JOBSEARCHER

SECURITY ANALYST (ADVANCED)

ARCHIVED

We can't find an active application page for this role right now. It may reopen or be listed elsewhere. Use Next Steps to search for an active apply link and similar live jobs.

Tasks and Activities The resource (Advanced, Security Analyst) will be responsible for providing daily support for the Department's information security infrastructure as part of the Office of Enterprise Security Management's security team, including working with other teams in the Department's Information Systems Administration (ISA), as well as the Florida Digital Services (FLDS) staff, providing Tier 3 information security support for the customers served by the Department. This resource in this position may also be assigned other deliverables, tasks, and projects as needed in support of cybersecurity operations. The resource will report directly to the Department's Information Security Officer and shall perform, at a minimum, the tasks and/or activities described below: a. Work with the Department's Contract Manager to serve as the primary point of contact to ensure that start-up activities are completed within fourteen (14) days prior to the performance of services. Start-up activities include Department's fingerprint background check and online information security training security requirements. b. Assist with implementing, tuning, and planning regarding the Department's Managed Security Service Provider (Client), Security Information and Event Management (SIEM) and vulnerability management. c. Assist in the support of enterprise vulnerability management to identify, classify, and work with technology staff on remediation paths and plans. d. Assist in the support of Distributed Denial of Services (DDoS) protection services utilized by the Department. e. Support and maintain endpoint detection and response (MDR/XDR) tools. f. Analyze, troubleshoot and resolve issues with the NextGen Antivirus solutions on servers and client systems.; g. Monitoring of Intrusion Detection / Intrusion Prevention systems (IDS/IPS) for cybersecurity threats and advise or participate in response actions.; h. Monitoring of Data Loss Prevention solutions, tuning, and response actions.; i. Monitoring of Network Access Control solution, tuning and response actions.: j. Monitoring of Email Security solutions, tuning, and response actions.: k. Support the administration of multi-factor authentication solution and initiatives. l. Support and perform as a technical member of the Computer Security Incident Response Team (CSIRT). m. Develop and maintain technical specifications, standards, procedures, and systems documentation, including Systems Security Plans (SSPs). n. Research and recommend appropriate technical solutions to meet Department requirements; o. Provide recommendations for potential process improvements for the Office of Enterprise Security Management's security team. p. Attend and participate in all assigned meetings; q. Attend and complete Department required training; and r. Complete a Project Status Report and a Project Timesheet on a weekly basis, as indicated below in sub-section 3. Required Source Documentation/Reports. Knowledge, Skills, and Abilities (KSA's) Experience: " At a minimum, we are seeking a candidate with (5) years of combined IT and security / cybersecurity work experience with a broad range of exposure to system analysis, operational experience with cybersecurity infrastructure, with (3) years or more of direct experience with information security. " This position requires knowledge of cybersecurity / security issues, vulnerability management, networking, firewall management and cloud-based security tools across a variety of computing platforms. " The candidate will be able to work independently and as a team member on multiple security projects, and occasionally as a cybersecurity lead on large complex security initiatives and projects that require increased skill in multiple IT functional areas. Education: " Bachelor's degree in Computer Science, Information Systems, Business Administration, or related field, or equivalent work experience. " Information Security related certifications (ex. CISSP, CISM, CISA, CompTIA Advanced Security Practitioner etc.) are desirable. Preferred KSA's: " 5+ years of combined IT and security cybersecurity work experience " 3+ years or more of direct information security / cybersecurity experience " 3+ years of experience with vulnerability management systems " Experience maintaining and supporting 3rd party anti-virus, EDR/MDR.XDR systems " Experience with monitoring IDS/IPS systems " Experience with SIEM products and systems " Experience with cloud-based email security solutions " Experience with Incident Response " Experience with Identify and advanced authentication (MFA) solutions