Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Security Analyst

EXOS

The Cybersecurity Analyst III at EXOS CYBER is the senior technical escalation point of the SOC — the final analyst-tier authority on the hardest, most ambiguous investigations before a case moves into engineering. When Tier 2 has driven an alert as far as standard playbooks and queries allow and still doesn't have a confident answer, it comes to you. You own confirmed, significant incidents end to end across our client environments. You will support day-to-day security operations for our clients with a primary focus on advanced detection, incident response, and threat hunting, working alongside our Cybersecurity Engineers, and Team Lead. Beyond the queue, you set the bar for investigation quality across the SOC. You QA escalations, mentor and develop Tier 1 and Tier 2, build out the investigation curriculum, and partner with engineering on detection strategy at the program level, not just one noisy rule at a time. This is a hands‑on, deeply technical role designed for analysts with 5+ years of experience (or 2+ years past Tier 2) who are ready to operate as the senior individual contributor in a real‑world MSSP detection‑and‑response practice spanning across a diverse client environments. Serve as the Tier 3 technical escalation point in the SOC. Take the incidents that Tier 2 cannot fully resolve, drive them to a definitive answer, and hand only genuinely engineering‑scoped or architecture‑level problems to the Cybersecurity Engineers and Team Lead with a clear, evidence‑backed recommendation and a proposed course of action. Lead confirmed true‑positive incidents end to end across client environments including but not limited to ransomware, business email compromise, account takeover, lateral movement, and data exfiltration including scoping and impact assessment, containment orchestration via SentinelOne, account isolation and credential rotation in Entra ID, eradication and recovery guidance, evidence preservation, root‑cause analysis, and client communication through resolution. Own and run the proactive threat hunting program: develop hypothesis‑driven hunts across the client base using various queries, EDR telemetry, and indicators from CTI feeds; document findings; and feed confirmed patterns back into detection engineering as durable, reusable detections. Perform host, memory, and network forensics (Velociraptor, endpoint and identity artifacts, timeline reconstruction) to establish what happened, when, and how far it went, and to support breach‑notification and legal/insurance coordination when an incident warrants it. Conduct phishing triage and support email‑based threat investigations, including user impact assessment and remediation steps. Partner with the Cybersecurity Engineers and AI Automation Engineer on detection strategy at the program level coverage and gap analysis against MITRE ATT&CK, detection content design, and false‑positive reduction across the fleet rather than one‑off alert tuning. Apply offensive and adversary‑emulation knowledge to inform detection coverage, and support purple team and adversary‑emulation exercises by translating attacker TTPs into detections and validating that controls fire as expected. Analyze endpoint, identity, and network telemetry to identify suspicious activity, lateral movement, and persistence, and lead phishing and email‑based threat investigations through full user‑impact assessment and remediation. Set and enforce investigation quality standards: QA Tier 1 and Tier 2 escalations and case documentation, run walk‑throughs of significant investigations, give kind and direct feedback, and own the Tier 1/Tier 2 onboarding and skills‑development curri Author the analytical narrative for the most complex client deliverables, post‑incident reports, after‑action reviews, and the senior‑analyst portion of monthly client reporting covering what we saw, what it means, and what we recommend, in language a client technical stakeholder can act on. Drive SOC operational maturity by shaping runbook and playbook architecture, investigation checklists, and repeatable workflows, and by mentoring the team toward consistent, defensible outcomes Must Haves 5+ years of experience in a SOC, incident response, MSSP, or security operations role, or 2+ years past a Tier 2 / Analyst II role in a comparable environment. Demonstrated ability to independently lead complex investigations and confirmed incidents to resolution across endpoint, identity, email, and network telemetry — not just triage and elevate. Advanced command of an EDR (SentinelOne, CrowdStrike, or Defender for Endpoint) and a SIEM (Blumira, Sentinel, Splunk, or QRadar) at the query, pivot, and detection‑authoring level. Practical host and network forensics and evidence‑preservation experience, including timeline reconstruction across Windows event logs, Active Directory, Entra ID, firewall, VPN, DNS, and email security logs. Hands‑on proactive threat hunting experience: building and executing hypothesis‑driven hunts and converting findings into detections. Proficient scripting in PowerShell and/or Python for investigation, log parsing, and automation. Working fluency with the MITRE ATT&CK framework for both investigation and detection‑coverage mapping. Strong command of the incident response lifecycle, escalation criteria, and chain‑of‑custody / evidence‑handling practices. Ability to lead under pressure in a multi‑client environment, prioritize across simultaneous active incidents, and maintain quality and clear documentation throughout. Excellent written communication, with the ability to produce client‑ready incident summaries, post‑incident reports, and analytical narratives, and to mentor junior analysts effectively. Solid fundamentals in TCP/IP, DNS, Windows and Linux internals, and identity and access management. Relevant certifications such as CompTIA CySA+, GIAC GCIH/GCIA/GCFA, BTL2, or equivalent demonstrated experience. Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline. Equivalent military training or certifications considered. Advanced certifications such as GIAC GCIA, GCFA, GCFE, GNFA, GCTI, GREM, or BTL2; offensive‑informed credentials (OSCP, CRTO) a strong plus given the role's detection and purple‑team‑support scope. Prior MSSP experience in a multi‑tenant model, including a multi‑tenant PSA/ticketing platform (ConnectWise, Autotask, ServiceNow, or similar). Detection engineering experience: Sigma rules, KQL, and SentinelOne / Blumira query syntax, plus comfort building detections from hunt findings. Experience with SOAR or rules‑based automation and operationalizing playbooks alongside an AI Automation Engineer. DFIR tooling depth (Velociraptor or comparable) and experience supporting legal, insurance, and breach‑notification workflows during major incidents. Vulnerability management and offensive‑output review experience (ConnectSecure, Tenable, Qualys; NodeZero or comparable pentest/attack‑path findings). Experience mentoring or formally developing junior analysts and building SOC training content. #J-18808-Ljbffr

