Salary : $106,288.00 - $150,113.60 Annually
Location : Throughout San Bernardino County, CA
Job Type: Full-time
Job Number: 26-15026-01
Department: Innovation and Technology Department
Opening Date: 09/19/2026
Closing Date: 10/2/2026 5:00 PM Pacific
FLSA: Non-Exempt
The JobThe
Innovation and Technology Department is seeking motivated and passionate professionals for the role of
Information Security Analyst II (ISA II)The analyst will be responsible for monitoring, analyzing, and collaborating on security incidents and events to safeguard the security operations of the Countywide Information Security Program, that provides protection, governance, risk, and compliance.
The ISA II monitors, analyzes, investigates, and responds to cybersecurity events and incidents that may affect County systems, applications, networks, and information assets. The analyst will work collaboratively with experienced cybersecurity team members, County departments with diverse business and regulatory requirements, and various technology teams to identify potential threats, evaluate security concerns and issues, and support efficient and effective response including identifying appropriate mitigation and remediation activities. They will respond to, defend against, consult on, and resolve enterprise and departmental security concerns, events, issues, and incidents related to cyber, operational, and information security.
Key responsibilities may include:
- Monitoring computer networks for security issues and suspicious activities.
- Performs as an incident responder and investigates cybersecurity incidents.
- Lead response efforts in collaboration with other IT teams, vendors, and cyber intelligence partners to analyze and remediate the issue.
- May lead or coordinate cybersecurity incidents and investigations with Human Resources, County departments, outside agencies (e.g. regulatory agencies) including law enforcement.
- Educates team members; and recommends security measures including protocols, policies, and standard practice to leadership.
- May lead, facilitate, coordinate, or conduct vulnerability assessments with a proactive focus on threat intelligence and the mitigation and prevention of cyber attacks.
- Collaborate with colleagues for network security design enhancements.
- Leads the coordinating and facilitating the Countywide Security Awareness Training Program
- Leads the coordinating and facilitating the Countywide Phishing Simulation Program.
- Leads the conducting, coordinating, and facilitating cybersecurity or information security tabletop exercises.
- Reviews and coordinating contracts, procurement documents, and software or service licensing agreements to identify and assess cybersecurity, privacy, and compliance risks, and provides recommendations to ensure adherence to organizational security policies and regulatory requirements.
- Participate in on-call rotation and after-hours maintenance as needed.
For more detailed information, refer to the Information Security Analyst II job description.
EXCELLENT BENEFITSTo review job-specific benefits, refer to:
Summary of Benefitsand the
Memoranda of Understanding (MOU)CONDITIONS OF EMPLOYMENTPre-Employment Process: Applicants must successfully pass a background check and a job-related physical exam, including a drug test, prior to employment
Availability: Incumbents may occasionally work evening and weekend hours. Some overtime, on-call, or call back work may be required.
Sponsorship: Please note San Bernardino County is not able to consider candidates who will require visa sponsorship at the time of application or in the future. Candidates must be able to present their legal right to work in the United States.
Minimum Requirements Candidates must meet the Experience AND Education requirement in order to qualify.REQUIRED EXPERIENCE:Three (3) years of experience assisting with the implementation, management, and monitoring of IT security solutions and programs.
REQUIRED EDUCATION:Sixty (60) semester (90 quarter) units of completed courses from an accredited** college or university in information security, information systems, programming, computer science, software engineering, or a closely related field.
SUBSTITUTIONS:- One (1) additional year of qualifying work experience may substitute for the education requirement.
- A Bachelor's degree in information security, information systems, information technology, programming, computer science, software engineering, or a closely related field may substitute one (1) year of the required experience.
**Qualifying degrees and coursework must be conferred by institutions accredited by an accrediting body recognized by the U.S. Department of Education. Degrees earned outside the United States must be accompanied by an evaluation from a recognized credential evaluation service verifying U.S. equivalency.
Desired QualificationsThe ideal candidate will possess:
- Master's degree in information systems, information security, information technology, computer science, or a closely related field.
- Information security experience in higher education or state/local government.
- Information security related training or certifications such as CEH, CSA, or CISSP.
- Experience performing information security audits or risk assessments.
- Ability to administer network and host-based tools for penetration testing and ethical hacking products and tools.
- Knowledge of host compromise, and various techniques for malware injection and MITRE Kill Chain Framework.
- Proficiency in performing risk, business impact, control, and vulnerability assessments, and in defining treatment strategies.
- Strong analytical skills to analyze security requirements and relate them to appropriate security controls.
- Experience with cloud infrastructure and provisioning technology.
Selection ProcessExamination Procedure: There will be a
competitive evaluation of qualifications based on the information provided in the Application and the Supplemental Questionnaire. You are encouraged to include detailed descriptions of your qualifying experience and skills, as only the most highly qualified applicants will be referred to the Department.
