
Innosoul inc
Hybrid in Tallahassee, Florida • 2d ago
Easy Apply
Third Party, Contract
Depends on Experience
4 results (2 new)

Innosoul inc
Hybrid in Tallahassee, Florida • 2d ago
Easy Apply
Third Party, Contract
Depends on Experience



Job ID: FL-RFQ738
Hybrid/Local Palo Alto Cortex/Tanium Admin with Proofpoint/Tessian/Abnormal Security Admin (all must), Exchange/Entra ID/Active Directory Admin, threat-hunting, PowerShell experience
Location: Tallahassee, FL (DOH)
Duration: 18 Months
5. CONTRACTOR QUALIFICATIONS AND EXPERIENCE:
Contractor staff assigned to this agreement must possess the following minimum qualifications and experience. All experience must be demonstrated in the proposed consultant s resume and candidate
qualification matrix and must be verifiable through prior employment, client references, project history, or other documentation requested by the Department. For purposes of this section, recent means experience performed within the five years immediately preceding submission of the proposed consultant. Hands-on production experience means direct responsibility for configuring, administering, investigating, troubleshooting, and operating a technology in a production enterprise environment. General familiarity, observation, oversight, sales support, training, shadowing, or laboratory-only experience does not satisfy a minimum hands-on experience requirement.
5.1. Seven years of progressively responsible information technology and cybersecurity experience in enterprise environments, including security engineering, security operations, endpoint security, identity security, cloud security, and messaging security.
5.2. Four years of recent hands-on production experience configuring, administering, tuning, investigating and troubleshooting Palo Alto Cortex and Tanium security technologies, including Palo Alto Cortex for Endpoint and Tanium Comply Modules.
5.3. Three years of recent hands-on production experience administering enterprise email security technologies. The proposed consultant must demonstrate hands-on production administration experience with Proofpoint, Tessian, and Abnormal Security. The required three years may consist of combined experience across these technologies, but experience with each named technology is mandatory.
5.4. Three years of recent hands-on Microsoft Exchange Administrator experience, including Exchange Online administration, mail flow, transport rules, connectors, message tracing, anti-spam controls, anti-phishing controls, quarantine, mail routing, and troubleshooting security-related messaging issues.
5.5. Three years of hands-on security incident-response experience, including alert triage, investigation, containment, eradication, recovery, root-cause analysis, and post-incident documentation.
5.6. Two years of hands-on threat-hunting experience using endpoint, identity, email, network, and cloud telemetry to identify malicious or anomalous activity not detected through standard alerting.
5.7. Demonstrated experience developing and tuning detection logic, security policies, alert thresholds, exclusions, allow and block rules, indicators, automated response actions, and other controls to improve detection efficacy and reduce false positives.
5.8. Demonstrated ability to investigate endpoint, identity, and email threats using artifacts such as process trees, command lines, hashes, URLs, domains, IP addresses, message headers, authentication events, user activity, and related telemetry.
5.9. Demonstrated experience with Microsoft Entra ID or Azure Active Directory security, including authentication events, sign-in risk, conditional access, identity protection, multifactor authentication, and identity-related incident investigation.
5.10. Demonstrated experience using PowerShell or comparable scripting to support security administration, investigation, data collection, configuration, and repeatable operational tasks.
5.11. Demonstrated experience creating and maintaining technical configurations, operational procedures, incident records, threat-hunting reports, security metrics, and remediation recommendations suitable for operational and management review.
5.12. Demonstrated experience performing substantially similar services in at least one large, distributed enterprise environment.
5.13. The proposed consultant must be capable of independently performing the services described in this scope of work upon assignment. Independent performance means the ability to execute routine administration, investigation, troubleshooting, configuration, threat hunting, and incident-response activities without requiring Department staff or other contractors to provide basic product instruction, repeated procedural instruction, or continuous technical oversight. Environment-specific orientation, access provisioning, architecture familiarization, Department approval requirements, and Department-specific procedures are not considered foundational technical training.
CONTRACTOR RESPONSIBILITIES:
6.1. SERVICE TASKS: Contractor will perform the following tasks in the time and manner specified by the Department:
6.1.1. Security Platform Administration and Engineering:
6.1.1.1. Serve as a primary hands-on administrator for assigned security platforms, including Microsoft Defender, Proofpoint, Tessian, and Abnormal Security.
