State of Florida

ENGINEERING TEAM LEAD - 72003934

State of Florida$100K — $125K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, or related field; equivalent work experience accepted.
  • 6+ years in cybersecurity engineering or related fields, with progressive responsibilities.
  • 2+ years in leading or mentoring technical staff, managing workloads effectively.
  • Hands-on experience with SIEM detections in a production environment.
  • Experience with structured detection logic frameworks like Sigma.

Responsibilities

  • Lead and manage a diverse cybersecurity engineering team to balance legacy and modern tools.
  • Execute operational and improvement activities on time and within scope.
  • Oversee the lifecycle management of SIEM detections from creation to retirement.
  • Validate and tune security telemetry for effective incident response and investigation.
  • Drive the modernization of SOC tools while maintaining current operational workflows.

Benefits

  • Opportunity for professional development and growth in a leading-edge tech environment.
  • Engaged in cutting-edge cybersecurity projects impacting state security.
  • Work within a collaborative team culture that prioritizes continuous improvement.
  • Access to benefits such as healthcare, retirement plans, and professional certifications.
Full Job Description
Requisition No: 883825

Agency: Management Services



Pay Plan: SES

Position Number: 72003934

Salary: $100,000 - $125,000

Posting Closing Date: 09/30/2026

Total Compensation Estimator Tool

Engineering Team Lead
Florida Digital Service
State of Florida Department of Management Services
This is an in-office position located in Tallahassee, FL

The Engineering Team Lead provides technical leadership and operational oversight for the cybersecurity engineering team responsible for supporting, developing, and sustaining the enterprise security tooling that enables SOC operations. This role ensures the reliability, availability, and effectiveness of security platforms, data pipelines, and telemetry sources used for threat detection, analysis, and incident response.

The Engineering Team Lead is accountable for the technical correctness, performance, and operational value of enterprise SIEM detections and supporting telemetry pipelines. This role requires deep hands-on expertise in detection engineering, telemetry selection, and data quality management to ensure that SOC operations receive only the data required for effective detection, investigation, and response. The Engineering Team Lead must be capable of directly tuning, validating, and troubleshooting detections and telemetry flows across environments.

The Engineering Team Lead is responsible for supporting SOC tool modernization by developing engineering capability, operational processes, and technical readiness necessary, while sustaining current operational requirements and advancing the organization toward the target-state architecture.

DUTIES & RESPONSIBILITIES
Leadership and Team Management
  • Lead a cybersecurity engineering team with varying technical skill sets, balancing legacy platform support with the development of modern security engineering capabilities.
  • Ensure timely execution of assigned operational, project, and improvement activities.
  • Manage task assignments, workloads, and priorities to ensure effective delivery of engineering support for SOC operations and enterprise initiatives.
  • Mentor and develop engineering staff by providing technical guidance, performance feedback, and opportunities to build depth across security platforms and technologies.


Security Tooling and Platform Management
  • Lead strategy and execution for the enterprise SOC tool stack, including SIEM, data lake, SOAR, detection, and threat intelligence platforms.
  • Own the technical lifecycle of SIEM detections, including creation, validation, tuning, versioning, deployment, and retirement, ensuring detections function as intended in production.
  • Ensure that security telemetry ingested from the Security Lake into the SIEM is intentionally scoped, operationally necessary, and optimized for detection and investigation use cases.
  • Support and maintain existing enterprise security consoles and centrally managed security solutions while planning and executing the transition to modernized, integrated SOC platforms.
  • Evaluate telemetry sources for signal value, redundancy, cost, and analytic usefulness, and remove or suppress data that does not materially support SOC operations. Ensure high availability, performance, and reliability of security tooling and supporting infrastructure.
  • Oversee ingestion and retention of security telemetry to ensure data completeness, accuracy, and usability.
  • Validate telemetry fidelity and data quality to support effective detection, analytics, and threat-hunting activities.


Detection Engineering and Telemetry Knowledge
  • Advanced knowledge of SIEM detection engineering concepts, including correlation logic, thresholds, suppression, enrichment, and performance impacts.
  • Strong understanding of security telemetry sources across endpoint, identity, network, cloud, and application domains and their relevance to detection use cases.
  • Knowledge of structured detection rule frameworks, including Sigma, and how abstract detection logic maps to platform-specific implementations.
  • Understanding of how data volume, latency, and quality affect SOC detection accuracy and investigative effectiveness.


Engineering Operations and Execution
  • Direct day-to-day engineering operations supporting SOC detection, response, and analytic workflows.
  • Manage configuration, integration, and lifecycle activities for security tools, ensuring alignment with enterprise architecture standards and security requirements.
  • Support troubleshooting, root-cause analysis, and remediation of tooling, data, or integration issues impacting SOC operations.
  • Coordinate engineering participation in incident response activities where tooling, telemetry, or platform expertise is required.


Coordination and Collaboration
  • Coordinate with the SOC Manager to understand analyst requirements and ensure engineering efforts support operational workflows and priorities.
  • Partner with the Enterprise Architecture Team Lead to ensure engineering implementations align with approved architecture standards and modernization initiatives.
  • Collaborate with other cybersecurity, IT, and data teams to support enterprise integrations, interoperability, and modernization objectives.
  • Participate in cross-functional projects, providing engineering expertise while respecting the priorities and constraints of partner teams.


