Systems Security Specialist

ePATHUSA IncTallahassee, FL

About The Position

Seeking a Systems Security Specialist who will serve as the primary hands-on administrator for assigned security platforms, including Microsoft Defender, Proofpoint, Tessian, Abnormal Security, Palo Alto Cortex, and related security technologies. This role involves direct configuration, maintenance, tuning, troubleshooting, and optimization of policies, rules, integrations, connectors, exclusions, allow/block lists, alerts, automated actions, and other platform settings. The specialist will monitor platform health, licensing, utilization, sensors/agents, integrations, data flow, and configuration drift, identifying and remediating operational issues, control gaps, conflicting configurations, integration failures, platform overlap, and opportunities to improve security effectiveness and operational efficiency. Additionally, the role includes performing Microsoft Exchange Administrator duties supporting Exchange Online and the Department's email security architecture, investigating various email-related threats, coordinating investigation and remediation actions across multiple security platforms, and continuously monitoring security work queues to triage and investigate security alerts and incidents. The specialist will determine scope and impact, identify affected users and assets, analyze evidence, recommend containment measures, and execute approved response actions. Critical incidents require immediate notification to the supervisor, with specific acknowledgment and triage timeframes for different incident priorities. Comprehensive incident documentation, including chronology, evidence, findings, actions, root cause, residual risk, and corrective actions, is required. For significant incidents, initial and final reports are necessary. The role also involves conducting regular threat hunts, developing investigative techniques, documenting findings, and translating validated findings into improved detections and operational procedures. Analyzing alert quality, detection coverage, and tuning detection logic, policies, and automated response actions to reduce false positives while maintaining detection capability is crucial. Maintaining up-to-date platform configuration documentation, runbooks, standard operating procedures, troubleshooting guides, and incident-response playbooks is also a key responsibility. Initial operational and security platform assessments will be conducted, delivering readiness assessments and baseline/stabilization plans. The specialist will maintain accurate work records, utilize Department systems, and comply with established procedures. Participation in various Department meetings and clear communication of technical information to diverse stakeholders are expected.

Requirements

  • Progressively responsible information technology and cybersecurity experience in enterprise environments, including security engineering, security operations, endpoint security, identity security, cloud security, and messaging security.
  • Recent hands-on production experience configuring, administering, tuning, investigating and troubleshooting Palo Alto Cortex and Tanium security technologies, including Palo Alto Cortex for Endpoint and Tanium Comply Modules.
  • Recent hands-on production experience administering enterprise email security technologies. The required three years may consist of combined experience across these technologies, but experience with each named technology is mandatory.
  • Recent hands-on Microsoft Exchange Administrator experience, including Exchange Online administration, mail flow, transport rules, connectors, message tracing, anti-spam controls, anti-phishing controls, quarantine, mail routing, and troubleshooting security-related messaging issues.
  • Hands-on security incident-response experience, including alert triage, investigation, containment, eradication, recovery, root-cause analysis, and post-incident documentation.
  • Hands-on threat-hunting experience using endpoint, identity, email, network, and cloud telemetry to identify malicious or anomalous activity not detected through standard alerting.

Nice To Haves

  • Demonstrated experience developing and tuning detection logic, security policies, alert thresholds, exclusions, allow and block rules, indicators, automated response actions, and other controls to improve detection efficacy and reduce false positives.
  • Demonstrated ability to investigate endpoint, identity, and email threats using artifacts such as process trees, command lines, hashes, URLs, domains, IP addresses, message headers, authentication events, user activity, and related telemetry.
  • Demonstrated experience with Microsoft Entra ID or Azure Active Directory security, including authentication events, sign-in risk, conditional access, identity protection, multifactor authentication, and identity-related incident investigation.
  • Demonstrated experience using PowerShell or comparable scripting to support security administration, investigation, data collection, configuration, and repeatable operational tasks.
  • Demonstrated experience creating and maintaining technical configurations, operational procedures, incident records, threat-hunting reports, security metrics, and remediation recommendations suitable for operational and management review.
  • Demonstrated experience performing substantially similar services in at least one large, distributed enterprise environment.

