IT Lead Security Engineer (Lead Infrastructure Security Engineer)
This position may be eligible for a telework opportunity in accordance with departmental policies and operational needs. Employees are currently required to work in-person at least four (4) days per week in alignment with Executive Order N-22-25. Additional in-office days may be required based on operational needs. The office is located at 1810 16th Street, Sacramento.
All employees (including OPT students) must provide valid work authorization per Form I-9. CalHR is not an E-Verified employer.
Why join CalHR?
The California Department of Human Resources (CalHR) was named a 2026 Gallup Exceptional Workplace Award winner for strengths development, a national recognition of organizations that build cultures helping people do their best work. This honor reflects our department-wide investment in a strengths-based workplace that supports growth, leadership, and a stronger employee experience. Join CalHR to work in an environment that prioritizes professional development and public service.
The California Department of Human Resources (CalHR) is the pillar of human resources management for all state employees. Our success is made possible by the hard work of more than 400 CalHR team members who serve as trusted advisors to our strategic partners and the public. If you are interested in providing exceptional human resource services and guidance, CalHR is the place for you. By joining our team, you’ll have the opportunity to make a meaningful impact while working alongside passionate professionals.
About the role
Under the general direction of the Information Technology Manager I, Department of Human Resources (CalHR), Infrastructure Unit, the Information Technology Specialist II serves as a senior technical resource responsible for designing, implementing, securing, and maintaining enterprise infrastructure supporting CalHR's business operations. The incumbent provides advanced technical expertise across cloud environments, servers, storage, networking, directory services, and infrastructure security.
Responsibilities
- Design, implement, secure, and maintain enterprise infrastructure across hybrid environments (e.g., Windows Server, Linux, VMware, and Microsoft Azure).
- Manage enterprise storage solutions alongside core server applications (e.g., Active Directory, IIS, Citrix XenApp, or Exchange).
- Configure, secure, and maintain enterprise network infrastructure (e.g., Palo Alto Firewalls, Cisco switching, wireless controllers, or Network Access Control/Forescout).
- Provide technical leadership and mentorship to junior systems engineers and technical staff.
- Develop advanced automation scripts (e.g., PowerShell, Bash, or Infrastructure as Code) to streamline deployments, patching, and security audits.
- Resolve complex, high-priority technical issues under pressure using analytical and problem-solving skills.
- Serve as a technical lead, steering complex IT projects and establishing technical standards.
Requirements
- Hands-on experience designing, implementing, and hardening complex server infrastructure across hybrid environments.
- Technical expertise in managing enterprise storage solutions and core server applications.
- Experience configuring, securing, and maintaining enterprise network infrastructure.
- Valid work authorization per Form I-9.
Qualifications
- Cloud Security Expertise: Advanced, hands-on experience designing, securing, and managing Microsoft Azure environments, with specific expertise in Cloud Security Posture Management (CSPM), Microsoft Defender for Cloud, Microsoft Sentinel, and Identity and Access Management (IAM/Entra ID).
- Enterprise Infrastructure & Operating Systems: Deep technical knowledge and experience configuring, hardening, and maintaining enterprise-level Windows Server (2016+), Linux, and VMware virtualization environments.
- Network & Perimeter Security: Proficiency with configuring, optimizing, and troubleshooting Palo Alto Firewalls, Cisco switches, and Network Access Control (NAC) systems like ForeScout.
- Storage Area Networks (SAN): Experience engineering and managing enterprise storage arrays, optimizing Fibre Channel protocols, and implementing storage encryption and data retention policies.
- Automation & Orchestration: Strong experience developing advanced automation scripts (e.g., PowerShell, Bash, or Infrastructure as Code).
- Analytical & Problem-Solving Skills: Excellent analytical, critical thinking, and troubleshooting skills.
- Professional Dependability & Communication: Exceptional written and verbal communication skills, a strong sense of accountability, and the ability to build collaborative relationships with teammates, stakeholders, and control agencies.
- Lead & Mentorship Experience: Demonstrated experience serving as a technical lead and mentoring junior systems engineers and technical staff.
- Industry Certifications (Highly Desired):
- Certified Information Systems Security Professional (CISSP)
- Certified Cloud Security Professional (CCSP)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Palo Alto Networks Certified Network Security Engineer (PCNSE)
Special Requirements
All interested applicants are required to submit a Statement of Qualifications (SOQ). Please provide direct responses to each of the numbered items listed below. Applicants must number and include the full text of the SOQ items in their response. Please include specific examples of your education, training, and/or experience. SOQs should be limited to a maximum of two (2) pages, single-spaced, twelve-point Arial font.
- Describe your hands-on experience designing, implementing, and hardening complex server infrastructure across hybrid environments (e.g., Windows Server, Linux, VMware, and Microsoft Azure).
- Please detail your technical expertise in managing enterprise storage solutions alongside core server applications (e.g., Active Directory, IIS, Citrix XenApp, or Exchange).
- Describe your experience configuring, securing, and maintaining enterprise network infrastructure (e.g., Palo Alto Firewalls, Cisco switching, wireless controllers, or Network Access Control/Forescout). Additionally, share how you provide technical leadership and mentorship.
Note: Applicants who do not follow these instructions may be disqualified from the selection process. Cover letters and resumes do not take the place of the SOQ.
Pay
$8,881.00 - $11,905.00 per month. New to State candidates will be hired into the minimum salary of the classification or minimum of alternate range when applicable.