Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity Analyst

EXOS

The Cybersecurity Analyst III at EXOS CYBER is the senior technical escalation point of the SOC — the final analyst-tier authority on the hardest, most ambiguous investigations before a case moves into engineering. When Tier 2 has driven an alert as far as standard playbooks and queries allow and still doesn't have a confident answer, it comes to you. You own confirmed, significant incidents end to end across our client environments. You will support day-to-day security operations for our clients with a primary focus on advanced detection, incident response, and threat hunting, working alongside our Cybersecurity Engineers, and Team Lead. Beyond the queue, you set the bar for investigation quality across the SOC. You QA escalations, mentor and develop Tier 1 and Tier 2, build out the investigation curriculum, and partner with engineering on detection strategy at the program level, not just one noisy rule at a time. This is a hands‑on, deeply technical role designed for analysts with 5+ years of experience (or 2+ years past Tier 2) who are ready to operate as the senior individual contributor in a real‑world MSSP detection‑and‑response practice spanning across a diverse client environments. Serve as the Tier 3 technical escalation point in the SOC. Take the incidents that Tier 2 cannot fully resolve, drive them to a definitive answer, and hand only genuinely engineering‑scoped or architecture‑level problems to the Cybersecurity Engineers and Team Lead with a clear, evidence‑backed recommendation and a proposed course of action. Lead confirmed true‑positive incidents end to end across client environments including but not limited to ransomware, business email compromise, account takeover, lateral movement, and data exfiltration including scoping and impact assessment, containment orchestration via SentinelOne, account isolation and credential rotation in Entra ID, eradication and recovery guidance, evidence preservation, root‑cause analysis, and client communication through resolution. Own and run the proactive threat hunting program: develop hypothesis‑driven hunts across the client base using various queries, EDR telemetry, and indicators from CTI feeds; document findings; and feed confirmed patterns back into detection engineering as durable, reusable detections. Perform host, memory, and network forensics (Velociraptor, endpoint and identity artifacts, timeline reconstruction) to establish what happened, when, and how far it went, and to support breach‑notification and legal/insurance coordination when an incident warrants it. Conduct phishing triage and support email‑based threat investigations, including user impact assessment and remediation steps. Partner with the Cybersecurity Engineers and AI Automation Engineer on detection strategy at the program level coverage and gap analysis against MITRE ATT&CK, detection content design, and false‑positive reduction across the fleet rather than one‑off alert tuning. Apply offensive and adversary‑emulation knowledge to inform detection coverage, and support purple team and adversary‑emulation exercises by translating attacker TTPs into detections and validating that controls fire as expected. Analyze endpoint, identity, and network telemetry to identify suspicious activity, lateral movement, and persistence, and lead phishing and email‑based threat investigations through full user‑impact assessment and remediation. Set and enforce investigation quality standards: QA Tier 1 and Tier 2 escalations and case documentation, run walk‑throughs of significant investigations, give kind and direct feedback, and own the Tier 1/Tier 2 onboarding and skills‑development curri Author the analytical narrative for the most complex client deliverables, post‑incident reports, after‑action reviews, and the senior‑analyst portion of monthly client reporting covering what we saw, what it means, and what we recommend, in language a client technical stakeholder can act on. Drive SOC operational maturity by shaping runbook and playbook architecture, investigation checklists, and repeatable workflows, and by mentoring the team toward consistent, defensible outcomes Must Haves 5+ years of experience in a SOC, incident response, MSSP, or security operations role, or 2+ years past a Tier 2 / Analyst II role in a comparable environment. Demonstrated ability to independently lead complex investigations and confirmed incidents to resolution across endpoint, identity, email, and network telemetry — not just triage and elevate. Advanced command of an EDR (SentinelOne, CrowdStrike, or Defender for Endpoint) and a SIEM (Blumira, Sentinel, Splunk, or QRadar) at the query, pivot, and detection‑authoring level. Practical host and network forensics and evidence‑preservation experience, including timeline reconstruction across Windows event logs, Active Directory, Entra ID, firewall, VPN, DNS, and email security logs. Hands‑on proactive threat hunting experience: building and executing hypothesis‑driven hunts and converting findings into detections. Proficient scripting in PowerShell and/or Python for investigation, log parsing, and automation. Working fluency with the MITRE ATT&CK framework for both investigation and detection‑coverage mapping. Strong command of the incident response lifecycle, escalation criteria, and chain‑of‑custody / evidence‑handling practices. Ability to lead under pressure in a multi‑client environment, prioritize across simultaneous active incidents, and maintain quality and clear documentation throughout. Excellent written communication, with the ability to produce client‑ready incident summaries, post‑incident reports, and analytical narratives, and to mentor junior analysts effectively. Solid fundamentals in TCP/IP, DNS, Windows and Linux internals, and identity and access management. Relevant certifications such as CompTIA CySA+, GIAC GCIH/GCIA/GCFA, BTL2, or equivalent demonstrated experience. Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline. Equivalent military training or certifications considered. Advanced certifications such as GIAC GCIA, GCFA, GCFE, GNFA, GCTI, GREM, or BTL2; offensive‑informed credentials (OSCP, CRTO) a strong plus given the role's detection and purple‑team‑support scope. Prior MSSP experience in a multi‑tenant model, including a multi‑tenant PSA/ticketing platform (ConnectWise, Autotask, ServiceNow, or similar). Detection engineering experience: Sigma rules, KQL, and SentinelOne / Blumira query syntax, plus comfort building detections from hunt findings. Experience with SOAR or rules‑based automation and operationalizing playbooks alongside an AI Automation Engineer. DFIR tooling depth (Velociraptor or comparable) and experience supporting legal, insurance, and breach‑notification workflows during major incidents. Vulnerability management and offensive‑output review experience (ConnectSecure, Tenable, Qualys; NodeZero or comparable pentest/attack‑path findings). Experience mentoring or formally developing junior analysts and building SOC training content. #J-18808-Ljbffr

