Systems Security Specialist

Prosum

  • Tallahassee, FL
  • 9 days ago

    Highlights

    3+ years of hands-on Microsoft Exchange / Exchange Online administration , including mail flow, transport rules, connectors, message tracing, anti-spam, anti-phishing, quarantine, mail routing, and security-related troubleshooting. We are seeking an experienced Systems Security Specialist to provide hands-on enterprise security engineering, security operations, email security administration, threat response, and threat-hunting support within a large enterprise environment.

    Numbers & Facts

    LocationTallahassee, FL

    Description

    Systems Security Specialist
    Location: Tallahassee, FL
    Work Schedule: Onsite, Monday through Friday, 8:00 AM to 5:00 PM ET
    Employment Type: Long-Term Contract
    Target Start: October 2026
    Position Overview
    We are seeking an experienced Systems Security Specialist to provide hands-on enterprise security engineering, security operations, email security administration, threat response, and threat-hunting support within a large enterprise environment.

    This individual will serve as a primary hands-on administrator for assigned security technologies and will independently handle configuration, administration, tuning, troubleshooting, investigations, documentation, and incident response.

    This is a highly technical, hands-on position requiring someone who can operate independently in a complex production security environment.
    Required Experience

    • 7+ years of progressively responsible IT and cybersecurity experience within enterprise environments, including security engineering, security operations, endpoint security, identity security, cloud security, and messaging security.

    • 4+ years of recent hands-on production experience configuring, administering, tuning, investigating, and troubleshooting Palo Alto Cortex and Tanium, including Cortex for Endpoint and Tanium Comply.

    • 3+ years of recent hands-on enterprise email security administration experience.

    • Hands-on production experience with Proofpoint, Tessian, and Abnormal Security is required.

    • 3+ years of hands-on Microsoft Exchange / Exchange Online administration, including mail flow, transport rules, connectors, message tracing, anti-spam, anti-phishing, quarantine, mail routing, and security-related troubleshooting.

    • 3+ years of hands-on security incident response experience covering alert triage, investigation, containment, eradication, recovery, root-cause analysis, and post-incident documentation.

    • 2+ years of hands-on threat-hunting experience across endpoint, identity, email, network, and cloud telemetry.

    • Experience developing and tuning detection logic, security policies, alert thresholds, exclusions, allow/block rules, indicators, and automated response actions.

    • Strong experience investigating endpoint, identity, and email threats using process trees, command lines, hashes, URLs, domains, IP addresses, message headers, authentication events, and user activity.

    • Experience with Microsoft Entra ID / Azure Active Directory security, including authentication events, sign-in risk, Conditional Access, Identity Protection, MFA, and identity-related incident investigation.

    • Experience using PowerShell or comparable scripting for security administration, investigations, data collection, configuration, and operational automation.

    • Experience creating technical documentation, operational procedures, incident records, threat-hunting reports, security metrics, and remediation recommendations.

    • Experience supporting a large, distributed enterprise environment.

    • Ability to independently perform security administration, investigations, troubleshooting, configuration, threat hunting, and incident response without requiring foundational technical training.
    Key Responsibilities Security Platform Administration & Engineering

    • Serve as a primary hands-on administrator for enterprise security platforms, including Microsoft Defender, Proofpoint, Tessian, Abnormal Security, Palo Alto Cortex, and Tanium.

    • Configure, tune, maintain, troubleshoot, and optimize security policies, rules, integrations, connectors, exclusions, allow/block lists, alerting, and automated actions.

    • Monitor platform health, integrations, agent/sensor status, data flow, utilization, and configuration drift.

    • Identify control gaps, overlapping technologies, conflicting configurations, and opportunities to improve security effectiveness.
    Microsoft Exchange & Email Security

    • Administer and support Exchange Online and enterprise email security technologies.

    • Troubleshoot mail flow, connectors, transport rules, message tracing, quarantine, anti-spam, anti-phishing, impersonation protection, domain controls, and security integrations.

    • Investigate phishing, business email compromise, malicious attachments and links, spoofing, account compromise, and anomalous email activity.

    • Coordinate security configuration and response activities across Microsoft and third-party email security platforms.
    Incident Response

    • Monitor security alerts and actively perform alert triage and incident response.

    • Independently investigate incidents, determine scope and impact, identify affected users and assets, analyze evidence, and recommend or execute approved containment actions.

    • Support endpoint isolation, indicator blocking, malicious email removal, account/session containment, policy changes, and evidence preservation.

    • Perform root-cause analysis and document incident findings, actions taken, residual risks, and corrective recommendations.
    Threat Hunting

    • Conduct proactive, hypothesis-driven threat hunts across endpoint, identity, email, network, and cloud telemetry.

    • Develop queries and investigative techniques to identify suspicious behaviors, persistence, credential abuse, lateral movement, malicious PowerShell or command execution, anomalous authentication, and other indicators of compromise.

    • Document threat-hunting activities, findings, techniques, and recommended improvements.

    • Translate validated findings into improved detections, blocking controls, configuration changes, and incident-response procedures.
    Detection Engineering & Security Optimization

    • Analyze alert quality and detection coverage and tune controls to reduce false positives while maintaining effective detection.

    • Develop, test, document, and maintain detection logic, security policies, indicators, automated response actions, and escalation criteria.

    • Identify security control gaps, integration failures, configuration weaknesses, and operational dependencies.

    • Validate the effectiveness of security configuration and detection changes.
    Documentation & Operational Support

    • Maintain configuration documentation, runbooks, SOPs, troubleshooting guides, and incident-response playbooks.

    • Document material security platform changes and ensure processes are reproducible by authorized personnel.

    • Provide knowledge transfer regarding environment-specific configurations and procedures.

    • Maintain accurate records of completed work, active investigations, incidents, threat hunts, platform issues, risks, and planned actions.

    • Participate in operational, incident, change-management, architecture, and security meetings.

    • Communicate technical information clearly to both technical and non-technical stakeholders.
    Additional Requirements

    • Must be able to work onsite in Tallahassee, Florida, Monday through Friday during standard business hours.

    • Occasional after-hours availability may be required for security incidents, emergency changes, or scheduled maintenance.

    • Must be able to successfully complete required pre-employment/background screening.

    • Candidates should be comfortable working independently within a structured enterprise security environment with established incident-response and change-management procedures.

    Similar Jobs