Cyber Security Engineer

EXOS

Indianapolis (IN)

On-site

USD 100,000 - 140,000

Full time

18 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

EXOS is seeking a Cybersecurity Engineer to own and maintain the SOC security stack across multiple client environments. You will deploy, upgrade, and integrate tools, measure protection, and provide clear recommendations for improvement.

This hands-on role requires 5+ years in security or infra engineering and the ability to run a multi-tenant stack at scale. You will tune detections, coordinate with SOC analysts, and drive changes through controlled processes while maintaining documentation

Qualifications

  • 5+ years in IT or security, including 3+ years engineering or administering security platforms such as EDR, SIEM, XDR, SOAR, firewalls, IPS, Web Proxies, email security, etc.
  • Administration of DNS-layer and email security platforms such as Cisco Umbrella, DNSFilter, and Avanan.
  • Solid networking fundamentals, including TCP/IP, routing, switching, VLANs, DNS, DHCP, and proxy concepts.
  • Working knowledge of Windows Server, Active Directory, Entra ID, Microsoft 365, and Linux administration.
  • Scripting in PowerShell and/or Python, and comfort working with REST APIs.
  • Experience running change management, testing, and documentation for production security systems.
  • The ability to assess a control environment, spot gaps, and write clear recommendations with priority, effort, and business impact.
  • Clear communication with analysts, managers, and client IT teams, including written change notices and post-change summaries.
  • Relevant certifications such as CompTIA Security+, CySA+, Cisco CCNA, or equivalent experience.

Responsibilities

  • Own administration and health of the SOC security stack, including security tools like SentinelOne, CrowdStrike, Splunk, Cisco Firepower, Cisco ASA, Cisco Umbrella, DNSFilter, Avanan, and our security awareness training platform.
  • Plan and deliver platform updates, agent upgrades, policy changes, and version lifecycles across client tenants. Every change goes through change control with testing, a maintenance window, and a rollback plan.
  • Deploy and onboard security tooling for new clients, including agent rollout, log source integration, policy baselines, and handoff documentation for the SOC.
  • Onboard log sources, maintain parsing and field extractions, monitor for stalled or missing sources, and keep license and storage use on target.
  • Build, tune, and maintain detections and correlation searches with the SOC analysts. Reduce false positive load and close coverage gaps mapped to MITRE ATT&CK.
  • Maintain perimeter and DNS security posture. Review Cisco Firepower and ASA rule sets, IPS policies, and VPN configurations, and manage Cisco Umbrella and DNSFilter policies across tenants.
  • Support phishing simulations and training campaigns in the security awareness platform.
  • Identify gaps across people, process, and technology. Run regular coverage reviews for agent deployment, log sources, and policy drift, benchmark against CIS Controls and NIST CSF, and present prioritized recommendations to the Security Operations Manager.
  • Evaluate new tools and features. Run proofs of concept, compare vendors, manage vendor support cases, and build business cases that weigh risk reduction, operational effort, and cost.
  • Automate repetitive work with PowerShell, Python, and platform APIs, and partner with the AI Automation Engineer on SOAR playbooks and integrations.
  • Support analysts during incidents with containment actions, emergency blocks, and tooling troubleshooting, and take part in the after-hours escalation rotation.
  • Keep engineering documentation current, including architecture diagrams, configuration standards, tool runbooks, and client-specific deployment notes.

Skills

Security engineering
Security platforms
DNS security
Networking fundamentals
Windows & Linux admin
Scripting (PowerShell/Python)
REST APIs
Change management
Clear communication
Security certifications

Education

Bachelor’s degree in Cybersecurity/IT/CS

Tools

Splunk
CrowdStrike
SentinelOne
Cisco Firepower/ASA
Cisco Umbrella
DNSFilter
Avanan

Job description

The Cybersecurity Engineer at EXOS owns the security stack that powers our SOC. You keep our detection and prevention tools healthy, current, and tuned across every client environment, and you find coverage gaps early. You report to the Security Operations Manager and serve as the engineering escalation point for Cybersecurity Analysts I, II, and III.

This is a hands-on builder role. You will deploy, upgrade, and integrate tools, measure how well they protect each client, and bring clear recommendations on what to improve next. The role is built for an engineer with 5+ years in security or infrastructure engineering who enjoys making a multi-tenant stack run cleanly at scale.

