CAL-CSIRS System Administrator
PO Box 1810, Mail Stop Y-14, Rancho Cordova, CA
Full Time
PO Box 1810, Mail Stop Y-14, Rancho Cordova, CA
Full Time
1-YEAR BASE TERM, WITH POTENTIAL 1-YEAR EXTENSION. WORK WILL BE PERFORMED REMOTELY.
Mandatory Requirements
- At least seven (7) years within the last ten (10) years of professional database administrator experience and a working understanding of relational database relationships.
- At least seven (7) years within the last ten (10) years of professional experience and understanding of compound queries (inner and outer joins).
- At least seven (7) years within the last ten (10) years of professional experience and understanding of eXtensible Markup Language (XML).
- At least seven (7) years within the last ten (10) years of professional experience and understanding of Structured Query Language (SQL) Server Reporting Services (SSRS).
- At least seven (7) years within the last ten (10) years of professional experience and understanding of delimited text files.
- At least seven (7) years within the last ten (10) years of professional experience in change control and configuration management, including maintaining change management documentation.
- At least seven (7) years within the last ten (10) years of professional experience administering user accounts and assigning permissions—create, read, update, and delete (CRUD)—and role-based access control (RBAC) for a Governance, Risk and Compliance (GRC) platform supporting hundreds of users.
- At least seven (7) years within the last ten (10) years of professional experience working with Governance, Risk, and Compliance (GRC) platforms (such as CAL-CSIRS, RSA Archer, ServiceNow, or equivalent), including configuration of modules, data fields, workflows, and handlers.
- At least seven (7) years within the last ten (10) years of professional experience administering GRC modules such as Incident Management, Security Event Notification (SEN), and Risk Assessment.
- Working knowledge of IT and information security industry trends and best practices.
Desirable Requirements
- Any professional experience conducting risk assessments for an IT environment with business units to support a diverse set of infrastructure and services.
- Working knowledge of the National Institute of Standards and Technology (NIST) Standards, the NIST Cybersecurity Framework, and NIST Special Publication (SP) 800-53 and other regulatory security standards and frameworks.
- Possession of one or more of the following information technology industry certifications:
- Security Operations & Engineering (Microsoft): Microsoft Security Operations Analyst (SC-200), Azure Security Engineer Associate (AZ-500), Cybersecurity Architect Expert (SC-100), Identity and Access Administrator Associate (SC-300), Azure Administrator Associate (AZ-104), or Security, Compliance, and Identity Fundamentals (SC-900);
- Governance, Risk & Audit: CISM, CISSP, CISA, CRISC, or CGRC (Certified in Governance, Risk, and Compliance / formerly CAP);
- Cloud Security: CCSP (Certified Cloud Security Professional), AWS Certified Solutions Architect, or AWS Certified Security – Specialty;
- SOC / Blue-Team / Incident Response: Any GIAC certification (e.g., GSEC, GCIH, GCDA, GMON, or GCFA), CompTIA Security+, or CompTIA CySA+.
- SIEM / SOAR Platforms: Splunk certifications (e.g., Core Certified Power user or Enterprise Security Certified Admin), or Palo Alto Networks Certified XSIAM Engineer;
- Project & Agile Delivery: PMP, PMI-ACP, or SAFe Scrum Master (SSM).
- Ten (10) years within the last fifteen (15) years of experience supporting statewide cybersecurity operations and modernization initiatives within a California State agency.
- Ten (10) years within the last fifteen (15) years of experience with Agile/Scrum delivery and tools such as Azure DevOps (ADO).
- Demonstrated leadership experience establishing and leading technical teams and overseeing the delivery of multiple (two or more) enterprise identity and access management (IAM) and cybersecurity initiatives from concept through implementation and ongoing operations, including at least one initiative incorporating AI/automation or other emerging technologies. Experience should include cross-functional stakeholder coordination and full-lifecycle delivery at an enterprise or public-sector scale.
- Depth operating a Microsoft-native SOC at scale – Sentinel + Defender XDR in a multi-tenant / MSSIP or enterprise environment.
- AI/GenAI applied to security operations SOC automation, detection engineering, or LLM triage.
- Zero Trust and identity governance (IGA) delivery Entra ID Governance, SailPoint, or Saviynt implementations.
- Security automation / SOAR playbook development (Azure Logic Apps, XSIAM, Splunk, SOAR).
- Public-sector compliance depth StateRAMP/FedRAMP, CJIS, or California SAM/SIMM 5300 experience.
- Knowledge transfer / mentoring of State staff.
Applications that do not complete the Prescreen Survey will not be considered.
Anvaya Solutions, Inc. is an equal opportunity employer. All employment decisions, including hiring, promotions, and compensation, are made without regard to race, color, religion, sex, national origin, or any other protected characteristic. We are committed to a merit-based workplace where every individual is treated with respect and has equal access to opportunities based solely on their qualifications and performance.
Loading Job Application......
If you have questions, please contact careers@anvayasolutions.com