| Location | Tallahassee, FL |
| Job Type | Contractor |
Systems Security Specialist (Cortex, Tanium & Email Security):
Total Required Experience in Years: 10%2B Years
Mode of Work:Not Specified in Provided Requirement Tallahassee, FL
The Systems Security Specialist will provide advanced cybersecurity engineering and security-operations support within a large, distributed enterprise environment. The position requires strong hands-on production experience across Palo Alto Cortex, Tanium, enterprise email security, Microsoft Exchange Online, endpoint security, identity security, incident response, and threat hunting.
The consultant must be capable of independently performing routine security administration, configuration, investigation, troubleshooting, threat hunting, and incident-response activities without requiring foundational product training or continuous technical oversight.
Configure, administer, tune, investigate, and troubleshoot Palo Alto Cortex and Tanium security technologies.
Administer Palo Alto Cortex for Endpoint.
Administer and support Tanium Comply modules.
Manage enterprise email-security technologies.
Administer Proofpoint, Tessian, and Abnormal Security.
Administer Microsoft Exchange Online security and messaging functions.
Manage mail flow, transport rules, connectors, and mail routing.
Perform message tracing and troubleshoot security-related messaging issues.
Administer anti-spam, anti-phishing, and quarantine controls.
Perform security alert triage and investigations.
Coordinate incident containment, eradication, and recovery.
Conduct root-cause analysis and post-incident documentation.
Perform proactive threat hunting across enterprise environments.
Hunt threats using endpoint, identity, email, network, and cloud telemetry.
Develop and tune security detection logic.
Configure security policies and alert thresholds.
Maintain exclusions and allow/block rules.
Develop and manage security indicators.
Configure automated response actions.
Improve detection effectiveness and reduce false positives.
Investigate endpoint, identity, and email-security threats.
Analyze:
Process Trees
Command Lines
File Hashes
URLs
Domains
IP Addresses
Email Headers
Authentication Events
User Activity
Create and maintain security metrics and remediation recommendations.
Maintain technical configurations, operational procedures, incident records, and threat-hunting reports.
Minimum 7%2B years of progressively responsible IT and cybersecurity experience in enterprise environments.
Experience covering:
Security Engineering
Security Operations
Endpoint Security
Identity Security
Cloud Security
Messaging Security
Minimum 4%2B years of recent hands-on production experience configuring, administering, tuning, investigating, and troubleshooting:
Palo Alto Cortex
Cortex for Endpoint
Tanium
Tanium Comply
Minimum 3%2B years of recent hands-on enterprise email-security administration experience.
Mandatory hands-on production administration experience with all three:
Proofpoint
Tessian
Abnormal Security
Minimum 3%2B years of recent hands-on Microsoft Exchange administration experience.
Strong Exchange Online administration experience.
Experience with mail flow, transport rules, connectors, message tracing, anti-spam, anti-phishing, quarantine, and mail routing.
Minimum 3%2B years of hands-on security incident-response experience.
Experience with alert triage, investigation, containment, eradication, recovery, root-cause analysis, and documentation.
Minimum 2%2B years of hands-on threat-hunting experience.
Experience developing and tuning detection logic, policies, thresholds, exclusions, indicators, and automated response actions.
Experience investigating endpoint, identity, and email threats.
Experience with Microsoft Entra ID / Azure Active Directory security.
Experience investigating authentication events and sign-in risks.
Knowledge of Conditional Access, Identity Protection, and MFA.
Experience using PowerShell or comparable scripting for security operations.
Experience working within a large, distributed enterprise environment.
Advanced Palo Alto Cortex expertise.
Advanced Tanium security administration.
Detection engineering and security-control optimization.
Advanced Microsoft Entra ID security experience.
Enterprise identity threat investigation.
Cloud-security operations.
Security automation using PowerShell.
Experience integrating endpoint, identity, email, network, and cloud telemetry.
Security metrics and management reporting experience.
Ability to independently administer enterprise cybersecurity platforms.
Ability to perform investigations and threat hunting without continuous technical supervision.
Strong endpoint, identity, email, and cloud-security investigation skills.
Ability to distinguish malicious activity from legitimate behavior.
Strong analytical and troubleshooting capabilities.
Ability to develop actionable remediation recommendations.
Strong technical documentation skills.
Ability to create management-ready security reports and metrics.
Experience delivering substantially similar services within at least one large, distributed enterprise environment.
Ability to independently execute routine administration, configuration, investigation, troubleshooting, threat hunting, and incident-response activities immediately upon assignment.
Education requirements were not specified in the provided requirement.
Palo Alto Networks Cortex Certification Preferred
Tanium Certified Operator / Administrator Preferred
Microsoft Security Operations Analyst (SC-200) Preferred
Microsoft Identity and Access Administrator (SC-300) Preferred
CompTIA Security%2B / CySA%2B Preferred
GIAC Incident Response / Threat Hunting Certification Preferred