Requisition No: 882525
Agency: Management Services
Pay Plan: Career Service
Position Number: 72004161
Salary: $70,000 - $105,000.00
Posting Closing Date: 09/08/2026
Total Compensation Estimator ToolCybersecurity Operations Center AnalystFlorida Digital ServiceState of Florida Department of Management ServicesThis is an in-office position located in Tallahassee, FLPosition Overview and Responsibilities:The Cybersecurity Operations Center (CSOC) Analyst supports real-time cybersecurity monitoring, detection, and incident response for Florida's state enterprise. Leveraging centralized telemetry, the CSOC Analyst identifies, analyzes, and responds to threats across multiple platforms, ensuring the protection of state systems and data.
This role is critical in correlating threat intelligence, validating alerts, supporting investigations, and collaborating with detection engineering and incident response teams to improve Florida's cyber defense
Key Responsibilities:- Monitor, analyze, and respond to security events from SIEM, EDR, IDS/IPS, DNS, firewall, cloud, and identity sources.
- Triage and prioritize alerts, escalating incidents per CSOC procedures and incident response playbooks.
- Correlate security telemetry with threat intelligence and behavioral analytics to identify anomalies and malicious activity.
- Provide contextualized threat intelligence to partner agencies and coordinate appropriate response.
- Conduct proactive threat hunting using industry standard query languages.
- Collaborate with detection engineering to validate alerts and enhance detection rules.
- Document investigations and incident response activities in case management systems.
- Assist in containment, eradication, and recovery efforts during incident response.
- Produce clear incident and investigation reports for both technical and non-technical audiences.
- Stay informed on current cybersecurity threats, tactics, techniques, and procedures (TTPs).
- Other related duties as required.
Knowledge, Skills and Abilities:Knowledge of:- Cyber Threat Intelligence analysis and production methods.
- Cybersecurity principles (CIA triad, defense-in-depth, MITRE ATT&CK).
- Alert tuning and detection engineering.
- Cyber Threat Hunting methodology, hypothesis driven threat hunting.
- Incident response lifecycle and NIST SP 800-61 guidance.
- Common attack vectors and detection strategies.
Skills in: - Log analysis across diverse sources (EDR, SIEM, network appliances, cloud services).
- Cyber Threat Intelligence analysis and production methods.
- Alert tuning and detection engineering.
- Security event correlation, enrichment, and alert tuning.
- Using log query languages such as KQL and SQL, and analysis tools such as query engines or search/analytics platforms (e.g., distributed search, indexing, and visualization systems)
Abilities to: - Follow standard operating procedures and escalate appropriately.
- Write clearly, specifically in the context of threat intelligence and threat analysis.
- Communicate clearly in writing and verbally, including documenting investigations.
- Work independently or in a team under high-pressure conditions.
Minimum Qualifications:Education:
- Associate's degree in Cybersecurity, Computer Science, or related field OR equivalent combination of education and experience.
Experience: - 3+ years in a cybersecurity operations, SOC analyst, or related role.
- Hands-on experience with SIEM tools (e.g., Splunk, Sentinel, Google SecOps OpenSearch, etc.), EDR, or firewall logs.
- Familiarity with cloud platforms and log query languages (KQL, SQL, etc.), Threat Intelligence Platforms.
Certification: - CompTIA Security+ (required within 12 months of hire).
Other Requirements: - Eligible to work in the U.S. without sponsorship.
- Ability to participate in on-call rotation and occasional after-hours work
PREFERRED QUALIFICATIONS - Bachelor's degree in Cybersecurity, Computer Science, or related discipline.
- Cloud security certifications (Microsoft Azure, Amazon AWS).
- SANS GCTI (Cyber Threat Intelligence)
- Experience in government, public sector, or regulated environments.
- Hands-on threat hunting and behavioral analytics experience.
On-Call Assignment - This position has been approved in accordance with Section 110.209, Florida Statutes, Chapter 60L-32, Florida Administrative Code, and Collective Bargaining Agreements with the Florida Nurses Association (FNA) and the American Federation of State, County, and Municipal Employees (AFSCME), Florida Council 79. The approved On-Call form has been forwarded to the servicing human resource office.
Criminal background investigation including fingerprinting and statewide and national criminal history records check per Section 110.1127 Florida Statutes, Chapter 435 Florida Statutes, and the Federal Bureau of Investigation's CJIS Security Policy CJISD-ITS-DOC-08140-4.5
Ability to sit for extended periods of time. Ability to stand for extended periods of time. Ability to drive and/or fly for long distances. Ability to lift, push and pull up to 30lbs.
Pursuant to F.S. 215.422 every officer or employee who is responsible for the approval or processing of vendors' invoices or distribution of warrants to vendors are mandated to process, resolve, and comply as section 215.422 requires.
Location: