CYBERSECURITY OPERATIONS CENTER ANALYST - 72004161

State of FloridaTALLAHASSEE, FL
$70,000 - $105,000Onsite

About The Position

The Cybersecurity Operations Center (CSOC) Analyst supports real-time cybersecurity monitoring, detection, and incident response for Florida’s state enterprise. Leveraging centralized telemetry, the CSOC Analyst identifies, analyzes, and responds to threats across multiple platforms, ensuring the protection of state systems and data. This role is critical in correlating threat intelligence, validating alerts, supporting investigations, and collaborating with detection engineering and incident response teams to improve Florida’s cyber defense.

Requirements

  • Knowledge of Cyber Threat Intelligence analysis and production methods.
  • Knowledge of Cybersecurity principles (CIA triad, defense-in-depth, MITRE ATT&CK).
  • Knowledge of Alert tuning and detection engineering.
  • Knowledge of Cyber Threat Hunting methodology, hypothesis driven threat hunting.
  • Knowledge of Incident response lifecycle and NIST SP 800-61 guidance.
  • Knowledge of Common attack vectors and detection strategies.
  • Skills in Log analysis across diverse sources (EDR, SIEM, network appliances, cloud services).
  • Skills in Cyber Threat Intelligence analysis and production methods.
  • Skills in Alert tuning and detection engineering.
  • Skills in Security event correlation, enrichment, and alert tuning.
  • Skills in Using log query languages such as KQL and SQL, and analysis tools such as query engines or search/analytics platforms (e.g., distributed search, indexing, and visualization systems).
  • Abilities to Follow standard operating procedures and escalate appropriately.
  • Abilities to Write clearly, specifically in the context of threat intelligence and threat analysis.
  • Abilities to Communicate clearly in writing and verbally, including documenting investigations.
  • Abilities to Work independently or in a team under high-pressure conditions.
  • Associate’s degree in Cybersecurity, Computer Science, or related field OR equivalent combination of education and experience.
  • 3+ years in a cybersecurity operations, SOC analyst, or related role.
  • Hands-on experience with SIEM tools (e.g., Splunk, Sentinel, Google SecOps OpenSearch, etc.), EDR, or firewall logs.
  • Familiarity with cloud platforms and log query languages (KQL, SQL, etc.), Threat Intelligence Platforms.
  • Eligible to work in the U.S. without sponsorship.

Nice To Haves

  • Bachelor’s degree in Cybersecurity, Computer Science, or related discipline.
  • Cloud security certifications (Microsoft Azure, Amazon AWS).
  • SANS GCTI (Cyber Threat Intelligence)
  • Experience in government, public sector, or regulated environments.
  • Hands-on threat hunting and behavioral analytics experience.

Responsibilities

  • Monitor, analyze, and respond to security events from SIEM, EDR, IDS/IPS, DNS, firewall, cloud, and identity sources.
  • Triage and prioritize alerts, escalating incidents per CSOC procedures and incident response playbooks.
  • Correlate security telemetry with threat intelligence and behavioral analytics to identify anomalies and malicious activity.
  • Provide contextualized threat intelligence to partner agencies and coordinate appropriate response.
  • Conduct proactive threat hunting using industry standard query languages.
  • Collaborate with detection engineering to validate alerts and enhance detection rules.
  • Document investigations and incident response activities in case management systems.
  • Assist in containment, eradication, and recovery efforts during incident response.
  • Produce clear incident and investigation reports for both technical and non-technical audiences.
  • Stay informed on current cybersecurity threats, tactics, techniques, and procedures (TTPs).
  • Other related duties as required.

Benefits

  • On-call rotation
  • Occasional after-hours work
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service