Vacancy posted 4 hours ago
Similar jobs that could be interesting for youBased on the Cyber Security Analyst in Indianapolis, IN vacancy
  • $69.4k - $158k

    Job Number: R0243018 Cyber Security Analyst The Opportunity As a security operations center analyst, you're in the middle of the action, responding to and mitigating threats in real time. You're the first line of cyber defense for your organization, and they look to... 
    Suggested
    Work at office
    Local area
    Remote work
    Shift work

    Phase2 Technology

    Indianapolis, IN
    5 days ago
  •  ...including at a network of Eskenazi Health Center sites located throughout Indianapolis. FLSA Status Exempt Job Role Summary The Cyber Security Analyst position is a results-oriented position that has day-to-day hands-on experience with all levels of access including entry... 
    Suggested
    Full time
    Local area
    Flexible hours
    Shift work

    Marion County Public Health Department

    Indianapolis, IN
    2 days ago
  • $102.17k

     ...Trinnex delivers value and impact to public sector clients across the country. Job Description Join the Trinnex Security Team as a Senior Cyber Security Analyst, where you will operate at the intersection of cybersecurity and DevSecOps to protect critical software... 
    Suggested
    H1b

    CDM Smith

    Indianapolis, IN
    2 days ago
  • $102.17k - $178.78k

    Trinnex is hiring a Senior Cyber Security Analyst to safeguard critical software systems supporting water utilities. The analyst will work at the intersection of cybersecurity and DevSecOps to ensure applications are resilient against threats. This position involves advanced... 
    Suggested

    Trinnex

    Indianapolis, IN
    2 days ago
  • $83.44k - $125.16k

    Anticipated End Date: 2026-08-10 Position Title: Systems Analyst Senior Job Description: Systems Analyst Senior Location: This role requires associates to be in-office 1-2 days per week, fostering collaboration and connectivity, while providing flexibility to support... 
    Suggested
    Full time
    Temporary work
    Work experience placement
    Work at office
    Local area
    Day shift
    2 days per week
    1 day per week

    Elevance Health

    Indianapolis, IN
    19 hours ago
  •  ...enterprise software architectures that support the bank's information security operations functions. This role performs feedback and...  ...Information Technology security leadership. Assists Security Analysts as an escalation point for security alerts, events, and logs, escalating... 
    Remote work

    WesBanco Bank Inc.

