Job Description
Systems Security Specialist
Location: Tallahassee, FL
Work Schedule: Onsite, Monday through Friday, 8:00 AM to 5:00 PM ET
Employment Type: Long-Term Contract
Target Start: October 2026
Position Overview
We are seeking an experienced Systems Security Specialist to provide hands-on enterprise security engineering, security operations, email security administration, threat response, and threat-hunting support within a large enterprise environment.
This individual will serve as a primary hands-on administrator for assigned security technologies and will independently handle configuration, administration, tuning, troubleshooting, investigations, documentation, and incident response.
This is a highly technical, hands-on position requiring someone who can operate independently in a complex production security environment.
Required Experience
Please view our Privacy Policy.
Systems Security Specialist
Location: Tallahassee, FL
Work Schedule: Onsite, Monday through Friday, 8:00 AM to 5:00 PM ET
Employment Type: Long-Term Contract
Target Start: October 2026
Position Overview
We are seeking an experienced Systems Security Specialist to provide hands-on enterprise security engineering, security operations, email security administration, threat response, and threat-hunting support within a large enterprise environment.
This individual will serve as a primary hands-on administrator for assigned security technologies and will independently handle configuration, administration, tuning, troubleshooting, investigations, documentation, and incident response.
This is a highly technical, hands-on position requiring someone who can operate independently in a complex production security environment.
Required Experience
- 7+ years of progressively responsible IT and cybersecurity experience within enterprise environments, including security engineering, security operations, endpoint security, identity security, cloud security, and messaging security.
- 4+ years of recent hands-on production experience configuring, administering, tuning, investigating, and troubleshooting Palo Alto Cortex and Tanium, including Cortex for Endpoint and Tanium Comply.
- 3+ years of recent hands-on enterprise email security administration experience.
- Hands-on production experience with Proofpoint, Tessian, and Abnormal Security is required.
- 3+ years of hands-on Microsoft Exchange / Exchange Online administration, including mail flow, transport rules, connectors, message tracing, anti-spam, anti-phishing, quarantine, mail routing, and security-related troubleshooting.
- 3+ years of hands-on security incident response experience covering alert triage, investigation, containment, eradication, recovery, root-cause analysis, and post-incident documentation.
- 2+ years of hands-on threat-hunting experience across endpoint, identity, email, network, and cloud telemetry.
- Experience developing and tuning detection logic, security policies, alert thresholds, exclusions, allow/block rules, indicators, and automated response actions.
- Strong experience investigating endpoint, identity, and email threats using process trees, command lines, hashes, URLs, domains, IP addresses, message headers, authentication events, and user activity.
- Experience with Microsoft Entra ID / Azure Active Directory security, including authentication events, sign-in risk, Conditional Access, Identity Protection, MFA, and identity-related incident investigation.
- Experience using PowerShell or comparable scripting for security administration, investigations, data collection, configuration, and operational automation.
- Experience creating technical documentation, operational procedures, incident records, threat-hunting reports, security metrics, and remediation recommendations.
- Experience supporting a large, distributed enterprise environment.
- Ability to independently perform security administration, investigations, troubleshooting, configuration, threat hunting, and incident response without requiring foundational technical training.
- Serve as a primary hands-on administrator for enterprise security platforms, including Microsoft Defender, Proofpoint, Tessian, Abnormal Security, Palo Alto Cortex, and Tanium.
- Configure, tune, maintain, troubleshoot, and optimize security policies, rules, integrations, connectors, exclusions, allow/block lists, alerting, and automated actions.
- Monitor platform health, integrations, agent/sensor status, data flow, utilization, and configuration drift.
- Identify control gaps, overlapping technologies, conflicting configurations, and opportunities to improve security effectiveness.
- Administer and support Exchange Online and enterprise email security technologies.
- Troubleshoot mail flow, connectors, transport rules, message tracing, quarantine, anti-spam, anti-phishing, impersonation protection, domain controls, and security integrations.
- Investigate phishing, business email compromise, malicious attachments and links, spoofing, account compromise, and anomalous email activity.
- Coordinate security configuration and response activities across Microsoft and third-party email security platforms.
- Monitor security alerts and actively perform alert triage and incident response.
- Independently investigate incidents, determine scope and impact, identify affected users and assets, analyze evidence, and recommend or execute approved containment actions.
- Support endpoint isolation, indicator blocking, malicious email removal, account/session containment, policy changes, and evidence preservation.
- Perform root-cause analysis and document incident findings, actions taken, residual risks, and corrective recommendations.
- Conduct proactive, hypothesis-driven threat hunts across endpoint, identity, email, network, and cloud telemetry.
- Develop queries and investigative techniques to identify suspicious behaviors, persistence, credential abuse, lateral movement, malicious PowerShell or command execution, anomalous authentication, and other indicators of compromise.
- Document threat-hunting activities, findings, techniques, and recommended improvements.
- Translate validated findings into improved detections, blocking controls, configuration changes, and incident-response procedures.
- Analyze alert quality and detection coverage and tune controls to reduce false positives while maintaining effective detection.
- Develop, test, document, and maintain detection logic, security policies, indicators, automated response actions, and escalation criteria.
- Identify security control gaps, integration failures, configuration weaknesses, and operational dependencies.
- Validate the effectiveness of security configuration and detection changes.
- Maintain configuration documentation, runbooks, SOPs, troubleshooting guides, and incident-response playbooks.
- Document material security platform changes and ensure processes are reproducible by authorized personnel.
- Provide knowledge transfer regarding environment-specific configurations and procedures.
- Maintain accurate records of completed work, active investigations, incidents, threat hunts, platform issues, risks, and planned actions.
- Participate in operational, incident, change-management, architecture, and security meetings.
- Communicate technical information clearly to both technical and non-technical stakeholders.
- Must be able to work onsite in Tallahassee, Florida, Monday through Friday during standard business hours.
- Occasional after-hours availability may be required for security incidents, emergency changes, or scheduled maintenance.
- Must be able to successfully complete required pre-employment/background screening.
- Candidates should be comfortable working independently within a structured enterprise security environment with established incident-response and change-management procedures.
Please view our Privacy Policy.
