Skip to main content
EXOS logo

Cybersecurity Engineer

EXOS
1 day ago
Contract
On-site
Indianapolis, Indiana, United States

Job Description

Our Company

In 2009 EXOS established itself as an IT consulting and staff augmentation firm. We specialize in focusing on what the client needs and adapting to how our client works. Our number one goal is to deliver the RIGHT solution, with the RIGHT resource, for the RIGHT price at the RIGHT time.


The Company has three areas of focus:


Professional Services and Consulting: As a full-service IT consulting firm, we offer a wide array of services to adapt to our clients' businesses. No matter what is needed, we have a solution that fits. Whether it be custom application development or providing highly specialized IT resources to run a project, we assist our clients to ensure their IT initiatives cross the finish line.


Staffing: Our solutions foster stronger relationships with customers, suppliers, and partners, which greatly improve our clients' productivity, while reducing overall IT costs.


Managed Services: We realize our clients don't have the time to worry about the most important tools that their people use: technology. We take care of our clients' networks and service their systems.


Our Values

We are Empowering


At EXOS we empower our clients by providing them with essential strategic IT guidance, reliable service, and the talent necessary to achieve their business goals. We empower our team by living a culture of collaboration, trust, and learning, creating growth opportunities, and charting a clear career path for all our team members.


We are Connected

At EXOS we are connected to our clients and their purpose. We are not just a talent and technology partner; we are an extension of your business. We seek to understand where leadership is driving the company, and we connect across all aspects of the business necessary to make that goal a reality. We are connected to the communities we serve and invested in organizations that make them great places to live. As the EXOS team, we are connected through our common commitment to our cultural imperatives, the “Three Ps”: Be Positive, Be Productive and Be Progressive, in the sense that we are always challenging each other to learn and grow.


We are Trusted

For more than fifteen years EXOS has been a trusted partner in providing Talent, IT and Cybersecurity solutions for our clients. Whether it's servicing large-scale enterprise clients or start up professional firms, our team is there to help solve pain points and provide strategic direction. The trust we have with one another as a team is earned. We live a culture of accountability with a goal of excellence. We are invested in one another's success, personally and professionally. We are a trust first, learn together and celebrate collectively team.

What You Will Do

The Cybersecurity Engineer at EXOS owns the security stack that powers our SOC. You keep our detection and prevention tools healthy, current, and tuned across every client environment, and you find coverage gaps early. You report to the Security Operations Manager and serve as the engineering escalation point for Cybersecurity Analysts I, II, and III.


This is a hands-on builder role. You will deploy, upgrade, and integrate tools, measure how well they protect each client, and bring clear recommendations on what to improve next. The role is built for an engineer with 5+ years in security or infrastructure engineering who enjoys making a multi-tenant stack run cleanly at scale.

· Own administration and health of the SOC security stack, including security tools like SentinelOne, CrowdStrike, Splunk, Cisco Firepower, Cisco ASA, Cisco Umbrella, DNSFilter, Avanan, and our security awareness training platform.

· Plan and deliver platform updates, agent upgrades, policy changes, and version lifecycles across client tenants. Every change goes through change control with testing, a maintenance window, and a rollback plan.

· Deploy and onboard security tooling for new clients, including agent rollout, log source integration, policy baselines, and handoff documentation for the SOC.

· Onboard log sources, maintain parsing and field extractions, monitor for stalled or missing sources, and keep license and storage use on target.

· Build, tune, and maintain detections and correlation searches with the SOC analysts. Reduce false positive load and close coverage gaps mapped to MITRE ATT&CK.

· Maintain perimeter and DNS security posture. Review Cisco Firepower and ASA rule sets, IPS policies, and VPN configurations, and manage Cisco Umbrella and DNSFilter policies across tenants.

· Support phishing simulations and training campaigns in the security awareness platform.

· Identify gaps across people, process, and technology. Run regular coverage reviews for agent deployment, log sources, and policy drift, benchmark against CIS Controls and NIST CSF, and present prioritized recommendations to the Security Operations Manager.

· Evaluate new tools and features. Run proofs of concept, compare vendors, manage vendor support cases, and build business cases that weigh risk reduction, operational effort, and cost.

· Automate repetitive work with PowerShell, Python, and platform APIs, and partner with the AI Automation Engineer on SOAR playbooks and integrations.

· Support analysts during incidents with containment actions, emergency blocks, and tooling troubleshooting, and take part in the after-hours escalation rotation.

· Keep engineering documentation current, including architecture diagrams, configuration standards, tool runbooks, and client-specific deployment notes.


Job Requirements

What You Have Done

·  5+ years in IT or security, including 3+ years engineering or administering security platforms such as EDR, SIEM, XDR, SOAR, firewalls, IPS, Web Proxies, email security, etc.

· Administration of DNS-layer and email security platforms such as Cisco Umbrella, DNSFilter, and Avanan.

· Solid networking fundamentals, including TCP/IP, routing, switching, VLANs, DNS, DHCP, and proxy concepts.

· Working knowledge of Windows Server, Active Directory, Entra ID, Microsoft 365, and Linux administration.

· Scripting in PowerShell and/or Python, and comfort working with REST APIs.

· Experience running change management, testing, and documentation for production security systems.

· The ability to assess a control environment, spot gaps, and write clear recommendations with priority, effort, and business impact.

· Clear communication with analysts, managers, and client IT teams, including written change notices and post-change summaries.

· Relevant certifications such as CompTIA Security+, CySA+, Cisco CCNA, or equivalent experience.


Preferred Qualifications

· Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline. Equivalent military training or certifications considered.

· Prior MSP or MSSP experience in a multi-tenant model, including a multi-tenant PSA or ticketing platform (ConnectWise, Autotask, ServiceNow, or similar).

· Multi-site and multi-tenant deployment experience, including managing agents and policies across many client consoles or a parent and child tenant structure.

· Vendor certifications such as Splunk Core Certified Power User or Admin, CrowdStrike CCFA, SentinelOne platform certifications, or Cisco CCNP Security.

· Advanced security certifications such as GIAC GSEC, GCIA, or GCDA, or CISSP.

· Detection engineering experience with SPL, Sigma rules, KQL, or SentinelOne query syntax.

· Experience with SOAR or rules-based automation, and comfort operationalizing playbooks alongside an AI Automation Engineer.

· Exposure to the rest of our toolset, including Blumira, Velociraptor, ConnectSecure, and NodeZero.

· Configuration management or infrastructure-as-code experience (Ansible, Terraform, or similar).

· Experience aligning security controls to frameworks such as CIS Controls, NIST CSF, SOC 2, HIPAA, or CMMC.