Cybersecurity Analyst
EXOS
The Cybersecurity Analyst III at EXOS CYBER is the senior technical escalation point of the SOC — the final analyst-tier authority on the hardest, most ambiguous investigations before a case moves into engineering. When Tier 2 has driven an alert as far as standard playbooks and queries allow and still doesn't have a confident answer, it comes to you. You own confirmed, significant incidents end to end across our client environments. You will support day-to-day security operations for our clients with a primary focus on advanced detection, incident response, and threat hunting, working alongside our Cybersecurity Engineers, and Team Lead. Beyond the queue, you set the bar for investigation quality across the SOC. You QA escalations, mentor and develop Tier 1 and Tier 2, build out the investigation curriculum, and partner with engineering on detection strategy at the program level, not just one noisy rule at a time. This is a hands‑on, deeply technical role designed for analysts with 5+ years of experience (or 2+ years past Tier 2) who are ready to operate as the senior individual contributor in a real‑world MSSP detection‑and‑response practice spanning across a diverse client environments. Serve as the Tier 3 technical escalation point in the SOC. Take the incidents that Tier 2 cannot fully resolve, drive them to a definitive answer, and hand only genuinely engineering‑scoped or architecture‑level problems to the Cybersecurity Engineers and Team Lead with a clear, evidence‑backed recommendation and a proposed course of action. Lead confirmed true‑positive incidents end to end across client environments including but not limited to ransomware, business email compromise, account takeover, lateral movement, and data exfiltration including scoping and impact assessment, containment orchestration via SentinelOne, account isolation and credential rotation in Entra ID, eradication and recovery guidance, evidence preservation, root‑cause analysis, and client communication through resolution. Own and run the proactive threat hunting program: develop hypothesis‑driven hunts across the client base using various queries, EDR telemetry, and indicators from CTI feeds; document findings; and feed confirmed patterns back into detection engineering as durable, reusable detections. Perform host, memory, and network forensics (Velociraptor, endpoint and identity artifacts, timeline reconstruction) to establish what happened, when, and how far it went, and to support breach‑notification and legal/insurance coordination when an incident warrants it. Conduct phishing triage and support email‑based threat investigations, including user impact assessment and remediation steps. Partner with the Cybersecurity Engineers and AI Automation Engineer on detection strategy at the program level coverage and gap analysis against MITRE ATT&CK, detection content design, and false‑positive reduction across the fleet rather than one‑off alert tuning. Apply offensive and adversary‑emulation knowledge to inform detection coverage, and support purple team and adversary‑emulation exercises by translating attacker TTPs into detections and validating that controls fire as expected. Analyze endpoint, identity, and network telemetry to identify suspicious activity, lateral movement, and persistence, and lead phishing and email‑based threat investigations through full user‑impact assessment and remediation. Set and enforce investigation quality standards: QA Tier 1 and Tier 2 escalations and case documentation, run walk‑throughs of significant investigations, give kind and direct feedback, and own the Tier 1/Tier 2 onboarding and skills‑development curri Author the analytical narrative for the most complex client deliverables, post‑incident reports, after‑action reviews, and the senior‑analyst portion of monthly client reporting covering what we saw, what it means, and what we recommend, in language a client technical stakeholder can act on. Drive SOC operational maturity by shaping runbook and playbook architecture, investigation checklists, and repeatable workflows, and by mentoring the team toward consistent, defensible outcomes Must Haves 5+ years of experience in a SOC, incident response, MSSP, or security operations role, or 2+ years past a Tier 2 / Analyst II role in a comparable environment. Demonstrated ability to independently lead complex investigations and confirmed incidents to resolution across endpoint, identity, email, and network telemetry — not just triage and elevate. Advanced command of an EDR (SentinelOne, CrowdStrike, or Defender for Endpoint) and a SIEM (Blumira, Sentinel, Splunk, or QRadar) at the query, pivot, and detection‑authoring level. Practical host and network forensics and evidence‑preservation experience, including timeline reconstruction across Windows event logs, Active Directory, Entra ID, firewall, VPN, DNS, and email security logs. Hands‑on proactive threat hunting experience: building and executing hypothesis‑driven hunts and converting findings into detections. Proficient scripting in PowerShell and/or Python for investigation, log parsing, and automation. Working fluency with the MITRE ATT&CK framework for both investigation and detection‑coverage mapping. Strong command of the incident response lifecycle, escalation criteria, and chain‑of‑custody / evidence‑handling practices. Ability to lead under pressure in a multi‑client environment, prioritize across simultaneous active incidents, and maintain quality and clear documentation throughout. Excellent written communication, with the ability to produce client‑ready incident summaries, post‑incident reports, and analytical narratives, and to mentor junior analysts effectively. Solid fundamentals in TCP/IP, DNS, Windows and Linux internals, and identity and access management. Relevant certifications such as CompTIA CySA+, GIAC GCIH/GCIA/GCFA, BTL2, or equivalent demonstrated experience. Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline. Equivalent military training or certifications considered. Advanced certifications such as GIAC GCIA, GCFA, GCFE, GNFA, GCTI, GREM, or BTL2; offensive‑informed credentials (OSCP, CRTO) a strong plus given the role's detection and purple‑team‑support scope. Prior MSSP experience in a multi‑tenant model, including a multi‑tenant PSA/ticketing platform (ConnectWise, Autotask, ServiceNow, or similar). Detection engineering experience: Sigma rules, KQL, and SentinelOne / Blumira query syntax, plus comfort building detections from hunt findings. Experience with SOAR or rules‑based automation and operationalizing playbooks alongside an AI Automation Engineer. DFIR tooling depth (Velociraptor or comparable) and experience supporting legal, insurance, and breach‑notification workflows during major incidents. Vulnerability management and offensive‑output review experience (ConnectSecure, Tenable, Qualys; NodeZero or comparable pentest/attack‑path findings). Experience mentoring or formally developing junior analysts and building SOC training content. #J-18808-Ljbffr
- ## Cybersecurity AnalystApplylocations: Carmel, INtime type: Full timeposted on: Posted Todayjob requisition id: JR36320## **Creating Peace... ...building exceptional workplace cultures.***The Cybersecurity Analyst** is responsible for proactively and iteratively discovering signs...SuggestedTemporary workH1bRemote workFlexible hoursWeekend workAfternoon shift
$69.4k - $158k
...Cybersecurity Analyst The Opportunity: As a security operations center analyst, you're in the middle of the action, responding to and mitigating threats in real time. You're the first line of cyber defense for your organization, and they look to you for guidance...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote workShift work- ...enterprise, providing expert-level guidance and reporting outcomes to Information Technology security leadership. Assists Security Analysts as an escalation point for security alerts, events, and logs, escalating findings appropriately to senior management. Designs,...SuggestedRemote work
- To strengthen our data protection and governance capabilities, we are looking for a Data Protection Manager to support the operational implementation and continuous improvement of data protection practices across assigned legal entities and business functions. In this ...Suggested
$28 per hour
Business Developer (BD) – BrightView Responsible for improving BrightView’s market position and achieving profitable financial growth. Full‑time Community Manager – Developer Services Highly organized and service‑driven role managing a portfolio of developer‑controlled...SuggestedHourly payPermanent employmentFull timeContract workRemote work- Job Title Benefits (employee contribution): Health insurance Health savings account Dental insurance Vision insurance Flexible spending accounts Life insurance Retirement plan All qualified applicants will receive consideration for employment without regard to age, ...Flexible hours
$42.7 per hour
Job Title Hybrid position. Must live in the Indianapolis area. Pay: $42.70/hour Job Description In this role you will: Monitor and keep supervisor informed of status of information security and confidentiality conditions, including problem areas and recommended...Live inRemote work$30 per hour
...and Federal Sales Teams. The Information Security Compliance Analyst is expected to work with the GDI Performance Management team to... ...adopted. Required Skills & Experience: Experience with Cybersecurity and Information Security Understanding of the NIST SP 800-5...Hourly payTemporary workInternshipFlexible hours- ...Epic Application Analyst Must-have skills (minimum 1+ year experience): Epic Cadence, Grand Central, Prelude, Referrals, SER ServiceNow knowledge Strong customer service and communication skills Self-starter with the ability to work independently...Shift work
- Chief Information Security Officer (CISO), Growth About the Company Accomplished provider of top-tier security services Industry Security and Investigations Type Privately Held About the Role The Company is seeking a Chief Information Security Officer...
- Chief Information Security Officer (CISO) About the Company Trusted provider & publisher of consumer insights about car models & auto brands Industry Market Research Type Privately Held, Private Equity-backed Founded 1968 Employees 1001-5000 ...
- ...Our client, a healthcare organization, is seeking a Clinical Applications Analyst to join their team. As a Clinical Applications Analyst, you will be part of the IT Applications team supporting clinical, pharmacy, and multidisciplinary teams. Job Title: Clinical Applications...