Responsibilities

  • Serve as the primary hands-on administrator for assigned security platforms, including Microsoft Defender, Proofpoint, Tessian, Abnormal Security, Palo Alto Cortex, and related security technologies.
  • Directly configure, maintain, tune, troubleshoot, and optimize policies, rules, integrations, connectors, exclusions, allow/block lists, alerts, automated actions, and other platform settings.
  • Monitor platform health, licensing and utilization, sensors/agents, integrations, data flow, and configuration drift.
  • Identify and remediate operational issues, control gaps, conflicting configurations, integration failures, platform overlap, and opportunities to improve security effectiveness and operational efficiency.
  • Perform Microsoft Exchange Administrator duties supporting Exchange Online and the Department's email security architecture, including mail flow, connectors, transport/mail-flow rules, message tracing, quarantine, anti-spam, anti-phishing, impersonation protection, domain controls, and integrations with Microsoft Defender, Proofpoint, Tessian, and Abnormal Security.
  • Investigate phishing, business email compromise, malicious attachments and links, spoofing, account compromise, and anomalous email activity.
  • Coordinate investigation, configuration, containment, and remediation actions across Microsoft and third-party email security platforms.
  • Continuously monitor assigned security work queues during required business hours and independently triage and investigate security alerts and incidents.
  • Determine scope and impact, identify affected users and assets, analyze evidence, recommend containment measures, and execute Department-approved response actions, including endpoint isolation, indicator blocking, malicious email removal, account/session containment, and policy changes.
  • Immediately notify the designated Department supervisor of confirmed or suspected critical incidents or material escalations.
  • Acknowledge and begin triage within specified timeframes for different incident priorities (15 minutes for Priority 1/Critical, 30 minutes for Priority 2/High, 4 business hours for others, or Department-assigned timeframe, whichever is sooner).
  • When activated for after-hours response, acknowledge the request within 30 minutes and begin response activities as directed.
  • Maintain complete incident documentation, including chronology, evidence reviewed, findings, actions taken, root cause when determinable, residual risk, and recommended corrective actions.
  • For Department-designated significant incidents, provide an initial Significant Incident Summary within two business days after containment and a final Significant Incident Report within five business days after incident closure, unless otherwise directed.
  • Conduct at least two documented, hypothesis-driven threat hunts per calendar month across endpoint, identity, email, network, or cloud telemetry.
  • Develop queries and investigative techniques to identify suspicious activity, including persistence, credential abuse, lateral movement, malicious command or PowerShell execution, anomalous authentication, and other indicators of compromise.
  • Document each threat hunt, including the hypothesis/trigger, data sources, queries or techniques, findings, disposition, and recommended improvements.
  • Translate validated findings into improved detections, blocking controls, configuration changes, incident-response actions, and operational procedures.
  • Analyze alert quality and detection coverage; develop, test, tune, and maintain detection logic, policies, indicators, automated response actions, and escalation criteria.
  • Reduce false positives without materially reducing detection capability and validate the effectiveness of material configuration or detection changes after implementation.
  • Maintain current platform configuration documentation, runbooks, standard operating procedures, troubleshooting guides, and incident-response playbooks.
  • Document material Security Platform Configuration and Runbook Updates within five business days of implementation and provide targeted knowledge transfer so authorized Department personnel can reproduce and support established procedures.
  • Conduct initial operational and security platform assessments, delivering an Operational Readiness Assessment within 10 business days and a Security Platform Baseline and Stabilization Plan within 30 calendar days of receiving necessary access, documenting platform status, risks, configuration and integration gaps, corrective actions, and prioritized stabilization recommendations.
  • Maintain accurate Department work records covering completed work, open incidents, active investigations, threat hunts, platform issues, risks, decisions, and planned actions.
  • Use Department ticketing, change-management, timekeeping, and documentation systems and comply with established security, incident-response, and change-control procedures.
  • Participate in Department operational, incident, change, architecture, and security meetings as directed.
  • Clearly communicate technical information to technical and non-technical stakeholders and promptly escalate risks, decisions, dependencies, or access limitations that could prevent timely completion of assigned work.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service