Cyber Security Analyst
EXOS
The Cybersecurity Analyst III at EXOS CYBER is the senior technical escalation point of the SOC — the final analyst-tier authority on the hardest, most ambiguous investigations before a case moves into engineering. When Tier 2 has driven an alert as far as standard playbooks and queries allow and still doesn't have a confident answer, it comes to you. You own confirmed, significant incidents end to end across our client environments. You will support day-to-day security operations for our clients with a primary focus on advanced detection, incident response, and threat hunting, working alongside our Cybersecurity Engineers, and Team Lead. Beyond the queue, you set the bar for investigation quality across the SOC. You QA escalations, mentor and develop Tier 1 and Tier 2, build out the investigation curriculum, and partner with engineering on detection strategy at the program level, not just one noisy rule at a time. This is a hands‑on, deeply technical role designed for analysts with 5+ years of experience (or 2+ years past Tier 2) who are ready to operate as the senior individual contributor in a real‑world MSSP detection‑and‑response practice spanning across a diverse client environments. Serve as the Tier 3 technical escalation point in the SOC. Take the incidents that Tier 2 cannot fully resolve, drive them to a definitive answer, and hand only genuinely engineering‑scoped or architecture‑level problems to the Cybersecurity Engineers and Team Lead with a clear, evidence‑backed recommendation and a proposed course of action. Lead confirmed true‑positive incidents end to end across client environments including but not limited to ransomware, business email compromise, account takeover, lateral movement, and data exfiltration including scoping and impact assessment, containment orchestration via SentinelOne, account isolation and credential rotation in Entra ID, eradication and recovery guidance, evidence preservation, root‑cause analysis, and client communication through resolution. Own and run the proactive threat hunting program: develop hypothesis‑driven hunts across the client base using various queries, EDR telemetry, and indicators from CTI feeds; document findings; and feed confirmed patterns back into detection engineering as durable, reusable detections. Perform host, memory, and network forensics (Velociraptor, endpoint and identity artifacts, timeline reconstruction) to establish what happened, when, and how far it went, and to support breach‑notification and legal/insurance coordination when an incident warrants it. Conduct phishing triage and support email‑based threat investigations, including user impact assessment and remediation steps. Partner with the Cybersecurity Engineers and AI Automation Engineer on detection strategy at the program level coverage and gap analysis against MITRE ATT&CK, detection content design, and false‑positive reduction across the fleet rather than one‑off alert tuning. Apply offensive and adversary‑emulation knowledge to inform detection coverage, and support purple team and adversary‑emulation exercises by translating attacker TTPs into detections and validating that controls fire as expected. Analyze endpoint, identity, and network telemetry to identify suspicious activity, lateral movement, and persistence, and lead phishing and email‑based threat investigations through full user‑impact assessment and remediation. Set and enforce investigation quality standards: QA Tier 1 and Tier 2 escalations and case documentation, run walk‑throughs of significant investigations, give kind and direct feedback, and own the Tier 1/Tier 2 onboarding and skills‑development curri Author the analytical narrative for the most complex client deliverables, post‑incident reports, after‑action reviews, and the senior‑analyst portion of monthly client reporting covering what we saw, what it means, and what we recommend, in language a client technical stakeholder can act on. Drive SOC operational maturity by shaping runbook and playbook architecture, investigation checklists, and repeatable workflows, and by mentoring the team toward consistent, defensible outcomes Must Haves 5+ years of experience in a SOC, incident response, MSSP, or security operations role, or 2+ years past a Tier 2 / Analyst II role in a comparable environment. Demonstrated ability to independently lead complex investigations and confirmed incidents to resolution across endpoint, identity, email, and network telemetry — not just triage and elevate. Advanced command of an EDR (SentinelOne, CrowdStrike, or Defender for Endpoint) and a SIEM (Blumira, Sentinel, Splunk, or QRadar) at the query, pivot, and detection‑authoring level. Practical host and network forensics and evidence‑preservation experience, including timeline reconstruction across Windows event logs, Active Directory, Entra ID, firewall, VPN, DNS, and email security logs. Hands‑on proactive threat hunting experience: building and executing hypothesis‑driven hunts and converting findings into detections. Proficient scripting in PowerShell and/or Python for investigation, log parsing, and automation. Working fluency with the MITRE ATT&CK framework for both investigation and detection‑coverage mapping. Strong command of the incident response lifecycle, escalation criteria, and chain‑of‑custody / evidence‑handling practices. Ability to lead under pressure in a multi‑client environment, prioritize across simultaneous active incidents, and maintain quality and clear documentation throughout. Excellent written communication, with the ability to produce client‑ready incident summaries, post‑incident reports, and analytical narratives, and to mentor junior analysts effectively. Solid fundamentals in TCP/IP, DNS, Windows and Linux internals, and identity and access management. Relevant certifications such as CompTIA CySA+, GIAC GCIH/GCIA/GCFA, BTL2, or equivalent demonstrated experience. Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline. Equivalent military training or certifications considered. Advanced certifications such as GIAC GCIA, GCFA, GCFE, GNFA, GCTI, GREM, or BTL2; offensive‑informed credentials (OSCP, CRTO) a strong plus given the role's detection and purple‑team‑support scope. Prior MSSP experience in a multi‑tenant model, including a multi‑tenant PSA/ticketing platform (ConnectWise, Autotask, ServiceNow, or similar). Detection engineering experience: Sigma rules, KQL, and SentinelOne / Blumira query syntax, plus comfort building detections from hunt findings. Experience with SOAR or rules‑based automation and operationalizing playbooks alongside an AI Automation Engineer. DFIR tooling depth (Velociraptor or comparable) and experience supporting legal, insurance, and breach‑notification workflows during major incidents. Vulnerability management and offensive‑output review experience (ConnectSecure, Tenable, Qualys; NodeZero or comparable pentest/attack‑path findings). Experience mentoring or formally developing junior analysts and building SOC training content. #J-18808-Ljbffr
$69.4k - $158k
Cyber Security AnalystThe Opportunity:As a security operations center analyst, you’re in the middle of the action, responding to and mitigating threats in real time. You’re the first line of cyber defense for your organization, and they look to you for guidance on best...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote workShift work- ...ahead, and collaborating to achieve more, together. Come be a part of this journey with us as we champion lives! Job Summary Info Security rep is responsible for supporting OneAmerica's Information Security program through application security, vulnerability management...SuggestedFull timePart timeWork experience placementWork at officeLocal areaRemote workWork from homeFlexible hours
$40k - $55k
...Description Job Description: Title: Cyber Security Analyst – Enterprise Systems (IT) Fully Remote for candidates in EST/CST time zone | Location/Supporting: Longwood, FL | Experience: 2+ years of Cyber Security experience Please note: If this position...SuggestedWork at officeRemote work$134.5k - $265.1k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity.... ...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll...SuggestedLocal area$82.6k - $162.8k
Position Summary Join our Deloitte Cyber team to deliver powerful solutions to help our clients navigate the ever-changing threat... ...resilience, grow with confidence, and proactively manage to secure success. Identity security market is undergoing a fundamental transformation...SuggestedLocal areaVisa sponsorship$155.6k - $306.8k
Position Summary Help clients reduce cyber risk by leading forward deployed engineering work focused on patching, remediation... ...help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices. The Cyber...Local area$105.4k - $207.8k
Position Summary As a Senior Consultant - Cyber Defense and Resilience, you will help deliver security engineering solutions that modernize client security... ...into deployable capabilities that improve analyst efficiency, alert quality, and response speed. Recruiting...Local areaVisa sponsorship$105.4k - $207.8k
Position Summary Join Deloitte’s Cyber practice as a Cyber SecOps Senior Consultant... ...landscape through scalable, resilient security operations solutions. In this hands-on role... ...with security operations center analysts and threat detection engineers to prioritize...Local areaVisa sponsorship$97.61k - $188.38k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity.... ...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 10/31/2026Work you’ll...Local areaVisa sponsorship$105.4k - $207.8k
...As a Full Stack Engineer Senior Consultant in Deloitte Cyber’s Digital Trust & Privacy practice, you will operate at the intersection... ...engineering teams, and communicate effectively with business, security, privacy, legal, and compliance stakeholders.Recruiting for this...Local areaVisa sponsorship- Company DescriptionMaganti IT Resources LLCJob DescriptionTitle: Enterprise EngineerLocation: Indianapolis, IndianaType: permanentJob requirement:• 8 years of IP networking experience in a production environment, and 4 years of enterprise network design and architecture...Permanent employmentRemote work
$155.6k - $306.8k
Position Summary As an Engineering Manager in Deloitte Cyber’s Digital Trust & Privacy practice, you will help clients solve complex identity, access, and data protection challenges through AI-enabled engineering solutions. This role sits at the intersection of...Local areaVisa sponsorship$134.5k - $265.1k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity.... ...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll...Local areaVisa sponsorship- We Are:Accenture Security is one of the fastest growing areas of our business, and our global Cyber Investigation and Forensic Response (CIFR) practice is at the heart of how we help clients prepare for, respond to, and recover from the most consequential cyber incidents...Full timeLive inWork at officeLocal areaShift work
