Haystack
← Back to Jobs
Administrative
AC

Systems Security Specialist

Avenue Code, LLCTallahassee, FL🇺🇸United StatesPosted Sep 22, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Tallahassee, FL, United States
Posted
Yesterday

Job Description

Systems Security Specialist Tallahassee , Florida 

Seeking a Systems Security Specialist who will Serve as the primary hands-on administrator for assigned security platforms, including Microsoft Defender, Proofpoint, Tessian, Abnormal Security, Palo Alto Cortex, and related security technologies. Additionally:
  • Directly configure, maintain, tune, troubleshoot, and optimize policies, rules, integrations, connectors, exclusions, allow/block lists, alerts, automated actions, and other platform settings.
  • Monitor platform health, licensing and utilization, sensors/agents, integrations, data flow, and configuration drift.
  • Identify and remediate operational issues, control gaps, conflicting configurations, integration failures, platform overlap, and opportunities to improve security effectiveness and operational efficiency.
  • Perform Microsoft Exchange Administrator duties supporting Exchange Online and the Department's email security architecture, including mail flow, connectors, transport/mail-flow rules, message tracing, quarantine, anti-spam, anti-phishing, impersonation protection, domain controls, and integrations with Microsoft Defender, Proofpoint, Tessian, and Abnormal Security.
  • Investigate phishing, business email compromise, malicious attachments and links, spoofing, account compromise, and anomalous email activity.
  • Coordinate investigation, configuration, containment, and remediation actions across Microsoft and third-party email security platforms.
  • Continuously monitor assigned security work queues during required business hours and independently triage and investigate security alerts and incidents. Determine scope and impact, identify affected users and assets, analyze evidence, recommend containment measures, and execute Department-approved response actions, including endpoint isolation, indicator blocking, malicious email removal, account/session containment, and policy changes.
  • Immediately notify the designated Department supervisor of confirmed or suspected critical incidents or material escalations. During required business hours, acknowledge and begin triage within: 15 minutes: Priority 1/Critical incidents, 30 minutes: Priority 2/High incidents, 4 business hours: Other assigned security alerts, or within the Department-assigned timeframe, whichever is sooner, and when specifically activated for after-hours response, acknowledge the request within 30 minutes and begin response activities as directed.
  • Maintain complete incident documentation, including chronology, evidence reviewed, findings, actions taken, root cause when determinable, residual risk, and recommended corrective actions.
  • For Department-designated significant incidents, provide an initial Significant Incident Summary within two business days after containment and a final Significant Incident Report within five business days after incident closure, unless otherwise directed.
  • Conduct at least two documented, hypothesis-driven threat hunts per calendar month across endpoint, identity, email, network, or cloud telemetry.
  • Develop queries and investigative techniques to identify suspicious activity, including persistence, credential abuse, lateral movement, malicious command or PowerShell execution, anomalous authentication, and other indicators of compromise.
  • Document each threat hunt, including the hypothesis/trigger, data sources, queries or techniques, findings, disposition, and recommended improvements.
  • Translate validated findings into improved detections, blocking controls, configuration changes, incident-response actions, and operational procedures.
  • Analyze alert quality and detection coverage; develop, test, tune, and maintain detection logic, policies, indicators, automated response actions, and escalation criteria.
  • Reduce false positives without materially reducing detection capability and validate the effectiveness of material configuration or detection changes after implementation.
  • Maintain current platform configuration documentation, runbooks, standard operating procedures, troubleshooting guides, and incident-response playbooks.
  • Document material Security Platform Configuration and Runbook Updates within five business days of implementation and provide targeted knowledge transfer so authorized Department personnel can reproduce and support established procedures.
  • Conduct initial operational and security platform assessments, delivering an Operational Readiness Assessment within 10 business days and a Security Platform Baseline and Stabilization Plan within 30 calendar days of receiving necessary access, documenting platform status, risks, configuration and integration gaps, corrective actions, and prioritized stabilization recommendations.
  •  Maintain accurate Department work records covering completed work, open incidents, active investigations, threat hunts, platform issues, risks, decisions, and planned actions.
  • Use Department ticketing, change-management, timekeeping, and documentation systems and comply with established security, incident-response, and change-control procedures.
  • Participate in Department operational, incident, change, architecture, and security meetings as directed.
  • Clearly communicate technical information to technical and non-technical stakeholders and promptly escalate risks, decisions, dependencies, or access limitations that could prevent timely completion of assigned work.

Similar jobs