    Indianapolis, IN
    4 days ago
  • $104k - $156k

    Posting Type Remote/Hybrid Job Overview The Advanced Security Engineer is a technically deep, hands-on practitioner who forms the operational backbone of the enterprise security function. Operating within a layered defense-in-depth program, this engineer owns the design... 
    Remote work

    Relativity

    Indianapolis, IN
    1 day ago
  • $73.45k - $132.78k

     ...issues within Microsoft Intune-managed environments, while also operating effectively across desktop support, endpoint management, security compliance, and network-related challenges. You will be expected to move fluidly across technical domains. This means owning... 
    Full time

    Leidos

    Indianapolis, IN
    19 hours ago
  •  ...Chief Information Security Officer (CISO) About the Company Trusted provider & publisher of consumer insights about car models...  ...CISO) to take on an enterprise-level leadership role in global cyber security, information risk, and resilience. The CISO will be responsible... 

    Confidential

    Indianapolis, IN
    5 days ago
  •  ...Chief Information Security Officer (CISO), Growth About the Company Accomplished provider of top-tier security services Industry Security and Investigations Type Privately Held About the Role The Company is seeking a Chief Information... 

    Confidential

    Indianapolis, IN
    1 day ago
  •  ...Creating Peace of Mind by Pioneering Safety and Security** *At Allegion, we help keep the people...  ...workplace cultures.***The Cybersecurity Analyst** is responsible for proactively and...  ...Understanding of data privacy concerns and cyber security best practices.· Ability to deal... 
    Temporary work
    H1b
    Remote work
    Flexible hours
    Weekend work
    Afternoon shift

    Allegion Canada Inc.

    Carmel, IN
    5 days ago
  • $69.4k - $158k

    Cybersecurity Analyst As a security operations centre analyst, you’re in the middle of the action, responding to and mitigating threats in real time. You’re the first line of cyber defense for your organization, and they look to you for guidance on best practices and security... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work
    Shift work

    Booz Allen Hamilton

    Indianapolis, IN
    5 days ago
  • $69.4k - $158k

    Job Number: R0244031 Cybersecurity Analyst The Opportunity: As a security operations center analyst, you're in the middle of the action, responding to...  ...mitigating threats in real time. You're the first line of cyber defense for your organization, and they look to you for... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work
    Shift work

    Phase2 Technology

    Indianapolis, IN
    3 days ago
  •  ...Epic Application Analyst Must-have skills (minimum 1+ year experience): Epic Cadence, Grand Central, Prelude, Referrals, SER...  ...independently Preferred skills (nice to have): Epic Security knowledge Experience with Epic patient/referral workqueues... 
    Shift work

    ClinDCast LLC

    Indianapolis, IN
    1 day ago
  •  ...standards and structured methodologies. Evaluate existing environments and recommend improvements to performance, reliability, and security. Build strong, trust-based relationships through clear communication and proactive support. Collaborate with peers to drive... 
    Full time

    Designworks Talent LLC

    Indianapolis, IN
    2 days ago
  •  ...thousands of parking professionals. We integrate the best people, processes, and technology to provide powerful, high performance, and secure parking solutions. T2 Systems is headquartered in Indianapolis, Indiana with its Canadian office located in Burnaby, BC. We didn... 
    Work at office
    Remote work

    T2 Systems

    Indianapolis, IN
    5 days ago
  •  ...product and program teams, establishing architectural guardrails, reviewing designs to ensure alignment with target architecture, security, performance, resiliency, and operability standards, supporting both project-centric and product-centric delivery models. Govern integration... 
    For contractors

    AES Corporation

    Indianapolis, IN
    5 days ago
  •  ...Candidate 1. Infrastructure (Data Center Design, Networking, Systems Hardware, System Architecture Virtualization, Systems Management, Security) 2. Platforms (Application Development, Application Design, SDLC, Java, UI, Spring, IDE's, SOA) 3. Desktop (Desktops Architecture,... 
    Work at office

    Anchor Point Technology Resources

    Indianapolis, IN
    4 days ago
  •  ...duplication. Develops reference patterns for serverless, containers, event-driven, integration, and data platforms. Embeds cross-cloud security and compliance controls (identity, encryption, logging, data protection) with Security and Network partners. What’s Needed? Multi-... 