6.1.1.2. Directly perform the required platform administration, troubleshooting, configuration, tuning, and investigation activities. The consultant must not routinely defer assigned work to Department staff or other contractors.
6.1.1.3. Configure, tune, maintain, troubleshoot, and optimize policies, rules, integrations, connectors, exclusions, allow and block lists, alerting, automated actions, and other platform settings.
6.1.1.4. Review product health, licensing and utilization, sensor or agent status, integrations, data flow, and configuration drift and remediate identified issues within the consultant s assigned authority.
6.1.1.5. Evaluate platform overlap, control gaps, conflicting configurations, and opportunities to improve security effectiveness and operational efficiency, and provide technically supported recommendations.
6.1.2. Microsoft Exchange and Email Security Administration
6.1.2.1. Perform Microsoft Exchange Administrator duties supporting Exchange Online and the Department s email security architecture.
6.1.2.2. Administer and troubleshoot mail flow, connectors, transport and mail-flow rules, message tracing, quarantine, anti-spam, anti-phishing, impersonation protection, domain controls, and security integrations.
6.1.2.3. Investigate phishing, business email compromise, malicious attachments and links, spoofing, account compromise, and anomalous email behavior across Microsoft and third-party email security platforms.
6.1.2.4. Coordinate configuration and response actions across Proofpoint, Tessian, Abnormal Security, Microsoft Defender, and Exchange Online.
6.1.3. Threat Response and Incident Handling
6.1.3.1. Continuously monitor assigned security work queues during required business hours and provide active security alert triage and incident response.
6.1.3.2. Independently investigate security alerts and incidents, determine scope and impact, identify affected users and assets, collect and analyze evidence, recommend containment actions, and execute Department-approved response actions.
6.1.3.3. Support endpoint isolation, indicator blocking, malicious email removal, account and session containment, policy changes, evidence preservation, and other Departmentapproved response actions.
6.1.3.4. Notify the designated Department supervisor immediately upon identification of a confirmed or suspected critical security incident or material escalation in incident scope or impact.
6.1.3.5. For incidents assigned during required business hours, acknowledge and begin triage of Department-classified Priority 1 or Critical incidents within fifteen minutes, Priority 2 or High incidents within thirty minutes, and other assigned security alerts within four business hours or the Department-assigned timeframe, whichever is sooner.
6.1.3.6. When scheduled or specifically activated for after-hours response, acknowledge the Department s request within thirty minutes and begin response activities as directed.
6.1.3.7. Document incident chronology, evidence reviewed, findings, actions taken, root cause when determinable, residual risk, and recommended corrective actions.
6.1.4. Threat Hunting
6.1.4.1. Conduct no fewer than two documented proactive, hypothesis-driven threat hunts each calendar month across endpoint, identity, email, network, or cloud telemetry, unless the Department directs another quantity or priority based on operational needs.
6.1.4.2. Develop hunt queries and investigative methods to identify suspicious behaviors, persistence, credential abuse, lateral movement, malicious PowerShell or command execution, anomalous authentication, and other indicators of compromise.
6.1.4.3. Each threat hunt must be documented in a Threat-Hunt Report that includes the hypothesis or trigger, data sources reviewed, queries or techniques used, findings, disposition, and recommended detection or control improvements.
6.1.4.4. Translate validated threat-hunting findings into improved detections, blocking controls, configuration changes, incident-response actions, and documented operational procedures.
6.1.5. Detection Engineering and Security Optimization
6.1.5.1. Analyze alert quality and detection coverage and tune security controls to reduce false positives without materially reducing detection capability.
6.1.5.2. Develop, test, document, and maintain detection logic, security policies, indicators, automated response actions, and escalation criteria.
6.1.5.3. Identify control gaps, integration failures, configuration weaknesses, and unsupported operational dependencies and provide prioritized remediation recommendations.
6.1.5.4. Validate the effectiveness of material configuration and detection changes after implementation and document the result.
6.1.6. Operational Documentation and Knowledge Transfer
6.1.6.1. Maintain current configuration documentation, runbooks, standard operating procedures, troubleshooting guides, and incident-response playbooks for assigned platforms.