$76.4k - $138.6k
...through innovative, secure solutions that provide speed to market and business value. The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY's digital exposure through hands-on...Summer holidayLocal areaFlexible hours$124.2k - $186.2k
...investigation details. Reviewing, documenting, and updating existing SOC processes. Experience You’ll Need Bachelor’s degree in Cybersecurity, Information Systems, or other related technical disciplines, or equivalent experience. 3+ years of experience in Security Operations...Local areaRemote work- Anchor Point Technology Resources, established in 2004. Our corporate office is located in the heart of Indianapolis, Indiana, with locations in Cincinnati, OH and Louisville, KY. Anchor Point is a locally owned WBE. At Anchor Point, we will work closely with you to gain...Work at office
- Location: Indianapolis, IN (On-site) Type: Full-Time Industry: Civil Engineering / Infrastructure Overview Our client is seeking an experienced IT Consultant to join their growing IT Team. This role is ideal for a polished, service-oriented professional who excels at translating...Full time
$120k - $150k
...that is passionate about creating transformative change in healthcare. We are seeking a highly skilled and experienced Senior Systems Analyst – Oracle HCM to join our HRIT team. This individual will be a critical member of the Oracle HCM remediation and optimization...- Implementation Consultant T2 Systems is the largest parking, mobility, and transportation provider in North America, with more than 25 years in the parking management industry and currently serving thousands of parking professionals. We integrate the best people, processes...Work at officeRemote work
- ...Operations Systems Analyst The State Comptroller’s Office is seeking a detail‑oriented and technically skilled Operations Systems Analyst to run and monitor jobs in the PeopleSoft Financials system, print critical documents, and utilize and maintain mailing equipment....Contract workWork at officeMonday to Friday
$66.79k - $125k
...collaborative environment focused on enabling your career growth and continuous professional development. We are seeking a Systems Analyst to join our team. The Systems Analyst plays a critical role in supporting technology due diligence, integration planning, and post‑...Work experience placementLocal area$60.8k - $82.9k
...Become a part of our caring community As a Revenue Cycle EDI Systems Analyst , you will report to the VP, RCM. You will be responsible for supporting, monitoring, and optimizing revenue cycle systems utilized by the FSU. You will ensure accurate and timely billing...Bi-weekly payFull timeTemporary workApprenticeshipWork at officeRemote workHome office- ...About The Role Arbor Homes is currently looking for an IT Systems Analyst. This is a Tier 1 IT service desk role. The right candidate is a very likeable person with great “bedside manners,” a strong desire to help people and fix problems, solid desktop, and network support...Immediate startRemote work
$102.17k
...clients across the country. Job Description Join the Trinnex Security Team as a Senior Cyber Security Analyst, where you will operate at the intersection of cybersecurity and DevSecOps to protect critical software systems that support water utilities and infrastructure....H1b$26.65 - $42.7 per hour
Role: Information Security Analyst Location: Indianapolis, IN 46204 (Hybrid - Local Candidates Only) Duration: 6+ Months Contract Overview: The Information Security Analyst will audit and monitor systems containing confidential data, support compliance with state/federal...Hourly payContract workLocal area$115k - $150k
Hagerty Consulting, Inc. (Hagerty) is the nation's leading emergency management and homeland security consulting firm. Known for its public spirit, innovative thinking, problem-solving, and exceptional people, Hagerty is sought after to work on some of the largest and ...Permanent employmentTemporary workLocal areaImmediate startRemote workFlexible hours- Get AI-powered advice on this job and more exclusive features. Squadware Inc is hiring a Software Quality Assurance Analyst for a consulting position with one of our clients on the north side of Indianapolis. This role is full time and can be a 1099 contract or w-2 position...Full timeContract workRemote workRelocation
$117.1k - $187.3k
We believe in the power and joy of learning At Cengage, our employees have a direct impact in helping students around the world discover the power and joy of learning. We are bonded by our shared purpose - driving innovation that helps millions of learners improve their...Local areaWorldwide- Responsibilities Define and evolve enterprise architecture and multi-year technology roadmaps aligned to Utility strategy, RoE priorities, and targeted outcomes across Customer Engagement, T&D Transformation, and Smart Grid. Architect solutions around business domains and...For contractors
$117.1k - $152.65k
We believe in the power and joy of learning At Cengage, our employees have a direct impact in helping students around the world discover the power and joy of learning. We are bonded by our shared purpose - driving innovation that helps millions of learners improve their...Work experience placementLive inLocal areaWorldwide- Duties Support senior security specialist - manage the development, evaluation, implementation, and operation of procedures and methods used for safeguarding personnel, information, property, operations, and materials. Reviews changes to security guidelines and policies...Local area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Analyst. Be the first to apply!
- cybersecurity Indianapolis, IN
- no experience cyber security Indianapolis, IN
- cyber security Indianapolis, IN
- cybersecurity certificate Indianapolis, IN
- IT cyber security Indianapolis, IN
- cybersecurity administrator Indianapolis, IN
- remote cyber security Indianapolis, IN
- cybersecurity software engineer Indianapolis, IN
- cyber security technician Indianapolis, IN
- cybersecurity technical writer Indianapolis, IN