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cybersecurity Analyst in Indianapolis, IN vacancy
  •  ...About the Position: GadellNet is seeking a highly skilled Cybersecurity Analyst with a strong passion for information security and data protection. The ideal candidate is a technically proficient problem-solver who upholds high standards of excellence and consistently... 
    Suggested
    Monday to Friday
    Flexible hours

    GadellNet Consulting Services, LLC.

    Indianapolis, IN
    22 hours ago
  • ## Cybersecurity AnalystApplylocations: Carmel, INtime type: Full timeposted on: Posted Todayjob requisition id: JR36320## **Creating Peace...  ...building exceptional workplace cultures.***The Cybersecurity Analyst** is responsible for proactively and iteratively discovering signs... 
    Suggested
    Temporary work
    H1b
    Remote work
    Flexible hours
    Weekend work
    Afternoon shift

    Allegion Canada Inc.

    Carmel, IN
    22 hours ago
  •  ...GadellNet Consulting Services is seeking a Cybersecurity Analyst to investigate incidents, review escalations, and assess alerts while adhering to established procedures. The role emphasizes collaboration, documentation, and continual learning in a fast-paced IT security... 
    Suggested
    Monday to Friday

    GadellNet

    Indianapolis, IN
    1 day ago
  • $88.7k - $139.26k

     ...journey toward inclusivity and excellence.Your Role at Delta FaucetDelta Faucet Company is seeking an Operations Technology (OT) Cybersecurity Analyst to help secure and modernize the manufacturing technologies that power our plants and distribution operations. This role... 
    Suggested
    Full time
    Local area
    Remote work

    Masco

    Indianapolis, IN
    3 days ago
  • $88.7k - $139.26k

     ...from all backgrounds to join us on this journey toward inclusivity and excellence.Your Role at Delta FaucetWe're looking for a Cybersecurity Analyst to join our Information Security team and help strengthen our data protection, privacy, and governance capabilities. In this... 
    Suggested
    Full time
    Local area

    Masco

    Indianapolis, IN
    2 days ago
  • $105.4k - $207.8k

     ...understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our...  ...such as Microsoft Certified: Security Operations Analyst Associate (SC-200), Certified Cloud Security Professional, Certificate... 
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    1 day ago
  •  ...serving as a trusted partner to Optiv’s clients. By combining advanced business and security practitioner knowledge, the Principal AI Cybersecurity Advisor designs security solutions using some of the most advanced security services and technologies to achieve highly... 
    Full time
    Local area
    Remote work
    Work from home

    Optiv

    Indianapolis, IN
    2 days ago
  • $82.6k - $162.8k

    Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions... 
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    22 hours ago
  • $134.5k - $265.1k

    Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions... 
    Local area

    Deloitte

    Indianapolis, IN
    2 days ago
  •  ...Independence Bus Office, OH0713 NW Bancshares HQ, PA0258 Bellevue, PA0738 Processing CenterJob DescriptionSenior Application Systems Analyst provides analytical, tier 2/3 technical support for business applications, mentors and coaches junior team members; creates and... 
    Full time
    Work experience placement
    Work at office

    Northwest Bank

    Fishers, IN
    17 hours ago
  • $155.6k - $306.8k

     ...States without the need for employer sponsorship, now or at any time in the future.Preferred:Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Engineering, Information Technology, Mathematics, or PhysicsExperience in a consulting... 
    Local area

    Deloitte

    Indianapolis, IN
    4 days ago
  •  ...enterprise, providing expert-level guidance and reporting outcomes to Information Technology security leadership. Assists Security Analysts as an escalation point for security alerts, events, and logs, escalating findings appropriately to senior management. Designs,... 
    Remote work

    WesBanco Bank Inc.

    Indianapolis, IN
    3 days ago
  • Operational Resilience Senior Advisor (Information Security Senior Advisor) Location: This role requires associates to be in-office 1-2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance...
    Full time
    Temporary work
    Work at office
    Local area
    2 days per week
    1 day per week

    Elevance Health

    Indianapolis, IN
    2 days ago
  • Company DescriptionMaganti IT Resources LLCJob DescriptionTitle: Enterprise EngineerLocation: Indianapolis, IndianaType: permanentJob requirement:• 8 years of IP networking experience in a production environment, and 4 years of enterprise network design and architecture...
    Permanent employment
    Remote work

    Maganti IT Resources

    Indianapolis, IN
    22 hours ago
  • $155.6k - $306.8k

     ...a changing threat landscape.QualificationsRequired:Bachelor’s degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field; alternatively, equivalent demonstrated experience7+ experience in one or more Digital Trust & Privacy domains... 
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    2 days ago
  • $134.5k - $265.1k

    Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions... 
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    17 hours ago
  •  ...confidence in high-stakes situationsMinimum 4 years of client-facing consulting experience in infrastructure, enterprise architecture, cybersecurity, or a closely related disciplineMinimum 2 years of experience leading teams or workstreams in a consulting or advisory... 
    Full time
    Live in
    Work at office
    Local area
    Shift work

    Accenture

    Carmel, IN
    2 days ago
  • IN0534 Fishers, OH0523 Independence Bus Office, OH0713 NW Bancshares HQ, PA0258 Bellevue, PA0736 Administration CenterJob DescriptionThe AI Governance Officer is a senior-level contributor responsible for administering the Bank's enterprise AI governance framework and supporting...
    Full time
    Work at office

    Northwest Bank

    Fishers, IN
    4 days ago
  • $118.7k - $218.6k

     ...PKI Specialist - Senior ConsultantOur Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful... 
    Work experience placement
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    3 days ago
  • $155.6k - $306.8k

    Position Summary Deloitte Cyber understands the unique challenges and opportunities businesses face in cybersecurity. Deloitte’s Cyber team helps our clients navigate the ever-changing threat landscape. We simplify complexity, and enable businesses to operate with... 
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    3 days ago
  • $73.45k - $132.78k

    Leidos Civil IT division is focused on innovation and solving complex technical problems spanning infrastructure operations, cybersecurity analytics, and application modernizations. We rely on a team of skilled staff capable of operating across technical domains, embracing... 
    Full time

    Leidos

    Indianapolis, IN
    4 days ago
  • Job TitleBenefits (employee contribution):Health insuranceHealth savings accountDental insuranceVision insuranceFlexible spending accountsLife insuranceRetirement planAll qualified applicants will receive consideration for employment without regard to age, race, color,...

    Theoris

    Fishers, IN
    1 day ago
  • $100k - $121k

     ...than 70 countries across all 7 continents. The Data Security Analyst specializes in securing enterprise data warehouses; ETL/ELT...  ...Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related field. Typically, five (5) years of experience... 
    Hourly pay
    Contract work
    Local area

    Amentum

    Indianapolis, IN
    3 days ago
  • CLA is a top 10 national professional services firm where our purpose is to create opportunities every day, for our clients, our people, and our communities through industry-focused wealth advisory, digital, audit, tax, consulting, and outsourcing services. Even with more...
    Full time

    CliftonLarsonAllen

    Indianapolis, IN
    4 days ago
  •  ...business change, while staying committed to delivering value & outcomes that enables their success.We are seeking a Software Quality Analyst who will be responsible for defining, reviewing, and executing test cases and defect creation and tracking them through to... 
    Remote work

    eImagine Technology Group

    Indianapolis, IN
    4 days ago
  •  ...in IT infrastructure, Architecture, IT Service Management, etc.Experience in the areas like, Operating Systems, Virtualization, Cybersecurity, Disaster RecoverySRI Tech Solutions is an equal opportunity employer and does not discriminate on the basis of race, color, gender... 
    Work at office

    SRI Tech

    Indianapolis, IN
    22 hours ago
  •  ...in the financial industry, is seeking an Information Security Analyst to join their team. As a Security Analyst, you will be part of...  ...Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Management Information Systems, or a related field preferred;... 

    Experis

    Indianapolis, IN
    1 day ago
  • $69.4k - $158k

     ...Security AnalystThe Opportunity:As a security operations center analyst, you’re in the middle of the action, responding to and...  ...teamTS/SCI clearanceBachelor's degree in Information Systems, Cybersecurity, Engineering, or a related fieldClearance:Applicants selected... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work
    Shift work

    Booz Allen Hamilton

    Indianapolis, IN
    22 hours ago
  • $105.4k - $207.8k

     ...and cloud feedsCollaborating with security operations center analysts and threat detection engineers to prioritize, develop, and tune...  ..., mentoring junior team members, and staying current on cybersecurity threats, vulnerabilities, and compliance trendsA successful candidate... 
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    3 days ago
  • $105.4k - $207.8k

     ...operational requirements into deployable capabilities that improve analyst efficiency, alert quality, and response speed. Recruiting for...  ...Required: Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field, or equivalent... 
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity Analyst. Be the first to apply!