6.1.6.2. Document Security Platform Configuration and Runbook Updates within five business days after implementation and ensure that the work is reproducible by authorized Department personnel.
6.1.6.3. Provide targeted knowledge transfer to Department staff for environment-specific configurations, procedures, and changes. Knowledge transfer does not replace the Contractor s obligation to provide an independently qualified consultant who directly performs the required services.
6.1.7. Reporting and Service Management
6.1.7.1. Within ten business days after the Department provides the access reasonably necessary to begin work, the Contractor must submit an Initial Operational Readiness Assessment identifying access or integration gaps, assigned platform status, critical operational issues, unresolved incidents, immediate risks, and recommended first actions.
6.1.7.2. Within thirty calendar days after the Department provides the access reasonably necessary to begin work, the Contractor must submit a Security Platform Baseline and Stabilization Plan, which includes an assessment of Palo Alto Cortex, Proofpoint, Tessian, Abnormal Security, and Exchange Online security administration. The plan must identify platform health and configuration concerns, integration gaps, immediate corrective actions, a prioritized operational backlog, and recommended stabilization activities.
6.1.7.3. No later than the fifth business day following each reporting month, the Contractor must submit a Monthly Security Operations Package summarizing platform administration performed, material configuration changes, incidents supported and dispositioned, response-time performance, threat hunts completed, platform-health issues, control improvements, unresolved risks, open technical issues, documentation created or updated and recommended next actions.
6.1.7.4. For significant incidents identified by the Department, the Contractor must submit an initial Significant Incident Summary within two business days after containment and a final Significant Incident Report within five business days after incident closure, unless the Department establishes another timeframe.
6.1.7.5. Maintain accurate Department work records identifying completed work, open incidents, active investigations, threat hunts, platform issues, risks, decisions, and planned actions.
6.1.7.6. Participate in Department operational, incident, change, architecture, and security meetings as directed.
6.1.7.7. Use Department ticketing, change-management, timekeeping, and documentation systems and comply with established security, incident-response, and change-control procedures.
6.1.7.8. Provide clear technical information to technical and non-technical stakeholders and promptly elevate decisions, risks, or access limitations that prevent timely completion of assigned work.
🔢 Crunching numbers...
Tallahassee, Florida
•
Today
Hi, Systems Security SpecialistLocation:Tallahassee, FL (100% On-Site)Key Responsibilities Security Platform AdministrationAdminister and support enterprise security platforms including:Palo Alto CortexMicrosoft DefenderTaniumProofpointTessianAbnormal SecurityConfigure, maintain, troubleshoot, and optimize security controls, policies, alerts, integrations, and automated response actions.Monitor platform health, licensing, agent status, and security effectiveness.Identify control gaps and recom
Easy Apply
Contract
Depends on Experience
Tallahassee, Florida
•
Today
Department This position is within FSU's Department of Information Technology Services (ITS) and National High Magnetic Field Laboratory This position will be located at the National High Magnetic Field Laboratory (NHMFL). The NHMFL is the largest and highest-powered magnet laboratory in the world and is the only facility of its kind in the United States. The Computer Support Group (CSG) supports all aspects of IT at the Lab. Responsibilities This position specializes in the management, security
Full-time
Florida
•
Today
Systems Security Specialist Department of Health (DOH) Location: Tallahassee, FL (100% On-Site) Duration: October 2026 through June 2028 Schedule: Monday-Friday, 8:00 AM to 5:00 PM ET Needs to be 5 days on site in Tallahassee, Florida. Overview The Florida Department of Health is seeking an experienced Systems Security Specialist to support enterprise cybersecurity operations within the Office of Information Technology (OIT). This individual will serve as a primary security administrator
Easy Apply
Contract
$$44/hr on W2
Remote
•
Today
Systems Security Specialist 100% Remote Overview The Florida Department of Health is seeking an experienced Systems Security Specialistto support enterprise cybersecurity operations within the Office of Information Technology (OIT). This individual will serve as a primary security administrator responsible for managing and optimizing critical security platforms while supporting incident response, email security, threat hunting, and cybersecurity operations across a large enterprise enviro
Easy Apply
Contract
$40 - $444