Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity Analyst

EXOS

The Cybersecurity Analyst III at EXOS CYBER is the senior technical escalation point of the SOC — the final analyst-tier authority on the hardest, most ambiguous investigations before a case moves into engineering. When Tier 2 has driven an alert as far as standard playbooks and queries allow and still doesn't have a confident answer, it comes to you. You own confirmed, significant incidents end to end across our client environments. You will support day-to-day security operations for our clients with a primary focus on advanced detection, incident response, and threat hunting, working alongside our Cybersecurity Engineers, and Team Lead. Beyond the queue, you set the bar for investigation quality across the SOC. You QA escalations, mentor and develop Tier 1 and Tier 2, build out the investigation curriculum, and partner with engineering on detection strategy at the program level, not just one noisy rule at a time. This is a hands‑on, deeply technical role designed for analysts with 5+ years of experience (or 2+ years past Tier 2) who are ready to operate as the senior individual contributor in a real‑world MSSP detection‑and‑response practice spanning across a diverse client environments. Serve as the Tier 3 technical escalation point in the SOC. Take the incidents that Tier 2 cannot fully resolve, drive them to a definitive answer, and hand only genuinely engineering‑scoped or architecture‑level problems to the Cybersecurity Engineers and Team Lead with a clear, evidence‑backed recommendation and a proposed course of action. Lead confirmed true‑positive incidents end to end across client environments including but not limited to ransomware, business email compromise, account takeover, lateral movement, and data exfiltration including scoping and impact assessment, containment orchestration via SentinelOne, account isolation and credential rotation in Entra ID, eradication and recovery guidance, evidence preservation, root‑cause analysis, and client communication through resolution. Own and run the proactive threat hunting program: develop hypothesis‑driven hunts across the client base using various queries, EDR telemetry, and indicators from CTI feeds; document findings; and feed confirmed patterns back into detection engineering as durable, reusable detections. Perform host, memory, and network forensics (Velociraptor, endpoint and identity artifacts, timeline reconstruction) to establish what happened, when, and how far it went, and to support breach‑notification and legal/insurance coordination when an incident warrants it. Conduct phishing triage and support email‑based threat investigations, including user impact assessment and remediation steps. Partner with the Cybersecurity Engineers and AI Automation Engineer on detection strategy at the program level coverage and gap analysis against MITRE ATT&CK, detection content design, and false‑positive reduction across the fleet rather than one‑off alert tuning. Apply offensive and adversary‑emulation knowledge to inform detection coverage, and support purple team and adversary‑emulation exercises by translating attacker TTPs into detections and validating that controls fire as expected. Analyze endpoint, identity, and network telemetry to identify suspicious activity, lateral movement, and persistence, and lead phishing and email‑based threat investigations through full user‑impact assessment and remediation. Set and enforce investigation quality standards: QA Tier 1 and Tier 2 escalations and case documentation, run walk‑throughs of significant investigations, give kind and direct feedback, and own the Tier 1/Tier 2 onboarding and skills‑development curri Author the analytical narrative for the most complex client deliverables, post‑incident reports, after‑action reviews, and the senior‑analyst portion of monthly client reporting covering what we saw, what it means, and what we recommend, in language a client technical stakeholder can act on. Drive SOC operational maturity by shaping runbook and playbook architecture, investigation checklists, and repeatable workflows, and by mentoring the team toward consistent, defensible outcomes Must Haves 5+ years of experience in a SOC, incident response, MSSP, or security operations role, or 2+ years past a Tier 2 / Analyst II role in a comparable environment. Demonstrated ability to independently lead complex investigations and confirmed incidents to resolution across endpoint, identity, email, and network telemetry — not just triage and elevate. Advanced command of an EDR (SentinelOne, CrowdStrike, or Defender for Endpoint) and a SIEM (Blumira, Sentinel, Splunk, or QRadar) at the query, pivot, and detection‑authoring level. Practical host and network forensics and evidence‑preservation experience, including timeline reconstruction across Windows event logs, Active Directory, Entra ID, firewall, VPN, DNS, and email security logs. Hands‑on proactive threat hunting experience: building and executing hypothesis‑driven hunts and converting findings into detections. Proficient scripting in PowerShell and/or Python for investigation, log parsing, and automation. Working fluency with the MITRE ATT&CK framework for both investigation and detection‑coverage mapping. Strong command of the incident response lifecycle, escalation criteria, and chain‑of‑custody / evidence‑handling practices. Ability to lead under pressure in a multi‑client environment, prioritize across simultaneous active incidents, and maintain quality and clear documentation throughout. Excellent written communication, with the ability to produce client‑ready incident summaries, post‑incident reports, and analytical narratives, and to mentor junior analysts effectively. Solid fundamentals in TCP/IP, DNS, Windows and Linux internals, and identity and access management. Relevant certifications such as CompTIA CySA+, GIAC GCIH/GCIA/GCFA, BTL2, or equivalent demonstrated experience. Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline. Equivalent military training or certifications considered. Advanced certifications such as GIAC GCIA, GCFA, GCFE, GNFA, GCTI, GREM, or BTL2; offensive‑informed credentials (OSCP, CRTO) a strong plus given the role's detection and purple‑team‑support scope. Prior MSSP experience in a multi‑tenant model, including a multi‑tenant PSA/ticketing platform (ConnectWise, Autotask, ServiceNow, or similar). Detection engineering experience: Sigma rules, KQL, and SentinelOne / Blumira query syntax, plus comfort building detections from hunt findings. Experience with SOAR or rules‑based automation and operationalizing playbooks alongside an AI Automation Engineer. DFIR tooling depth (Velociraptor or comparable) and experience supporting legal, insurance, and breach‑notification workflows during major incidents. Vulnerability management and offensive‑output review experience (ConnectSecure, Tenable, Qualys; NodeZero or comparable pentest/attack‑path findings). Experience mentoring or formally developing junior analysts and building SOC training content. #J-18808-Ljbffr EXOS