    ManpowerGroup Global, Inc.

    Indianapolis, IN
    1 day ago
  • $150k - $165k

     ...maturing, and hands-on execution of the organization's information security program. Operating across a large enterprise environment of 2,5...  ...Review and triage escalated alerts; serve as a hands-on analyst when needed Maintain and improve SOC playbooks, runbooks, and... 
    Live in
    Remote work

    USIC

    Indianapolis, IN
    24 days ago
  • $150k - $175k

     ...Overview GovCIO is seeking an experienced Enterprise Cloud Architect to design, govern, and evolve enterprise network, cloud, and security-aligned operations supporting 24/7 Network Operations Center (NOC) activities. The role will translate business and security... 
    Full time
    Remote work
    Flexible hours
    Shift work
    Night shift

    GovCIO

    Indianapolis, IN
    4 days ago
  • $150.16k

     ...capabilities and technology investments. This individual will partner closely with business and technology stakeholders to deliver scalable, secure, and integrated solutions across the enterprise application portfolio. Leveraging platforms such as Microsoft Azure, Microsoft 365,... 
    H1b

    CDM Smith

    Indianapolis, IN
    2 days ago
  • $71k

     ...and maintain one. Knowledge in the following areas is preferred National Institute of Standards and Technology (NIST) SP 800‑53, Security and Privacy Controls for Information Systems and Organizations. Government Accountability Office (GAO) Government Auditing Standards... 
    Contract work
    Work experience placement
    Internship
    Work at office
    Flexible hours

    Sikich

    Indianapolis, IN
    1 day ago
  •  ...manage service tasks, track CAPA progress, and coordinate change requests. Collaborate with internal teams to support compliance, security, and continuous improvement initiatives. Qualifications 1-3 years of experience required. Bachelor’s degree in Information... 
    Contract work

    Net2Source (N2S)

    Indianapolis, IN
    5 days ago
  • $144.9k - $265.8k

     ...Implementation Architect and implement identity and authentication solutions using Microsoft Entra, Okta, Ping, Saviynt Design cloud security and IAM architectures for Azure, AWS, GCP, and hybrid environments Implement cloud IAM services (e.g., provisioning,... 
    Work experience placement
    Summer holiday
    Flexible hours

    EY

    Indianapolis, IN
    3 days ago
  •  ...or other confidential customer information that must be protected at all times. All employees must comply with HIPAA and all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy. All employees... 
    Work at office
    Local area
    Remote work

    Highmark Health

    Indianapolis, IN
    4 days ago
  •  ...Metadata API, ChangeSet, and Ant. Best Practices understanding on Coding Standards, Deployment, Apex, VF, Salesforce Integration, Security implementations Experience on Force.com Integration Technologies (WebServices, 3rd Party tool like CastIron/Boomi) to Integrate with... 
    Permanent employment
    Full time
    H1b
    Flexible hours

    SonSoft

    Indianapolis, IN
    14 days ago
  • Get AI-powered advice on this job and more exclusive features. Squadware Inc is hiring a Software Quality Assurance Analyst for a consulting position with one of our clients on the north side of Indianapolis. This role is full time and can be a 1099 contract or w-2 position... 
    Full time
    Contract work
    Remote work
    Relocation

    Squadware Inc

    Indianapolis, IN
    2 days ago
  • $86.45k - $136k

     ...implementations, is preferred. Must be a U.S. citizen with the ability to obtain and maintain a U.S. Department of Energy (DOE) security clearance. Benefits Annual base salary ranging from $86,450 to $136,000, depending on experience, qualifications, location, and... 
    Contract work
    Remote work
    Flexible hours

    Jobgether

    Indianapolis, IN
    7 hours ago
  • $119k - $144k

     ...environment with a strong focus on Cisco routing, Palo Alto firewalls, and secure architectural solutions. In this hands‑on, high‑impact position, you will work on technical troubleshooting efforts, advise analysts, and partner with vendors to drive forward‑looking network... 
    Local area

    MISO Default Brand

    Carmel, IN
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Security Analyst. Be the first to apply!