland Security, U.S. Citizenship and Immigration Services (DHSUSCIS) in partnership with the Social Security Administration (SSA).

If hired, you will be required to furnish proof that you are legally authorized to work in the United States. The CSU Chancellor’s Office is not a sponsoring agency for staff and Management positions (i.e., H1-B VISAS).

COVID19 Vaccination Policy

Per the CSU COVID-19 Vaccination Policy, it is strongly recommended that all Chancellor’s Office employees who are accessing office and campus facilities follow COVID-19 vaccine recommendations adopted by the U.S. Centers for Disease Control and Prevention (CDC) and the California Department of Public Health (CDPH) applicable to their age, medical condition, and other relevant indications.

CSU Out of State Employment Policy

California State University, Office of the Chancellor, as part of the CSU system, is a State of California Employer. As such, the University requires all employees upon date of hire to reside in the State of California. As of January 1, 2022, the CSU Out-of-State Employment Policy prohibits the hiring of employees to perform CSU-related work outside the state of California.

Background

The Chancellor's Office policy requires that the selected candidate successfully complete a full background check (including a criminal records check) prior to assuming this position.

Learn more about working at the California State University and the impact of our mission.

Advertised: Pacific Daylight Time
Applications close:

Back to search results Apply now Refer a friend

Search Results: 0