Search

Systems Security Specialist

PublishedPublished: 9/18/2026
Security Officer
Job Description

Systems Security Specialist
Location: Tallahassee, FL
Work Schedule: Onsite, Monday through Friday, 8:00 AM to 5:00 PM ET
Employment Type: Long-Term Contract
Target Start: October 2026
Position Overview
We are seeking an experienced Systems Security Specialist to provide hands-on enterprise security engineering, security operations, email security administration, threat response, and threat-hunting support within a large enterprise environment.

This individual will serve as a primary hands-on administrator for assigned security technologies and will independently handle configuration, administration, tuning, troubleshooting, investigations, documentation, and incident response.

This is a highly technical, hands-on position requiring someone who can operate independently in a complex production security environment.
Required Experience
  • 7+ years of progressively responsible IT and cybersecurity experience within enterprise environments, including security engineering, security operations, endpoint security, identity security, cloud security, and messaging security.
  • 4+ years of recent hands-on production experience configuring, administering, tuning, investigating, and troubleshooting Palo Alto Cortex and Tanium, including Cortex for Endpoint and Tanium Comply.
  • 3+ years of recent hands-on enterprise email security administration experience.
  • Hands-on production experience with Proofpoint, Tessian, and Abnormal Security is required.
  • 3+ years of hands-on Microsoft Exchange / Exchange Online administration, including mail flow, transport rules, connectors, message tracing, anti-spam, anti-phishing, quarantine, mail routing, and security-related troubleshooting.
  • 3+ years of hands-on security incident response experience covering alert triage, investigation, containment, eradication, recovery, root-cause analysis, and post-incident documentation.
  • 2+ years of hands-on threat-hunting experience across endpoint, identity, email, network, and cloud telemetry.
  • Experience developing and tuning detection logic, security policies, alert thresholds, exclusions, allow/block rules, indicators, and automated response actions.
  • Strong experience investigating endpoint, identity, and email threats using process trees, command lines, hashes, URLs, domains, IP addresses, message headers, authentication events, and user activity.
  • Experience with Microsoft Entra ID / Azure Active Directory security, including authentication events, sign-in risk, Conditional Access, Identity Protection, MFA, and identity-related incident investigation.
  • Experience using PowerShell or comparable scripting for security administration, investigations, data collection, configuration, and operational automation.
  • Experience creating technical documentation, operational procedures, incident records, threat-hunting reports, security metrics, and remediation recommendations.
  • Experience supporting a large, distributed enterprise environment.
  • Ability to independently perform security administration, investigations, troubleshooting, configuration, threat hunting, and incident response without requiring foundational technical training.
Key ResponsibilitiesSecurity Platform Administration & Engineering
  • Serve as a primary hands-on administrator for enterprise security platforms, including Microsoft Defender, Proofpoint, Tessian, Abnormal Security, Palo Alto Cortex, and Tanium.
  • Configure, tune, maintain, troubleshoot, and optimize security policies, rules, integrations, connectors, exclusions, allow/block lists, alerting, and automated actions.
  • Monitor platform health, integrations, agent/sensor status, data flow, utilization, and configuration drift.
  • Identify control gaps, overlapping technologies, conflicting configurations, and opportunities to improve security effectiveness.
Microsoft Exchange & Email Security
  • Administer and support Exchange Online and enterprise email security technologies.
  • Troubleshoot mail flow, connectors, transport rules, message tracing, quarantine, anti-spam, anti-phishing, impersonation protection, domain controls, and security integrations.
  • Investigate phishing, business email compromise, malicious attachments and links, spoofing, account compromise, and anomalous email activity.
  • Coordinate security configuration and response activities across Microsoft and third-party email security platforms.
Incident Response
  • Monitor security alerts and actively perform alert triage and incident response.
  • Independently investigate incidents, determine scope and impact, identify affected users and assets, analyze evidence, and recommend or execute approved containment actions.
  • Support endpoint isolation, indicator blocking, malicious email removal, account/session containment, policy changes, and evidence preservation.
  • Perform root-cause analysis and document incident findings, actions taken, residual risks, and corrective recommendations.
Threat Hunting
  • Conduct proactive, hypothesis-driven threat hunts across endpoint, identity, email, network, and cloud telemetry.
  • Develop queries and investigative techniques to identify suspicious behaviors, persistence, credential abuse, lateral movement, malicious PowerShell or command execution, anomalous authentication, and other indicators of compromise.
  • Document threat-hunting activities, findings, techniques, and recommended improvements.
  • Translate validated findings into improved detections, blocking controls, configuration changes, and incident-response procedures.
Detection Engineering & Security Optimization
  • Analyze alert quality and detection coverage and tune controls to reduce false positives while maintaining effective detection.
  • Develop, test, document, and maintain detection logic, security policies, indicators, automated response actions, and escalation criteria.
  • Identify security control gaps, integration failures, configuration weaknesses, and operational dependencies.
  • Validate the effectiveness of security configuration and detection changes.
Documentation & Operational Support
  • Maintain configuration documentation, runbooks, SOPs, troubleshooting guides, and incident-response playbooks.
  • Document material security platform changes and ensure processes are reproducible by authorized personnel.
  • Provide knowledge transfer regarding environment-specific configurations and procedures.
  • Maintain accurate records of completed work, active investigations, incidents, threat hunts, platform issues, risks, and planned actions.
  • Participate in operational, incident, change-management, architecture, and security meetings.
  • Communicate technical information clearly to both technical and non-technical stakeholders.
Additional Requirements
  • Must be able to work onsite in Tallahassee, Florida, Monday through Friday during standard business hours.
  • Occasional after-hours availability may be required for security incidents, emergency changes, or scheduled maintenance.
  • Must be able to successfully complete required pre-employment/background screening.
  • Candidates should be comfortable working independently within a structured enterprise security environment with established incident-response and change-management procedures.

Please view our Privacy Policy.