$118.7k - $218.6k
Position Summary Cyber Data Protection and PKI Specialist - Senior ConsultantOur Deloitte Cyber team understands the unique challenges... ...resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work You’ll...Work experience placementLocal areaVisa sponsorship- IN0534 Fishers, OH0523 Independence Bus Office, OH0713 NW Bancshares HQ, PA0258 Bellevue, PA0736 Administration CenterJob DescriptionThe AI Governance Officer is a senior-level contributor responsible for administering the Bank's enterprise AI governance framework and supporting...Full timeWork at office
$155.6k - $306.8k
Position Summary Deloitte Cyber understands the unique challenges and opportunities businesses face in cybersecurity. Deloitte... ...resilience, grow with confidence, and proactively manage their security posture.Recruiting for this role ends on 12/31/2026.Work you...Local areaVisa sponsorship$105.4k - $207.8k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities... ...confidence, and proactively manage to secure success. Recruiting for this role ends on... ...Microsoft Certified: Security Operations Analyst Associate (SC-200), Certified Cloud...Local areaVisa sponsorship$88.7k - $139.26k
...inclusivity and excellence.Your Role at Delta FaucetDelta Faucet Company is seeking an Operations Technology (OT) Cybersecurity Analyst to help secure and modernize the manufacturing technologies that power our plants and distribution operations. This role serves as a key...Full timeLocal areaRemote work- ...partner to Optiv’s clients. By combining advanced business and security practitioner knowledge, the Principal AI Cybersecurity Advisor... ...the Principal Advisor will drive thought leadership and inspired cyber security solutions powered by our ecosystem of people, products...Full timeLocal areaRemote workWork from home
- ...planning to optimize performance Conduct security checks, recovery drills, and compliance audits... ...management of threat-based alerting. The analyst will develop detection rules, correlation... ...certifications such as SANS GIAC Cyber Threat Intelligence (GCTI), Recorded Future...Full timeTemporary workRelocation
- ...Job Description Insight Global is seeking a Cyber Security Analyst for a top government services client. This individual will play a critical role in monitoring and defending enterprise systems against cyber threats in a fast-paced, mission-critical environment. The...Shift work
- CLA is a top 10 national professional services firm where our purpose is to create opportunities every day, for our clients, our people, and our communities through industry-focused wealth advisory, digital, audit, tax, consulting, and outsourcing services. Even with more...Full time
$73.45k - $132.78k
...issues within Microsoft Intune-managed environments, while also operating effectively across desktop support, endpoint management, security compliance, and network-related challenges. You will be expected to move fluidly across technical domains. This means owning...Full time- ..., Google and Microsoft Collaboration platforms, Storage and Backup services, Network Infrastructure, Network Operation Center, Cyber Security, Disaster Recovery, Infrastructure Automations, etc.Proficiency in IT Infrastructure:Strong understanding of Operating Systems...Work at office
- ...Chief Information Security Officer (CISO) About the Company Popular provider of enterprise resource planning & business management... ...role requires a leader with deep technical expertise in modern cyber detection and response, threat intelligence, and security...
- ...Information Security Advisor Senior Location: This role requires associates to be in-office 1-2 days per week, fostering collaboration... ...strategies for discovery, evaluation, and response to emerging cyber threats, insider risks, and fraud patterns. Capable of...Full timeTemporary workWork at officeLocal area2 days per week1 day per week
- ...balance project economics with adherence to strategic prioritiesRequired Skill and Experience• Experienced in the role of managing cyber security operations covering multiple cyber tracks/domains.• Broad knowledge across multiple domains like Security Operation Centre (SOC...Full timeTemporary workRelocation
$134.5k - $265.1k
Position Summary Deloitte’s Cyber team helps clients address evolving cybersecurity... ...You will design, implement, and optimize secure, outcome-focused solutions while... ...Collaborating with security operations center (SOC) analysts and threat detection engineers to...Local areaVisa sponsorship$134.5k - $265.1k
...experienced cybersecurity professional looking to help organizations reduce cyber risk and improve resilience? At Deloitte & Touche LLP, you’ll work with leading organizations to strengthen security, enable innovation, and reduce threat exposure. Join Deloitte’s Cyber...Local area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Security Analyst. Be the first to apply!
- information security consultant Indianapolis, IN
- cyber security analyst Indianapolis, IN
- entry level cyber security analyst Indianapolis, IN
- cyber Indianapolis, IN
- cybersecurity software engineer Indianapolis, IN
- cyber security technician Indianapolis, IN
- cybersecurity administrator Indianapolis, IN
- remote cyber security Indianapolis, IN
- cyber security lead Indianapolis, IN
- cyber security Indianapolis, IN


