exosIndianapolis, IN
Cyber Security Engineer
What You Will Do:
The Cybersecurity Engineer at EXOS owns the security stack that powers our SOC. You keep our detection and prevention tools healthy, current, and tuned across every client environment, and you find coverage gaps early. You report to the Security Operations Manager and serve as the engineering escalation point for Cybersecurity Analysts I, II, and III.This is a hands-on builder role. You will deploy, upgrade, and integrate tools, measure how well they protect each client, and bring clear recommendations on what to improve next. The role is built for an engineer with 5+ years in security or infrastructure engineering who enjoys making a multi-tenant stack run cleanly at scale.· Own administration and health of the SOC security stack, including security tools like Sentinel One, Crowd Strike, Splunk, Cisco Firepower, Cisco ASA, Cisco Umbrella, DNSFilter, Avanan, and our security awareness training platform.· Plan and deliver platform updates, agent upgrades, policy changes, and version lifecycles across client tenants. Every change goes through change control with testing, a maintenance window, and a rollback plan.· Deploy and onboard security tooling for new clients, including agent rollout, log source integration, policy baselines, and handoff documentation for the SOC.· Onboard log sources, maintain parsing and field extractions, monitor for stalled or missing sources, and keep license and storage use on target.· Build, tune, and maintain detections and correlation searches with the SOC analysts. Reduce false positive load and close coverage gaps mapped to MITRE ATT&CK.· Maintain perimeter and DNS security posture. Review Cisco Firepower and ASA rule sets, IPS policies, and VPN configurations, and manage Cisco Umbrella and DNSFilter policies across tenants.· Support phishing simulations and training campaigns in the security awareness platform.· Identify gaps across people, process, and technology. Run regular coverage reviews for agent deployment, log sources, and policy drift, benchmark against CIS Controls and NIST CSF, and present prioritized recommendations to the Security Operations Manager.· Evaluate new tools and features. Run proofs of concept, compare vendors, manage vendor support cases, and build business cases that weigh risk reduction, operational effort, and cost.· Automate repetitive work with Power Shell, Python, and platform APIs, and partner with the AI Automation Engineer on SOAR playbooks and integrations.· Support analysts during incidents with containment actions, emergency blocks, and tooling troubleshooting, and take part in the after-hours escalation rotation.· Keep engineering documentation current, including architecture diagrams, configuration standards, tool runbooks, and client-specific deployment notes. What You Have Done· 5+ years in IT or security, including 3+ years engineering or administering security platforms such as EDR, SIEM, XDR, SOAR, firewalls, IPS, Web Proxies, email security, etc.· Administration of DNS-layer and email security platforms such as Cisco Umbrella, DNSFilter, and Avanan.· Solid networking fundamentals, including TCP/IP, routing, switching, VLANs, DNS, DHCP, and proxy concepts.· Working knowledge of Windows Server, Active Directory, Entra ID, Microsoft 365, and Linux administration.· Scripting in Power Shell and/or Python, and comfort working with REST APIs.· Experience running change management, testing, and documentation for production security systems.· The ability to assess a control environment, spot gaps, and write clear recommendations with priority, effort, and business impact.· Clear communication with analysts, managers, and client IT teams, including written change notices and post-change summaries.· Relevant certifications such as CompTIA Security+, CySA+, Cisco CCNA, or equivalent experience.
Preferred Qualifications:
· Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline. Equivalent military training or certifications considered.· Prior MSP or MSSP experience in a multi-tenant model, including a multi-tenant PSA or ticketing platform (Connect Wise, Autotask, Service Now, or similar).· Multi-site and multi-tenant deployment experience, including managing agents and policies across many client consoles or a parent and child tenant structure.· Vendor certifications such as Splunk Core Certified Power User or Admin, Crowd Strike CCFA, Sentinel One platform certifications, or Cisco CCNP Security.· Advanced security certifications such as GIAC GSEC, GCIA, or GCDA, or CISSP.· Detection engineering experience with SPL, Sigma rules, KQL, or Sentinel One query syntax.· Experience with SOAR or rules-based automation, and comfort operationalizing playbooks alongside an AI Automation Engineer.· Exposure to the rest of our toolset, including Blumira, Velociraptor, Connect Secure, and Node Zero.· Configuration management or infrastructure-as-code experience (Ansible, Terraform, or similar).· Experience aligning security controls to frameworks such as CIS Controls, NIST CSF, SOC 2, HIPAA, or CMMC.
Also on the board Same function, level within a rung
Level
Senior
Location
Indianapolis, IN
Occupation
Information Security Engineers
Industry
Computer Systems Design Services
Posted
today