Cybersecurity Operations Center Analyst

MYFLORIDA CORPORATION
Tallahassee, FL, United States
6 days ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$70,000.0 - $105,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security Query Languages Domain Name System (DNS) Intelligence Analysis Networking Hardware Intrusion Detection and Prevention Intrusion Detection Systems
+12 more
Log Analysis Cloud Services Kusto Query Language Security Information and Event Management SQL Databases In-Plane Switching (IPS) Mitre Att&ck Cyber Threat Analysis Firewalls (Computer Science) Information Technology Cyber Warfare Splunk

Job description

The Cybersecurity Operations Center (CSOC) Analyst supports real-time cybersecurity monitoring, detection, and incident response for Florida’s state enterprise. Leveraging centralized telemetry, the CSOC Analyst identifies, analyzes, and responds to threats across multiple platforms, ensuring the protection of state systems and data.

This role is critical in correlating threat intelligence, validating alerts, supporting investigations, and collaborating with detection engineering and incident response teams to improve Florida’s cyber defense, + Monitor, analyze, and respond to security events from SIEM, EDR, IDS/IPS, DNS, firewall, cloud, and identity sources.

  • Triage and prioritize alerts, escalating incidents per CSOC procedures and incident response playbooks.

  • Correlate security telemetry with threat intelligence and behavioral analytics to identify anomalies and malicious activity.

  • Provide contextualized threat intelligence to partner agencies and coordinate appropriate response.

  • Conduct proactive threat hunting using industry standard query languages.

  • Collaborate with detection engineering to validate alerts and enhance detection rules.

  • Document investigations and incident response activities in case management systems.

  • Assist in containment, eradication, and recovery efforts during incident response.

  • Produce clear incident and investigation reports for both technical and non-technical audiences.

  • Stay informed on current cybersecurity threats, tactics, techniques, and procedures (TTPs).

  • Other related duties as required., Pursuant to F.S. 215.422 every officer or employee who is responsible for the approval or processing of vendors’ invoices or distribution of warrants to vendors are mandated to process, resolve, and comply as section 215.422 requires.

Our Organization and Mission:

Under the direction of Governor Ron DeSantis, Secretary Tom Berger and DMS’ Executive Leadership Team, the Florida Department of Management Services (DMS) is a customer-oriented agency with a broad portfolio that includes the efficient use and management of real estate, procurement, human resources, group insurance, retirement, telecommunications, fleet, and federal property assistance programs used throughout Florida’s state government. It is against this backdrop that DMS strives to demonstrate its motto, “We serve those who serve Florida.”

Special Notes:

DMS is committed to successfully recruiting and onboarding talented and skilled individuals into its workforce. We recognize the extensive training, experience, and transferable skills that veterans and individuals with disabilities bring to the workforce. Veterans and individuals with disabilities are encouraged to contact our agency recruiter for guidance and answers to questions through the following provided email addresses

Requirements

  • Cyber Threat Intelligence analysis and production methods.

  • Cybersecurity principles (CIA triad, defense-in-depth, MITRE ATT&CK).\

  • Alert tuning and detection engineering.

  • Cyber Threat Hunting methodology, hypothesis driven threat hunting.

  • Incident response lifecycle and NIST SP 800-61 guidance.

  • Common attack vectors and detection strategies.

Skills in:

  • Log analysis across diverse sources (EDR, SIEM, network appliances, cloud services).

  • Cyber Threat Intelligence analysis and production methods., + Associate’s degree in Cybersecurity, Computer Science, or related field OR equivalent combination of education and experience.

Experience:

  • 3+ years in a cybersecurity operations, SOC analyst, or related role.

  • Hands-on experience with SIEM tools (e.g., Splunk, Sentinel, Google SecOps OpenSearch, etc.), EDR, or firewall logs.

  • Familiarity with cloud platforms and log query languages (KQL, SQL, etc.), Threat Intelligence Platforms.

Certification:

  • CompTIA Security+ (required within 12 months of hire).

Other Requirements:

  • Eligible to work in the U.S. without sponsorship.

  • Ability to participate in on-call rotation and occasional after-hours work

PREFERRED QUALIFICATIONS

  • Bachelor’s degree in Cybersecurity, Computer Science, or related discipline.

  • Cloud security certifications (Microsoft Azure, Amazon AWS).

  • SANS GCTI (Cyber Threat Intelligence)

  • Experience in government, public sector, or regulated environments.

  • Hands-on threat hunting and behavioral analytics experience.

On-Call Assignment - This position has been approved in accordance with Section 110.209, Florida Statutes, Chapter 60L-32, Florida Administrative Code, and Collective Bargaining Agreements with the Florida Nurses Association (FNA) and the American Federation of State, County, and Municipal Employees (AFSCME), Florida Council 79. The approved On-Call form has been forwarded to the servicing human resource office.

Criminal background investigation including fingerprinting and statewide and national criminal history records check per Section 110.1127 Florida Statutes, Chapter 435 Florida Statutes, and the Federal Bureau of Investigation’s CJIS Security Policy CJISD-ITS-DOC-08140-4.5

Ability to sit for extended periods of time. Ability to stand for extended periods of time. Ability to drive and/or fly for long distances. Ability to lift, push and pull up to 30lbs.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler · LIVE

4:23 min

Boosting security operations center productivity with intelligent data analysis

Chris Wysopal Chris Wysopal +2 · World Congress 2024

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all