Application Procedure: Please complete and submit the online employment application and supplemental questionnaire for consideration before
5:00 PM ST, FRIDAY, OCTOBER 2, 2026.
Resumes will not be accepted in lieu of the application and/or supplemental questionnaires.
To ensure timely and successful submission of your online application, please allow ample time to complete and submit your application before the filing deadline. Applicants will be automatically logged-out if they have not submitted the application and all required materials prior to the posted deadline. Once your application has been successfully submitted you will receive an onscreen confirmation and an email. We recommend that you save and/or print these for your records. Please note: if you do not receive an onscreen confirmation and an email acknowledging our receipt of your application, we have not received your application.
If you need technical assistance, follow this link to or contact their Toll-Free Applicant Support line at
(855) 524-5627. Please note that Human Resources is not responsible for any issues or delays caused by your internet connection, computer, or browser when submitting an application.
01
PLEASE READ THE BELOW STATEMENT
Instructions: The information provided on your application and in your responses to the following Supplemental Questionnaire will be used to determine if you meet the minimum requirements for this position, as well as in a
competitive evaluation of qualifications. It is in your best interest to be as thorough as possible in your responses. Applicants will not be able to update their application materials or answers to the questionnaire once the application has been submitted.
Failure to submit all requested information may result in disqualification or adversely affect the evaluation of your application.Note: Experience listed on this questionnaire must also be listed and fully detailed in the work experience section of your application.
- I have read and understand the above statement.
02
Education/Coursework: Please provide your completed education information. Please note, failure to provide the required education information can adversely affect the evaluation of your application.
COURSEWORK: If listing coursework, include the school name, class title, number of units, and type of units (semester/quarter). Unofficial transcripts may be attached in lieu of listing coursework. Example: CSUSB, Intro to Computer Science, 3 semester.
DEGREE: If you possess a degree from an accredited college or university, include the school name, type of degree, and major. Example: CSUSB, Bachelor of Science, Computer Science
If no education, indicate "N/A."
03
Security Operations Center Experience: Describe your experience and competency level (i.e., expert, moderate, novice, or knowledge only) assisting with the implementation, management, and monitoring and analysis of IT cybersecurity incidents and events, solutions threat intelligence analysis and investigation, penetration testing, vulnerability scanning, and use of other related computer forensic tools and programs. Ensure to include name of employer. Experience listed must be listed and fully detailed in the work experience section of your application. If none, indicate "N/A"
04
Incident Response Management Experience: Describe your experience and competency level (i.e., expert, moderate, novice, or knowledge only) assisting or leading a cyber or information security event, incident, or breach. Describe in detail at least two (2) notable cybersecurity network intrusions/incidents where you were the primary or lead individual and share your experience and approach, methodology, actions taken, preventive measures suggested/recommended, and your interaction with law enforcement (if applicable). Ensure to include name of employer, date (month and year) of the intrusion/incident, without providing any sensitive information specific to these two intrusions/incidents. If none, indicate "N/A"
05
Security Awareness Training Program and Policy Formulation Experience: Describe your experience and competency level (i.e., expert, moderate, novice, or knowledge only) establishing, supporting, and innovating your organization's security awareness training program that includes phishing simulation exercises. Specific to this program, describe in detail at least two (2) accomplishments that demonstrate cybersecurity risk was mitigated. Describe your experience by citing at least two (2) examples of your work in formulating a policy, standard, or process/procedure associated with an organization's information security program. Ensure to include the name of the employer. Experience must be listed and fully detailed in the work experience section of your application. If none, indicate "N/A"
06
Applicant Acknowledgement - Notification via email: As part of our efforts to increase efficiency and promote conservation of resources, Human Resources uses email to communicate with applicants. Therefore, all future communications regarding this recruitment, including applicant status and testing notifications, will be made via email.)
Each applicant needs their own email address. We strongly encourage you, as an applicant, to ensure that the email address you have provided with your application is current, secure and readily accessible to you. Adjust Spam and/or other filters so that our emails are accepted. Please carefully read any notices that we send you and follow any instructions provided in a timely manner. We will not be responsible in any way if you do not receive our emails (i.e., for the non-delivery of our emails or if you fail to check your e-mail on a timely basis).
- I acknowledge that I have read, understood, and agree to the above statement.
07
**ATTENTION GMAIL USERS**We have become aware of an increase in Gmail's spam filter sensitivity. Due to this change, it is possible that emails coming from San Bernardino County Human Resources may be marked as spam and will not make it into your Gmail inbox.
For your convenience, a step-by-step guide to create and apply filters within Gmail is available in the attached PDF. Once downloaded, follow the instructions so that you will