Seeking a Systems Security Specialist who will serve as the primary hands-on administrator for assigned security platforms, including Microsoft Defender, Proofpoint, Tessian, Abnormal Security, Palo Alto Cortex, and related security technologies. This role involves direct configuration, maintenance, tuning, troubleshooting, and optimization of policies, rules, integrations, connectors, exclusions, allow/block lists, alerts, automated actions, and other platform settings. The specialist will monitor platform health, licensing, utilization, sensors/agents, integrations, data flow, and configuration drift, identifying and remediating operational issues, control gaps, conflicting configurations, integration failures, platform overlap, and opportunities to improve security effectiveness and operational efficiency. Additionally, the role includes performing Microsoft Exchange Administrator duties supporting Exchange Online and the Department's email security architecture, investigating various email-related threats, coordinating investigation and remediation actions across multiple security platforms, and continuously monitoring security work queues to triage and investigate security alerts and incidents. The specialist will determine scope and impact, identify affected users and assets, analyze evidence, recommend containment measures, and execute approved response actions. Critical incidents require immediate notification to the supervisor, with specific acknowledgment and triage timeframes for different incident priorities. Comprehensive incident documentation, including chronology, evidence, findings, actions, root cause, residual risk, and corrective actions, is required. For significant incidents, initial and final reports are necessary. The role also involves conducting regular threat hunts, developing investigative techniques, documenting findings, and translating validated findings into improved detections and operational procedures. Analyzing alert quality, detection coverage, and tuning detection logic, policies, and automated response actions to reduce false positives while maintaining detection capability is crucial. Maintaining up-to-date platform configuration documentation, runbooks, standard operating procedures, troubleshooting guides, and incident-response playbooks is also a key responsibility. Initial operational and security platform assessments will be conducted, delivering readiness assessments and baseline/stabilization plans. The specialist will maintain accurate work records, utilize Department systems, and comply with established procedures. Participation in various Department meetings and clear communication of technical information to diverse stakeholders are expected.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed