Cybersecurity Manager

The State Bar of California•San Francisco, CA
•Hybrid

About The Position

The Cybersecurity & Infrastructure Manager serves as the State Bar's lead cybersecurity manager, providing strategic leadership and hands-on technical expertise to protect the State Bar's hybrid technology environment, including its data centers in Los Angeles and San Francisco. This position leads the cybersecurity program, including security monitoring, incident response, vulnerability management, and security policy, and oversees assigned infrastructure services that support a secure and resilient technology environment. The manager leads a team of technical specialists, manages security and infrastructure vendors, and partners closely with the Infrastructure and Cloud, Applications, and end-user support teams to integrate security across operations. This role reports on cybersecurity risk and operational status to senior leadership.

Requirements

  • Bachelor’s degree in computer science, Cybersecurity, or a related field (or equivalent experience).
  • Minimum of five (5) years of experience in IT security, including three (3) years of supervisory or team-lead experience.
  • Knowledge of: Cybersecurity tools and technologies, including Next-Generation Firewalls (NGFWs), Extended Detection and Response (XDR), Endpoint Detection and Response (EDR), Web Application Firewall (WAF), and Security Information and Event Management (SIEM) systems.
  • Knowledge of: Secure system and network design principles, including Zero Trust Architecture (ZTA) and Defense in Depth.
  • Knowledge of: Cloud security frameworks and tools (e.g., Microsoft Defender for Cloud, Microsoft Sentinel, and CIS Cloud Controls).
  • Knowledge of: Encryption technologies and secure data handling practices, including data at rest, in transit, and during processing.
  • Knowledge of: Systems hardening principles and practices.
  • Knowledge of: Compliance frameworks and regulatory security and privacy standards (e.g., FedRAMP, NIST, ISO 27001, GDPR, HIPAA, PCI DSS).
  • Knowledge of: Emerging cybersecurity threats, trends, and innovations, including AI/ML implications in security and supply chain risk management.
  • Knowledge of: Incident response frameworks.
  • Knowledge of: Methods for conducting risk assessments, vulnerability assessments, penetration testing and threat intelligence.
  • Knowledge of: Security training and awareness best practices to foster a security-conscious culture.
  • Knowledge of: Effective documentation and reporting methods for policies, procedures, and incident records.
  • Knowledge of: Principles of supervision, staff development, and performance management.
  • Ability to: Oversee the implementation and management of security technologies.
  • Ability to: Oversee assigned infrastructure operations to ensure secure, reliable, and available services.
  • Ability to: Design and implement secure networks and systems, incorporating ZTA and Defense in Depth principles.
  • Ability to: Interpret and apply compliance frameworks and regulatory standards.
  • Ability to: Analyze and resolve security incidents proactively using problem-solving skills.
  • Ability to: Communicate complex security concepts to technical and non-technical audiences.
  • Ability to: Mentor and develop high-performing cybersecurity teams.
  • Ability to: Collaborate across organizational levels and external stakeholders to develop security solutions.
  • Ability to: Adapt to changing priorities while maintaining alignment with organizational goals.
  • Ability to: Present strategies and recommendations clearly and persuasively.
  • Ability to: Maintain confidentiality and professionalism in handling sensitive information.

Nice To Haves

  • Experience with IT infrastructure operations is highly desirable.
  • Professional certifications such as CISSP or equivalent are a plus but not required.

Responsibilities

  • Execute the organization's risk-based cybersecurity strategy to protect systems, data, and operations.
  • Establish, enforce, and continuously improve security policies, standards, and procedures aligned with organizational goals.
  • Serve as the hands-on technical lead for security incident response, directing triage, investigation, containment, and recovery, including log, endpoint, and network analysis and digital forensics, and coordinate vendors and partners during an event.
  • Develop, test, and maintain the incident response plan, and run tabletop and recovery exercises that prepare technical teams and leadership to respond.
  • Collaborate with internal teams and external partners to integrate security across all aspects of operations.
  • Enhance cybersecurity visibility by developing dashboards that provide actionable insights for executives and IT teams.
  • Oversee the design and implementation of secure IT architectures in collaboration with technical teams.
  • Automate security monitoring and incident response workflows using SOAR frameworks.
  • Oversee security monitoring and analytics capabilities through SIEM and threat-hunting tools.
  • Conduct risk and vulnerability assessments; implement remediation strategies.
  • Ensure compliance with applicable regulatory and industry security and privacy standards relevant to the State Bar.
  • Oversee encryption solutions and ensure timely application of security patches and updates in coordination with infrastructure teams.
  • Develop, test, and maintain an incident response plan; investigate and remediate security incidents.
  • Conduct engaging security awareness training to promote a security-first culture.
  • Research, evaluate, and implement advanced security tools and emerging technologies to enhance the organization's security posture and resilience.
  • Maintain detailed documentation of security policies, procedures, and incidents.
  • Execute cloud security strategy to support the State Bar’s Hybrid & Multi-Cloud solutions across various providers.
  • Provide actionable reports to senior management on cybersecurity risks, status, and improvement initiatives.
  • Oversee assigned infrastructure services, ensuring they are secure, reliable, and well maintained.
  • Supervise, coach, and develop technical staff, ensuring they have the tools, training, and direction needed for continuous growth.

Benefits

  • The State Bar of California’s mission is to protect the public and includes the primary functions of licensing, regulation, and discipline of attorneys; the advancement of the ethical and competent practice of law; and support of efforts for greater access to, and inclusion in, the legal system.
  • Clarity
  • Investing in Our People
  • Excellence
  • Respect
  • Growth Mindset
  • We are a diverse, equitable, and inclusive workplace where all of our employees and prospective employees experience fairness, dignity, and respect.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service