CYBERSECURITY ENGINEERING MANAGER - 72003934
Requisition No: 884851
Agency: Management Services
Working Title: CYBERSECURITY ENGINEERING MANAGER - 72003934
Pay Plan: SES
Position Number: 72003934
Salary: $100,000 - $125,000
Posting Closing Date: 10/15/2026
Total Compensation Estimator Tool
Cybersecurity Engineering Manager
Florida Digital Service
State of Florida Department of Management Services
This is an in-office position located in Tallahassee, FL
The Cybersecurity Engineering Manager leads the Cybersecurity Engineering section, providing technical leadership and operational oversight for the enterprise security tooling that supports Security Operations Center (SOC) operations. This position is responsible for the reliability, availability, integration, and effectiveness of security platforms, telemetry, and data pipelines used for threat detection, analysis, threat hunting, and incident response.
The position leads the modernization of SOC capabilities by developing engineering processes, technical capabilities, and operational readiness while sustaining current security operations and advancing the organization toward its target-state architecture.
The position supervises, develops, and evaluates employees; assigns and prioritizes work; and ensures effective execution of operational, engineering, and modernization initiatives.
DUTIES & RESPONSIBILITIES
MANAGEMENT AND LEADERSHIP
- Lead and supervise the Cybersecurity Engineering team, balancing operational support, project priorities, and modernization initiatives.
- Assign and prioritize workloads; monitor productivity, quality, attendance, deadlines, and professional conduct.
- Establish goals, delegate assignments, and promote accountability, collaboration, innovation, and continuous improvement.
- Mentor and develop staff through technical guidance, performance feedback, training, and professional development opportunities.
- Conduct performance evaluations and address performance or behavioral issues through appropriate corrective and progressive discipline.
- Lead and support organizational and operational change.
SECURITY TOOLING AND PLATFORM MANAGEMENT
- Lead strategy and execution for the enterprise SOC technology stack, including SIEM, data lake, SOAR, detection, and threat intelligence platforms.
- Maintain and support existing security platforms while planning and executing modernization and integration efforts.
- Ensure the availability, reliability, performance, and security of enterprise security tooling and supporting infrastructure.
- Oversee security telemetry ingestion, retention, and data quality to support effective detection, analytics, and threat hunting.
- Identify and address gaps in tooling, telemetry, detection coverage, and platform capabilities.
ENGINEERING OPERATIONS
- Direct day-to-day engineering operations supporting SOC detection, response, and analytical activities.
- Oversee configuration, integration, maintenance, and lifecycle management of security technologies in accordance with enterprise architecture and security standards.
- Lead troubleshooting, root-cause analysis, and remediation of tooling, telemetry, integration, and platform issues.
- Coordinate engineering support for incident response activities requiring specialized tooling or telemetry expertise.
- Ensure timely execution of operational, project, and engineering improvement activities.
COLLABORATION AND COORDINATION
- Partner with the SOC Manager to align engineering capabilities with analyst requirements, operational workflows, and priorities.
- Collaborate with Enterprise Architecture to ensure engineering solutions align with approved architecture standards and modernization initiatives.
- Coordinate with cybersecurity, IT, data, and other enterprise teams to support integrations, interoperability, and modernization efforts.
- Provide engineering expertise for cross-functional initiatives while coordinating priorities and dependencies with partner teams.
PROCESS IMPROVEMENT AND MATURITY
- Drive continuous improvement of engineering processes, platform reliability, scalability, and operational support.
- Develop and maintain engineering documentation, runbooks, procedures, and technical standards.
- Identify opportunities to improve security tooling, telemetry, detection capabilities, and analytical support.
- Support cybersecurity and SOC maturity initiatives through improved platform resilience, automation, integration, and operational effectiveness.
*Other duties as assigned.
KNOWLEDGE, SKILLS, AND ABILITIES:
KNOWLEDGE
- Enterprise cybersecurity engineering principles including the design, implementation, and operation of security platforms that support SOC detection, analytics, and incident response workflows.
- Security tooling architectures and technologies, including SIEM, data lakes, SOAR, detection engineering platforms, and threat intelligence systems.
- Security telemetry sources, detection engineering concepts, analytic workflows, and the technical dependencies required to support effective threat detection and hunting.
- Systems security management practices related to availability, reliability, performance, and resilience of security platforms and supporting infrastructure.
- Incident response processes and the role of engineering support during investigations, containment, and recovery activities.
- Documentation, configuration management, and operational support practices used to sustain complex security platforms over time.
- Modernization concepts relevant to cybersecurity engineering including platform consolidation, automation, scalability, and interoperability.
SKILLS
- Designing, implementing, tuning, and validating SIEM detections using structured detection logic.
- Authoring, reviewing, and operationalizing Sigma rules and adapting them to enterprise environments and tooling constraints.
- Analyzing detection performance using quantitative metrics such as alert volume, false positive rates, and coverage by telemetry source.
- Leading and mentoring cybersecurity engineers.
- Directing engineering priorities, assigning tasks, and managing workloads to support SOC operations, enterprise initiatives, and improvement activities.
- Designing, implementing, configuring, and maintaining security platforms and integrations that enable detection, analytics, and incident response.