Process Improvement and Maturity
  • Drive continuous improvement of engineering processes, tooling reliability, and operational support models.
  • Identify gaps in detection coverage, telemetry, or tooling capabilities and propose technical solutions in coordination with architecture and SOC leadership.
  • Support development and maintenance of engineering documentation, runbooks, and standard operating procedures.
  • Contribute to SOC and enterprise cybersecurity maturity initiatives by improving platform resilience, scalability, and analytic enablement.

*Other duties as assigned.

Knowledge, skills, and abilities, including utilization of equipment, required for the position:

Knowledge
  • Enterprise cybersecurity engineering principles including the design, implementation, and operation of security platforms that support SOC detection, analytics, and incident response workflows.
  • Security tooling architectures and technologies, including SIEM, data lakes, SOAR, detection engineering platforms, and threat intelligence systems.
  • Security telemetry sources, detection engineering concepts, analytic workflows, and the technical dependencies required to support effective threat detection and hunting.
  • Systems security management practices related to availability, reliability, performance, and resilience of security platforms and supporting infrastructure.
  • Incident response processes and the role of engineering support during investigations, containment, and recovery activities.
  • Documentation, configuration management, and operational support practices used to sustain complex security platforms over time.
  • Modernization concepts relevant to cybersecurity engineering, including platform consolidation, automation, scalability, and interoperability.


Skills
  • Designing, implementing, tuning, and validating SIEM detections using structured detection logic.
  • Authoring, reviewing, and operationalizing Sigma rules and adapting them to enterprise environments and tooling constraints.
  • Analyzing detection performance using quantitative metrics such as alert volume, false positive rates, and coverage by telemetry source.
  • Leading and mentoring cybersecurity engineers.
  • Directing engineering priorities, assigning tasks, and managing workloads to support SOC operations, enterprise initiatives, and improvement activities.
  • Designing, implementing, configuring, and maintaining security platforms and integrations that enable detection, analytics, and incident response.
  • Troubleshooting complex technical issues involving security tools, telemetry pipelines, data quality, and system integrations.
  • Validating telemetry fidelity and detection enablement to ensure SOC analysts can effectively perform alert triage, threat hunting, and investigations.
  • Coordinating engineering support for SOC operations, including participation in incident response activities requiring platform or tooling expertise.
  • Developing and maintaining technical documentation, runbooks, and standard operating procedures for engineering operations and platform support.
  • Identifying technical risks, or inefficiencies in tooling and proposing practical engineering solutions.


Abilities
  • Balance current-state operational demands with long-term modernization objectives in a transitioning engineering and SOC environment.
  • Ensure the reliability, availability, and performance of security tooling while evolving platform capabilities and integrations.
  • Translate SOC operational needs and analyst workflows into effective engineering solutions.
  • Independently tune detections and telemetry pipelines to support evolving SOC operational needs.
  • Make data-driven decisions about which telemetry sources should or should not be forwarded into the SIEM.
  • Execute engineering work in alignment with enterprise architecture standards while supporting iterative improvement and innovation.
  • Foster effective collaboration across organizational boundaries while respecting differing priorities and constraints.
  • Anticipate emerging technical requirements and prepare engineering capabilities to support future detection, analytics, and response needs.
  • Drive continuous improvement of engineering processes, support models, and platform resilience to advance SOC and enterprise cybersecurity maturity.


MINIMUM QUALIFICATIONS
  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related field; equivalent professional experience may be considered in lieu of a degree.
  • 6+ years of progressively responsible experience in cybersecurity engineering, security operations engineering, or related technical roles supporting enterprise security platforms.
  • At least 2 years' experience developing or following engineering processes related to change management, configuration management, or operational support.
  • At least 2 years of experience leading, mentoring, or coordinating technical staff, including task prioritization and workload management.
  • Demonstrated experience designing, implementing, configuring, or maintaining security tooling such as SIEM, SOAR, security data platforms, detection systems, or threat intelligence platforms.
  • Demonstrated hands-on experience developing, tuning, and maintaining SIEM detections in a production SOC environment.
  • Experience authoring or operationalizing Sigma rules or equivalent structured detection logic.
  • Demonstrated experience selecting, filtering, or optimizing security telemetry to support detection and investigation outcomes.
  • Experience collaborating with cross-functional teams to support incident response, platform integration, or modernization initiatives.
  • Strong written and verbal communication skills sufficient to provide technical guidance to internal teams and enterprise stakeholders.
  • Relevant professional certifications such as CISSP, CCSP, cloud security certifications, or equivalent, preferred.


Other job-related requirements for this position:

Criminal background investigation including fingerprinting and statewide and national criminal history records check per Section 110.1127 Florida Statutes, Chapter 435 Florida Statutes, and the Federal Bureau of Investigation's CJIS Security Policy CJISD-ITS-DOC-08140-4.5

Ability to sit for extended periods of time. Ability to stand for extended periods of time. Ability to drive and/or fly for long distances. Ability to lift, push and pull up to 30lbs.

About State of Florida

The State of Florida is a state located in the southeastern region of the United States. It is the third-most populous state and the 22nd largest by area. The state capital is Tallahassee and its largest city is Jacksonville. Florida is known for its warm climate, beautiful beaches, and tourist attractions such as Walt Disney World, Universal Studios, and the Kennedy Space Center. The state is also home to a number of universities and colleges, including the University of Florida, Florida State University, and the University of Miami.
Learn more about State of Florida

Similar Jobs

More Jobs at State of Florida

More Information Technology Jobs

Find similar ENGINEERING TEAM LEAD - 72003934 jobs: