CYBERSECURITY OPERATIONS CENTER ANALYST
State of FloridaAbout the role
Requisition No: 859787
Agency: Management Services
Working Title: CYBERSECURITY OPERATIONS CENTER ANALYST
Pay Plan: Career Service
Position Number: 72003970
Salary: $45,000 - $90,000
Posting Closing Date: 09/09/2025
Total Compensation Estimator Tool
Cybersecurity Operations Center Analyst
Florida Digital Service
State of Florida Department of Management Services
This position is located in Tallahassee, FL
The Cybersecurity Operations Center (CSOC) Analyst supports real-time cybersecurity monitoring, detection, and incident response for Florida’s state enterprise. Leveraging centralized telemetry, the CSOC Analyst identifies, analyzes, and responds to threats across multiple platforms, ensuring the protection of state systems and data.
This role is critical in correlating threat intelligence, validating alerts, supporting investigations, and collaborating with detection engineering and incident response teams to improve Florida’s cyber defense
DUTIES & RESPONSIBILITIES
• Monitor, analyze, and respond to security events from SIEM, EDR, IDS/IPS, DNS, firewall, cloud, and identity sources.
• Triage and prioritize alerts, escalating incidents per CSOC procedures and incident response playbooks.
• Correlate security telemetry with threat intelligence and behavioral analytics to identify anomalies and malicious activity.
• Provide contextualized threat intelligence to partner agencies and coordinate appropriate response.
• Conduct proactive threat hunting using industy standard query languages.
• Collaborate with detection engineering to validate alerts and enhance detection rules.
• Document investigations and incident response activities in case management systems.
• Assist in containment, eradication, and recovery efforts during incident response.
• Produce clear incident and investigation reports for both technical and non-technical audiences.
• Stay informed on current cybersecurity threats, tactics, techniques, and procedures (TTPs).
• Participate in after-hours on-call rotations as required.
Knowledge, skills, and abilities, including utilization of equipment, required for the position:
Knowledge of:
• Cybersecurity principles (CIA triad, defense-in-depth, MITRE ATT&CK).
• Incident response lifecycle and NIST SP 800-61 guidance.
• Common attack vectors and detection strategies.
Skills in:
• Log analysis across diverse sources (EDR, SIEM, network appliances, cloud services).
• Security event correlation, enrichment, and alert tuning.
• Using log query languages such as KQL and SQL, and analysis tools such as query engines or search/analytics platforms (e.g., distributed search, indexing, and visualization systems)
Abilities to:
• Follow standard operating procedures and escalate appropriately.
• Communicate clearly in writing and verbally, including documenting investigations.
• Work independently or in a team under high-pressure conditions.
MINIMUM QUALIFICATIONS
Education:
• Associate’s degree in Cybersecurity, Computer Science, or related field OR equivalent combination of education and experience.
Experience:
• 1+ years in a cybersecurity operations, SOC analyst, or related role.
• Hands-on experience with SIEM tools (e.g., Splunk, Sentinel, Google SecOps OpenSearch, etc.), EDR, or firewall logs.
• Familiarity with cloud platforms and log query languages (KQL, SQL, etc.)
Certification:
• CompTIA Security+ (required within 12 months of hire).
Other:
• Eligible to work in the U.S. without sponsorship.
• Ability to participate in on-call rotation and occasional after-hours work
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s