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Cybersecurity Analyst in Indianapolis, IN vacancy
  • $69.4k - $158k

    Cybersecurity AnalystThe Opportunity:As a security operations center (SOC) analyst, you’re in the middle of the action, responding to and mitigating threats in real time. You’re the first line of cyber defense for your organization, and they look to you for guidance on... 
    Suggested
    Full time
    Contract work
    Part time
    Local area
    Remote work
    Shift work

    Booz Allen Hamilton

    Indianapolis, IN
    3 days ago
  •  ...like in an increasingly complex industrial world.Our OT Security practice works at the intersection of operational technology and cybersecurity—helping critical infrastructure owners across energy, utilities, oil & gas, manufacturing, water, and life sciences defend what... 
    Suggested
    Full time
    Work experience placement
    Live in
    Work at office
    Local area
    Remote work

    Accenture

    Carmel, IN
    2 days ago
  • $82.6k - $162.8k

    Position Summary Helping clients protect people, assets, and critical operations requires a practical approach to physical security and resilience. As a Physical Security Consultant, you will support clients in assessing risk, strengthening protective measures, and...
    Suggested
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    8 hours ago
  • $82.6k - $162.8k

    Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions... 
    Suggested
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    2 days ago
  • $82.6k - $162.8k

     ...Security & Risk Strategy Consultant Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful... 
    Suggested
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    1 day ago
  • $105.4k - $207.8k

     ...AI Security Senior ConsultantOur Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions... 
    Local area
    Worldwide
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    3 days ago
  • $82.6k - $162.8k

     ...understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our...  ...research; and collaborate with security operations center analysts, threat hunters, incident responders, Platform Operations... 
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    1 day ago
  • $77.9k - $153k

     ...Senior Information Security Analyst Job Locations US-IL-Chicago | US-IN-Evansville | US-MN-Lake Elmo | US-IN-Indianapolis | US-IN-Lafayette Category/Function Risk/Security Position Type Regular Full-Time Requisition ID 2... 
    Full time
    Work experience placement
    Immediate start

    Old National Bank

    Indianapolis, IN
    1 day ago
  • Job Title Benefits (employee contribution): Health insurance Health savings account Dental insurance Vision insurance Flexible spending accounts Life insurance Retirement plan All qualified applicants will receive consideration for employment without regard to age, ...
    Flexible hours

    inSync Staffing

    Fishers, IN
    3 days ago
  •  ...Software Quality Analyst At eimagine, we know that your best work happens when you live your best life and share your unique talents, so we do everything we can to be intentional in a remote enabled environment to make that possible. Recognized as a Best Places to Work... 
    Remote work

    eImagine Technology Group

    Indianapolis, IN
    4 days ago
  • $84.35k - $137.07k

     ...most recognized brands and a beacon for engineering excellence.Position Summary:As the Business Continuity and Industrial Security Analyst you will be responsible to support the implementation and adherence of the U.S. Department of War (DoW) and Rolls-Royce Corporate &... 
    Full time
    Remote work
    Flexible hours

    Rolls-Royce

    Indianapolis, IN
    4 days ago
  • OverviewThe Infosys Oracle unit is a global leader in providing comprehensive Oracle services that accelerate business growth and digital transformation. With over 25 years of experience, our team of experts delivers innovative solutions across various industry verticals...
    Full time
    Temporary work
    Relocation

    Infosys Technologies

    Indianapolis, IN
    8 hours ago
  • $69.4k - $158k

     ...Security AnalystThe Opportunity:As a security operations center analyst, you’re in the middle of the action, responding to and...  ...teamTS/SCI clearanceBachelor's degree in an Information Systems, Cybersecurity, or Engineering fieldClearance:Applicants selected will be subject... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work
    Shift work

    Booz Allen Hamilton

    Indianapolis, IN
    8 hours ago
  • $82.6k - $162.8k

    Position Summary Consultant - Technology Resilience Accelerate your career as a Consultant, Technical Resilience, helping clients strengthen their ability to prepare for, respond to, and recover from disruption. In this role, you will support the design and delivery...
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    8 hours ago
  • $59k - $79.6k

