City and County of San Francisco · San Francisco, CA

Technology Engineer – Senior (1043) - Security Specialty - Citywide (C00096) — San Francisco, CA

Full-timeSan Francisco, CAPosted 2026-07-06Apply on SmartRecruiters

Full job description

Under general direction, analyzes, plans, designs, implements, maintains, troubleshoots and enhances technology. Serves as the senior technical contributor for systems or platforms.

The 1043 Senior Technology Engineer is the advanced journey level in the Engineer series. The class is distinguished from the journey level 1042 Technology Engineer by the complexity and size of the systems or network supported. It is also distinguished from the Journey level by the amount of discretion exercised over technical issues, problems and resolutions, and that it possesses a significant level of specialized technical and functional expertise beyond that expected at the Journey level. Tis level is distinguished from the Principal level 1044 Technology Engineer – Principal in that Senior level exercises no or limited supervisory responsibilities or the lower technical leadership displayed. Positions at this level require highly specialized performance of their duties. The Senior level formulates recommendations consistent with directives, policies, standards and regulations. Work is judged primarily on overall results with great latitude in determining work methods and assignment requirements. The Senior has greater authority over assignments and decisions required to complete the work than lower level classifications.

This classification performs a wide range of complex analytical, design, planning, implementation, enhancement and problem resolution tasks on systems and platforms. It works within a framework of established procedures and interprets policies, procedures and guidelines. This level may formulate recommendations consistent with directives, policies, standards and regulations. Incumbents require only occasional instruction or assistance. Work is reviewed upon completion and for overall results.

Supervision Exercised:

Essential Duties:

  • Architects, designs, implements, maintains and operates information system security and privacy controls and countermeasures.
  • Analyzes and recommends security and privacy controls and procedures in acquisition, development, and change management lifecycle of information systems, and monitors for compliance.
  • Analyzes and recommends security and privacy controls and procedures in business processes related to use of information systems and assets, and monitors for compliance.
  • Monitors information systems for security incidents, vulnerabilities and privacy risks; develops monitoring and visibility capabilities; reports on incidents, vulnerabilities and trends.
  • Responds to information system security and privacy incidents, including investigation of, countermeasures to and recovery from computer-based attacks, unauthorized access and policy breaches; interacts and coordinates with third-party incident responders, including law enforcement.
  • Administers authentication and access controls, including provisioning, changes and deprovisioning of user and system accounts, security/access roles and access permissions to information assets.
  • Analyzes trends, news and changes in threat, compliance, and privacy regulatory environment with respect to organizational risk; advises organization management and develops and executes plans for compliance and mitigation of risk; performs risk and compliance self-assessments and engages and coordinates third-party risk and compliance assessments.
  • Analyzes and develops information security and privacy governance, including organizational policies, procedures, standards, baselines and guidelines with respect to information security, privacy, and use and operation of information systems.
  • Develops and administers, or provides advice, evaluation and oversight for, information security and privacy training and awareness programs.

Education

Experience

Three (3) years of experience analyzing, installing, configuring, enhancing, and/or maintaining the components of a system or platform.

Substitution:

Positions with the Port

Selection Procedures

Preliminary Questionnaire:

Tech Engineer – Security Core Exam (Weight: 100%):

Candidates self-certifying meeting the Minimum Qualifications will be invited to participate in the online Tech Engineer – Security Core Exam. Candidates will be sent a web link via email that will allow them to take the online Tech Engineer – Security Core Exam that is designed to measure basic analytical and technical abilities associated with the target job, which may include but not be limited to:

  • Knowledge of security operations including concepts, investigations and incident management
  • Knowledge of security engineering
  • Knowledge of communication and network security
  • Knowledge of asset security operations
  • Knowledge of identity and access management including controlling access and managing identity
  • Knowledge of mobile security including managing and securing mobile devices and software
  • Knowledge of security assessment and testing

This computer-administered test can be taken at home or at a time and location of one’s convenience, but only within a two week period specified on the test notification. Candidates must have access to a computer and reliable internet connection to participate in this exam. The test consists of 20 questions and it must be completed within 50 minutes. Questions are presented one at a time on the computer screen. There is no penalty for guessing. Candidates may not return to questions presented earlier in the exam; they can only move forward. A passing score must be attained on this test in order to continue further in the selection process. Test questions and answers are not available for public inspection or review.

Candidates’ scores on the Tech Engineer – Security Core Exam may also be applied to other announcements involving other job titles, when directed by the Human Resources Director.

Score Banking: Scores attained on the Tech Engineer – Security Core Exam will be 'banked' for three years, starting from the date of the examination. This means that, during this three-year time period, candidates need not take this test again. Rather, if another announcement you applied to and are deemed qualified for requires the Tech Engineer – Security Core Exam and is held within one year of your Tech Engineer – Security Core Exam date your score will be automatically applied to that announcement. However, after one year, a candidate has the option