CYBERSECURITY ANALYST
Florida Jobs
Cybersecurity Analyst
The Florida Department of Health is seeking a highly motivated Cybersecurity Analyst to join the Office of Information Technology. This position plays a critical role in defending one of Florida's largest public-sector technology environments, protecting the systems and data that support statewide public health programs, County Health Departments, healthcare partners, and millions of Floridians.
If you thrive in a fast-paced Security Operations Center (SOC) environment, enjoy investigating sophisticated cyber threats, and want your work to have a direct impact on public health and safety, we encourage you to apply. This position serves within the Security Administration section of the Office of the CIO and supports enterprise cybersecurity operations across the Department.
Your specific responsibilities include:
- Monitor, analyze, investigate, and respond to cybersecurity alerts and incidents across enterprise systems.
- Perform security event correlation using data from endpoints, servers, identity systems, Microsoft 365, cloud platforms, networks, SIEM, EDR, and other security technologies.
- Conduct incident triage, containment, eradication, recovery, and post-incident analysis.
- Perform proactive threat hunting to identify indicators of compromise and emerging threats before they impact the organization.
- Document the complete incident lifecycle, including evidence, timelines, technical findings, remediation activities, and executive reporting.
- Analyze cyber threats, vulnerabilities, attacker tactics, techniques, and procedures (TTPs), and recommend improvements to strengthen the Department's security posture.
- Configure, tune, and optimize enterprise cybersecurity technologies in accordance with approved security standards and change management procedures.
- Support enterprise risk management by identifying control gaps, assisting with security assessments, and tracking remediation efforts.
- Maintain incident response playbooks, standard operating procedures, and operational metrics.
Required knowledge, skills, and abilities include:
- Proficient computer skills to include Word, Excel, PowerPoint and Outlook; knowledge of monitoring processes and/or working with ticketing software; knowledge of computer data bases; knowledge of laws, legal codes, court procedures and government rules & regulations; knowledge of the structure and content of the English language including the meaning and spelling of words, rules of composition, and grammar; understanding written sentences and paragraphs in work related documents; communicating effectively with others verbally and in writing; talking to others to effectively convey information; ability to establish and maintain effective working relationships with others; listening to what other people are saying and asking questions as appropriate; conduct fact-finding research; knowledge of the methods of data collection and analysis; organize data into logical format for presentation in reports, documents and other written materials; knowing how to find information and identifying essential information; finding ways to structure or classify multiple pieces of information; ability to plan, organize and prioritize work assignments; ability to work independently; ability to maintain a high degree of accuracy and close attention to detail; ability to maintain confidentiality; knowledge of the cybersecurity incident-response lifecycle; security operations and agency-adopted incident-response and risk-management frameworks; SIEM and EDR technologies; Microsoft 365, identity, endpoint, server, network, and cloud telemetry; Windows and Linux fundamentals; common network protocols; threat intelligence; vulnerability management; malware behavior; digital forensics; evidence handling; access control; and change management; skill in security alert triage, log correlation, incident investigation, threat hunting, incident documentation, security-tool configuration and tuning, scripting and automation, network and process analysis, technical writing, and the use of Department-issued computing equipment, ticketing systems, and approved cybersecurity platforms; ability to assess incident scope, severity, and business impact; manage concurrent incidents and competing priorities; exercise sound judgment under time-sensitive conditions; maintain complete and accurate records; support after-hours cybersecurity response when required.
Qualifications:
Successful candidates will have experience with many of the following: Security Operations Center (SOC) environments; SIEM platforms; Endpoint Detection and Response (EDR); Microsoft 365 security technologies; Windows and Linux administration; Identity and access management; Network protocols and network security; Incident response; Threat hunting; Digital forensics; Vulnerability management; Security monitoring and log analysis; Risk management; Scripting or automation (PowerShell, Python, or similar); Technical writing and incident documentation.
While not required, certifications such as the following are highly desirable: GIAC (GCIH, GCIA, GCFA, GCFE, GREM); CISSP; Security+; CySA+; CEH; Microsoft Security certifications; Splunk, Sentinel, or similar SIEM certifications.
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to CYBERSECURITY ANALYST. Be the first to apply!
- cyber security lead Tallahassee, FL
- remote cyber security Tallahassee, FL
- entry level cyber security Tallahassee, FL
- cybersecurity administrator Tallahassee, FL
- cyber security Tallahassee, FL
- cyber security incident responder Tallahassee, FL
- cybersecurity software engineer Tallahassee, FL
- IT cyber security Tallahassee, FL
- cybersecurity policy and compliance analyst Tallahassee, FL
- cybersecurity specialist Tallahassee, FL