     ...The IT Configuration Analyst, Junior supports configuration management activities that keep the enterprise configuration management database (CMDB) accurate, complete, and reliable across infrastructure and application services. The role focuses on collecting, validating... 
    Contract work
    Work at office

    ASM Research, An Accenture Federal Services Company

    Indianapolis, IN
    1 day ago
  • $80k - $95k

     ...ITC Digital Solutions is seeking highly motivated Security Operations Analyst to join our team in Indianapolis, IN to support our government clients. The successful applicant will work closely with our clients to provide technical support in information security response... 
    Full time
    Local area

    Capgemini Government Solutions LLC

    Indianapolis, IN
    8 hours ago
  •  ...Job Title: Senior Security Operations Analyst Note: Open to Security Operations Analyst (2-4 years), Senior Security Operations...  ...edge Job Description: Defend, Innovate, and Elevate Your Cybersecurity Career As a Security Operations Analyst, you'll stand on... 
    Remote work

    Loxo

    Indianapolis, IN
    2 days ago
  •  ...AreAccenture Security helps organizations prepare, protect, detect, respond, and recover along with all points of the security lifecycle. Cybersecurity challenges are different for every business in every industry. Leveraging our global resources and advanced technologies, we... 
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Carmel, IN
    3 days ago
  • $163.4k - $322.1k

    Position Summary Drive strategic consulting, advisory, and delivery efforts that help clients strengthen physical security programs, align security capabilities to enterprise priorities, and build resilience across people, facilities, assets, and operations. This...
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    8 hours ago
  • $134.5k - $265.1k

    Position Summary Our Deloitte Cyber Defense & Resilience team recognizes that resilient organizations must protect not only data and technology, but also people, facilities, assets, and operations. Join our Physical Security consulting team to help clients address...
    Contract work
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    8 hours ago
  •  ...technology, and supporting operational teams during an acute crisis.You will partner closely with the Cyber Intelligence country lead, cybersecurity delivery leadership and account teams, and Accenture’s broader Cyber Resilience & Defense professionals to ensure our services... 
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Carmel, IN
    4 days ago
  • $152.7k - $294k

     ...strategic plan writing. Technical Depth: Broad and deep knowledge of information security domains and technologies – including cybersecurity architecture, risk management, identity and access management (IAM), incident response, and emerging threat mitigation techniques... 
    Summer holiday
    Local area
    Flexible hours
    Shift work

    Ernst & Young Oman

    Indianapolis, IN
    1 day ago
  •  ...strategy, and financial performance of managed SOC engagements, leading teams of managers and analysts - onshore and offshore - to solve some of today's toughest cybersecurity and organizational challenges.Recruiting for this role ends on 12/31/2026.Work you'll doAs an... 
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    8 hours ago
  •  ...to our diverse teams of passionate and expert professionals, including Managers, technical leads, and analysts, to help solve some of today's toughest cybersecurity and organizational challenges, enabling our clients to grow the business while managing evolving risk across... 
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    8 hours ago
  • Position Summary Deloitte helps organizations protect and grow their business by delivering risk management solutions across critical domains, including cyber. Within that environment, this role leads the delivery, growth, and continuous improvement of large-scale...
    Contract work
    Local area
    Visa sponsorship

    Deloitte

    Indianapolis, IN
    8 hours ago
  • IT Consultant Location: Indianapolis, IN (On-site) Type: Full-Time Industry: Civil Engineering / Infrastructure Overview Our client is seeking an experienced IT Consultant to join their growing IT Team. This role is ideal for a polished, service-oriented professional...
    Full time

    Designworks Talent LLC

    Indianapolis, IN
    3 days ago
  • We Are:Accenture is a leading global professional services company that helps the world’s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth, and enhance citizen services—creating tangible...
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Carmel, IN
    3 days ago
  • Job Title Provide advanced support for Roche Navify, investigating and resolving both application-level and backend server-related issues. Perform in-depth analysis of system functionality, interfaces, configurations, and workflows to identify root causes of technical...

    Insight Global

    Indianapolis, IN
    2 days ago
  • $55k - $65k

    Description Information Security Analyst Carmel, IN $55,000-$65,000/year - compensation may be adjusted based on the skills, experience, and education of the chosen candidate About First Farmers Bank & Trust First Farmers Bank & Trust has been proudly serving families... 
    Temporary work
    Casual work
    Work at office
    Local area

    First-Farmers-Bank-

    Carmel, IN
    2 days ago
  • Job Title: Information Security Analyst Contract: 6 Months Location: Indianapolis IN 46204 Job Mode: Hybrid (3 Days work from office...  ...Degree in information security or technology Familiar with cybersecurity security framework (e.g. NIST, ISO, SOC 2, CIS, Cobit, etc.) Computer... 
    Contract work
    Work at office
    Work from home

    campus4tech

    Indianapolis, IN
    6 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity Analyst. Be the first to apply!