- Troubleshooting complex technical issues involving security tools, telemetry pipelines, data quality, and system integrations.
- Validating telemetry fidelity and detection enablement to ensure SOC analysts can effectively perform alert triage, threat hunting, and investigations.
- Coordinating engineering support for SOC operations, including participation in incident response activities requiring platform or tooling expertise.
- Developing and maintaining technical documentation, runbooks, and standard operating procedures for engineering operations and platform support.
- Identifying technical risks, or inefficiencies in tooling and proposing practical engineering solutions.
ABILITIES
- Balance current-state operational demands with long-term modernization objectives in a transitioning engineering and SOC environment.
- Ensure the reliability, availability, and performance of security tooling while evolving platform capabilities and integrations.
- Translate SOC operational needs and analyst workflows into effective engineering solutions.
- Independently tune detections and telemetry pipelines to support evolving SOC operational needs.
- Make data-driven decisions about which telemetry sources should or should not be forwarded into the SIEM.
- Execute engineering work in alignment with enterprise architecture standards while supporting iterative improvement and innovation.
- Foster effective collaboration across organizational boundaries while respecting differing priorities and constraints.
- Anticipate emerging technical requirements and prepare engineering capabilities to support future detection, analytics, and response needs.
- Drive continuous improvement of engineering processes, support models, and platform resilience to advance SOC and enterprise cybersecurity maturity.
MINIMUM QUALIFICATIONS
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related field; equivalent professional experience may be considered in lieu of a degree.
- 6+ years of progressively responsible experience in cybersecurity engineering, security operations engineering, or related technical roles supporting enterprise security platforms.
- At least 2 years’ experience developing or following engineering processes related to change management, configuration management, or operational support.
- At least 2 years’ of experience leading, mentoring, or coordinating technical staff, including task prioritization and workload management.
- Demonstrated experience designing, implementing, configuring, or maintaining security tooling such as SIEM, SOAR, security data platforms, detection systems, or threat intelligence platforms.
- Demonstrated hands-on experience developing, tuning, and maintaining SIEM detections in a production SOC environment.
- Experience authoring or operationalizing Sigma rules or equivalent structured detection logic.
- Demonstrated experience selecting, filtering, or optimizing security telemetry to support detection and investigation outcomes.
- Experience collaborating with cross-functional teams to support incident response, platform integration, or modernization initiatives.
- Strong written and verbal communication skills are sufficient to provide technical guidance to internal teams and enterprise stakeholders.
- Relevant professional certifications such as CISSP, CCSP, cloud security certifications, or equivalent, preferred.
Other job-related requirements for this position:
Criminal background investigation including fingerprinting and statewide and national criminal history records check per Section 110.1127 Florida Statutes, Chapter 435 Florida Statutes, and the Federal Bureau of Investigation’s CJIS Security Policy CJISD-ITS-DOC-08140-4.5
Ability to sit for extended periods of time. Ability to stand for extended periods of time. Ability to drive and/or fly long distances. Ability to lift, push and pull up to 30lbs.
Our Organization and Mission:
Under the direction of Governor Ron DeSantis, Secretary Tom Berger and DMS’ Executive Leadership Team, the Florida Department of Management Services (DMS) is a customer-oriented agency with a broad portfolio that includes the efficient use and management of real estate, procurement, human resources, group insurance, retirement, telecommunications, fleet, and federal property assistance programs used throughout Florida’s state government. It is against this backdrop that DMS strives to demonstrate its motto, “We serve those who serve Florida.”
Special Notes:
DMS is committed to successfully recruiting and onboarding talented and skilled individuals into its workforce. We recognize the extensive training, experience and transferrable skills that veterans and individuals with disabilities bring to the workforce. Veterans and individuals with disabilities are encouraged to contact our recruiter for guidance and answers to questions through the following provided email addresses:
DMS.Ability@dms.myflorida.com
DMS.Veterans@dms.myflorida.com
An individual with a disability is qualified if he or she satisfies the skills, experience, and other job related requirements for a position and can perform the essential functions of the position with or without reasonable accommodation. Candidates requiring a reasonable accommodation, as defined by the Americans with Disabilities Act, must contact the DMS Human Resources (HR) Office at (850) 488-2707. DMS requests applicants notify HR in advance to allow sufficient time to provide the accommodation.
Criminal background investigation including fingerprinting and statewide and national criminal history records check per Section 110.1127 Florida Statutes, Chapter 435 Florida Statutes and the Federal Bureau of Investigation’s CJIS Security Policy CJISD-ITS-DOC-08140.
Pursuant to F.S. 215.422 every officer or employee who is responsible for the approval or processing of vendors’ invoices or distribution of warrants to vendors are mandated to process, resolve and comply as section 215.422 requires
Candidates requiring a reasonable accommodation, as defined by the Americans with Disabilities Act, must notify the agency hiring authority and/or People First Service Center (1-866-663-4735). Notification to the hiring authority must be made in advance to allow sufficient time to provide the accommodation.
The State of Florida supports a Drug-Free workplace. All employees are subject to reasonable suspicion drug testing in accordance with Section 112.0455, F.S., Drug-Free Workplace Act.
TALLAHASSEE, FL, US, 32399
Nearest Major Market: Tallahassee