> Markdown version of [/jobs/ext/2224815-information-security-analyst-iv](https://www.wearedevelopers.com/jobs/ext/2224815-information-security-analyst-iv). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # INFORMATION SECURITY ANALYST IV - **Company:** Florida, Inc - **Location:** Tallahassee, FL, United States - **Experience:** Experienced - **Salary:** $70,000.0 - $80,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing, Cloud Computing Security, Cyber Security, System Configuration, Disaster Recovery, Multi-Factor Authentication, Identity and Access Management, Intrusion Detection and Prevention, Security Information and Event Management, Software Vulnerability Management, Data Logging, Cloud Platform System, Malware, Firewalls (Computer Science), Information Technology, Cybercrime - **Published:** August 25, 2026 - **Apply:** https://www.dice.com/job-detail/57ae15e1-4af7-4ff8-ad38-d59b9a371b7a ## About the Role * Knowledge of cloud security concepts and control implementation; * Knowledge of identity and access security controls, including MFA, conditional access, and privileged access review; * Knowledge of logging, monitoring, and telemetry architecture in enterprise environments; * Knowledge of security assessment methodologies, configuration review practices, and remediation validation; * Knowledge of threat detection, malware analysis, incident response, and forensics fundamentals; * Working knowledge of the NIST Cybersecurity Framework (CSF) and its application in state government; * Familiarity with Florida cybersecurity requirements (Section 282.318, F.S.; Rule 60GG-2, F.A.C.; FDS/CSOC reporting); * Deep technical proficiency with SIEM, EDR, firewall, email security, and vulnerability management platforms; * Skilled in designing, configuring, and administering enterprise security tooling; * Skilled in investigating security events, performing triage, and documenting findings; * Skilled in performing threat hunting and advanced analysis under time constraints; * Skilled in prioritizing vulnerabilities, coordinating remediation, and producing measurable risk metrics; * Skilled in producing technical documentation, reporting, and audit evidence; * Ability to communicate technical details clearly to technical and nontechnical audiences; * Ability to coordinate effectively with IT staff and external auditors; * Ability to maintain composure and accuracy during security incidents and escalations; * Ability to plan, organize, and manage multiple operational security tasks simultaneously; * Ability to support disaster recovery and business continuity testing through technical readiness validation; and * Ability to translate complex technical findings into concise, actionable reports., * Four (4) years of professional cybersecurity operations, incident response, security engineering, and monitoring experience in a hands-on role in a government or enterprise environment; OR * A bachelor's degree in Computer Science, Cybersecurity, or an IT-related field from an accredited college or university may substitute for the required experience. * Experience with security monitoring, SIEM tools, and cybersecurity governance; * Experience with identity management platforms, cloud environments, and endpoint security; * Experience conducting or supporting risk assessments and compliance audits; and * Experience interpreting statutory or regulatory cybersecurity requirements. Preferred Qualifications: * SSCP, GCIH, GCIA, CySA+, SecurityX, ECIH, CSA, or equivalent. * Experience in government, regulatory, or law enforcement network environments. The incumbent must be: * Reliable and dependable. * Strong skills in problem solving and critical thinking. * Excellent time management skills and ability to manage multiple tasks. * Proven interpersonal and communication skills. * The ability to work with all levels of employees in a professional manner. * Excellent analytical and decision-making abilities. * Detail-oriented and capable of maintaining high-quality documentation. * Able to lead teams, facilitate meetings, and manage major agency initiatives. ## Description This position serves as the Information Security Analyst IV (ISA IV) and is responsible for the design, configuration, administration, monitoring, and continuous improvement of enterprise cybersecurity controls. This role performs hands-on security operations, incident response, vulnerability management, threat hunting, and cloud and identity security engineering. The ISA IV provides technical execution and documented evidence that supports the Chief Information Security Officer (CISO). Duties are as follows: * Monitors security events and alerts across multiple platforms, investigates potential security incidents, performs triage, and coordinates technical response activities to ensure timely containment and remediation; * Conducts threat hunting activities, performs malware analysis, and documents all investigative steps in support of statutory reporting requirements; * Designs, implements, and maintains enterprise security controls, including endpoint detection and response tools, SIEM configurations, identity and access security technologies, email security protections, multi-factor authentication, conditional access policies, and cloud security configurations; * Ensures that logging, monitoring, and telemetry systems operate effectively to detect and respond to threats; * Manages day-to-day vulnerability management activities, including scanning, analysis of findings, prioritization of remediation, coordination with IT personnel, validation of fixes, and documentation of remediation metrics; * Ensures vulnerabilities are addressed promptly and provides clear technical reporting to the CISO; * Supports identity and access governance processes by reviewing privileged access assignments, monitoring administrative account activity, assisting with access certifications, and validating the effectiveness of identity-related security controls; * Performs technical security assessments and configuration reviews, conducts security testing for new systems and applications, supports penetration testing, and validates that required security controls have been implemented prior to deployment or production use; * Develops and maintains technical security procedures, documentation, runbooks, and operational artifacts necessary for consistent security operations; * Produces operational security metrics and dashboards that support agency leadership and statewide reporting requirements; * Provides technical guidance to IT staff and project teams to ensure secure implementation of technologies across the agency; * Supports the agency's disaster recovery and business continuity testing by ensuring technical systems and controls are appropriately validated and capable of supporting required recovery objectives; * Provides technical evidence and documentation required for internal and external audits, maintains inventories of security systems, and supports the CISO's preparation of the annual comprehensive risk assessment; * Assists in developing technical security standards and ensures accurate documentation of implemented controls; * Prepares technical incident documentation that supports the CISO's mandatory classification and reporting of incidents to the Cybersecurity Operations Center (CSOC) within statutory deadlines; * Assists in preparing quarterly cybersecurity status reports and other materials for agency leadership; * Supports the CISO's participation in statewide cybersecurity coordination efforts; * Assists in evidence gathering and coordination for independent audits; * Ensures technical accuracy and completeness of all materials provided; * Tests and maintains disaster recovery strategies; * Works with vendors and partners on security engineering, monitoring, and posturing tasks; * Travels to remote FGCC locations as needed to perform job-related duties; * Participates in after-hours or on-call incident response activities to ensure timely handling of critical security events; and * Performs other related duties as assigned. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)