  • Own administration and health of the SOC security stack, including security tools like SentinelOne, CrowdStrike, Splunk, Cisco Firepower, Cisco ASA, Cisco Umbrella, DNSFilter, Avanan, and our security awareness training platform.
  • Plan and deliver platform updates, agent upgrades, policy changes, and version lifecycles across client tenants. Every change goes through change control with testing, a maintenance window, and a rollback plan.
  • Deploy and onboard security tooling for new clients, including agent rollout, log source integration, policy baselines, and handoff documentation for the SOC.
  • Onboard log sources, maintain parsing and field extractions, monitor for stalled or missing sources, and keep license and storage use on target.
  • Build, tune, and maintain detections and correlation searches with the SOC analysts. Reduce false positive load and close coverage gaps mapped to MITRE ATT&CK.
  • Maintain perimeter and DNS security posture. Review Cisco Firepower and ASA rule sets, IPS policies, and VPN configurations, and manage Cisco Umbrella and DNSFilter policies across tenants.
  • Support phishing simulations and training campaigns in the security awareness platform.
  • Identify gaps across people, process, and technology. Run regular coverage reviews for agent deployment, log sources, and policy drift, benchmark against CIS Controls and NIST CSF, and present prioritized recommendations to the Security Operations Manager.
  • Evaluate new tools and features. Run proofs of concept, compare vendors, manage vendor support cases, and build business cases that weigh risk reduction, operational effort, and cost.
  • Automate repetitive work with PowerShell, Python, and platform APIs, and partner with the AI Automation Engineer on SOAR playbooks and integrations.
  • Support analysts during incidents with containment actions, emergency blocks, and tooling troubleshooting, and take part in the after-hours escalation rotation.
  • Keep engineering documentation current, including architecture diagrams, configuration standards, tool runbooks, and client-specific deployment notes.
What You Have Done
  • 5+ years in IT or security, including 3+ years engineering or administering security platforms such as EDR, SIEM, XDR, SOAR, firewalls, IPS, Web Proxies, email security, etc.
  • Administration of DNS-layer and email security platforms such as Cisco Umbrella, DNSFilter, and Avanan.
  • Solid networking fundamentals, including TCP/IP, routing, switching, VLANs, DNS, DHCP, and proxy concepts.
  • Working knowledge of Windows Server, Active Directory, Entra ID, Microsoft 365, and Linux administration.
  • Scripting in PowerShell and/or Python, and comfort working with REST APIs.
  • Experience running change management, testing, and documentation for production security systems.
  • The ability to assess a control environment, spot gaps, and write clear recommendations with priority, effort, and business impact.
  • Clear communication with analysts, managers, and client IT teams, including written change notices and post-change summaries.
  • Relevant certifications such as CompTIA Security+, CySA+, Cisco CCNA, or equivalent experience.
Preferred Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline. Equivalent military training or certifications considered.
  • Prior MSP or MSSP experience in a multi-tenant model, including a multi-tenant PSA or ticketing platform (ConnectWise, Autotask, ServiceNow, or similar).
  • Multi-site and multi-tenant deployment experience, including managing agents and policies across many client consoles or a parent and child tenant structure.
  • Vendor certifications such as Splunk Core Certified Power User or Admin, CrowdStrike CCFA, SentinelOne platform certifications, or Cisco CCNP Security.
  • Advanced security certifications such as GIAC GSEC, GCIA, or GCDA, or CISSP.
  • Detection engineering experience with SPL, Sigma rules, KQL, or SentinelOne query syntax.
  • Experience with SOAR or rules-based automation, and comfort operationalizing playbooks alongside an AI Automation Engineer.
  • Exposure to the rest of our toolset, including Blumira, Velociraptor, ConnectSecure, and NodeZero.
  • Configuration management or infrastructure-as-code experience (Ansible, Terraform, or similar).
  • Experience aligning security controls to frameworks such as CIS Controls, NIST CSF, SOC 2, HIPAA, or CMMC.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Systems Security Professional
Information Systems Security Professional

Vytwo • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Cyber Security Engineer
Cyber Security Engineer

PowerGrid Services • Hartselle (AL)

On-site
USD 90,000 - 130,000
Cyber Security Engineer
Cyber Security Engineer

PowerGrid Services, LLC • Hartselle (AL), Northern (KY)

Hybrid
USD 80,000 - 110,000
Security Engineer
Security Engineer

AccruePartners • Charlotte (NC)

On-site
USD 110,000 - 140,000
Cyber Security Engineer
Cyber Security Engineer

Qualibar • United States

Hybrid
USD 120,000 - 180,000
Security Engineer
Security Engineer

Eleven Recruiting • San Francisco (CA)

On-site
USD 120,000 - 160,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

On-site
USD 80,000 - 110,000
Engineer, Security
Engineer, Security

11:11 Systems • United States

On-site
USD 120,000 - 160,000
Security Operations Lead
Security Operations Lead

The Phoenix Group • Washington

On-site
USD 140,000 - 190,000