Cybersecurity Lead

EXOS

Evansville (IN)

On-site

USD 120,000 - 180,000

Full time

9 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

EXOS is seeking an on-site Cybersecurity Lead to own the Evansville client environment. You will be the day-to-day security authority, mentor a small EXOS team, and translate risk into business-focused recommendations that get funded.

You will drive the security roadmap, partner with client IT leadership, and coordinate with EXOS SOC/MDR teams to ensure robust detection, containment, and recovery across endpoints, identities, and cloud services.

Qualifications

  • 8+ years in cybersecurity roles spanning security operations, incident response, engineering, or program leadership.
  • Experience leading a small security team and driving programs.
  • Proven ability to independently lead complex investigations to resolution.
  • Strong knowledge of enterprise identity, endpoint security, and cloud security.
  • Familiarity with CJIS, CIS, NIST CSF, ISO/IEC 27001 is a plus.

Responsibilities

  • Serve as on-site cybersecurity lead and primary client contact; manage relationships with client leadership and IT staff.
  • Own and drive the client security program and roadmap, assess controls, and track quarterly progress.
  • Lead incident response for major events with scoping, containment, eradication, and communication.
  • Coordinate with EXOS SOC/MDR partners to tune detections and improve playbooks.
  • Oversee vulnerability management and risk acceptance reporting to leadership.
  • Develop and deliver client-facing security reports, roadmaps, and after-action reviews.

Skills

Cybersecurity leadership
Incident response
EDR/SIEM expertise
Identity and access management
Vulnerability management
Regulatory compliance (NIST/CIS/ISO)
On-site management
Executive communication

Education

Bachelor's degree in Cybersecurity/IT or related
CISSP/CISM/GIAC or equivalent

Tools

EDR platform
SIEM

Job description

The Cybersecurity Lead at EXOS CYBER is the on-site owner of cybersecurity delivery for our Evansville, Indiana client environment. You are the person in the building: the day-to-day security authority the client's leadership and IT staff turn to, the technical escalation point for the analysts and engineers supporting the environment, and the bridge between what our SOC sees remotely and what is actually happening on the ground. When something needs a decision or a plan, it comes to you.

Beyond running operations, you set the direction. You own the client's security roadmap, translate risk into business-language recommendations that get funded, and lead a small team of EXOS cybersecurity professionals with a hands-on, mentor-first style. This is a senior, player-coach role designed for someone with 8+ years in cybersecurity (including 2+ years leading people or programs) who is ready to run a real-world security program end to end, on site, inside an environment that matters to the community it serves.

  • Serve as the on-site cybersecurity lead and primary point of contact for the Evansville client. Own the relationship with client leadership and IT staff, run the recurring security cadence (weekly operational syncs, monthly reporting, quarterly roadmap reviews), and make sure the client always knows where they stand and what comes next.
  • Lead and develop the EXOS cybersecurity team supporting the environment: set priorities, assign work, coach analysts and engineers, run regular one-on-ones and performance conversations, and build a clear growth path for each team member in partnership with the EXOS Cyber leadership team.
  • Own the client's security program and roadmap. Assess the environment against any compliance and regulatory controls and, where applicable, CJIS and other regulatory requirements; identify gaps; and drive a prioritized, plan that moves the client forward each quarter with measurable outcomes.
  • Serve as the senior technical escalation point for confirmed incidents in the environment, including but not limited to ransomware, business email compromise, account takeover, lateral movement, and data exfiltration. Lead scoping and impact assessment, containment through the EDR platform, identity isolation and credential rotation in the identity platform, eradication and recovery guidance, evidence preservation, root-cause analysis, and client communication through resolution.
  • Coordinate with the EXOS SOC and MDR partners on detection and response for the environment. Review escalations, confirm the environment-specific context the remote team does not have, and close the loop so tuning, coverage gaps, and lessons learned make it back into detections and playbooks.
  • Lead vulnerability and exposure management for the environment: run the scanning cadence, work directly with client system owners and the EXOS IT team to get findings fixed, track risk acceptance decisions, and report progress in terms leadership understands.
  • Partner with the client's IT staff and EXOS IT for identity and access management security for the environment, including MFA and conditional access posture, privileged account hygiene, on-boarding/off-boarding/current account reviews, and identity threat detection and response (ITDR).
  • Plan and lead security projects and control implementations from design through documentation and handoff, including new tooling rollouts, hardening initiatives, and platform migrations, delivering on time and with the client informed at every step.
  • Run and assist with the client's security awareness, phishing simulation, and tabletop exercise program, and lead incident response plan development, testing, and annual review with client leadership.
  • Author the client-facing narrative: monthly security reports, post-incident reports, after-action reviews, and board- or council-ready summaries covering what we saw, what it means, and what we recommend, in language a non-technical decision maker can act on.
  • Serve as a trusted advisor to client leadership on cybersecurity strategy, technology investments, cyber insurance requirements, and risk management, and stay current on emerging threats, vulnerabilities, and industry trends so the guidance you give stays sharp.
  • Contribute back to EXOS Cyber: share runbooks, playbooks, and lessons learned with the broader practice, support pre-sales and scoping conversations for similar engagements when asked, and help set the standard for what on-site cybersecurity leadership looks like at EXOS.
What You Have Done
  • 8+ years of experience in cybersecurity roles spanning security operations, incident response, engineering, or program leadership, with at least 2 years leading people, projects, or a security program. MSP/MSSP or multi-client experience strongly preferred.
  • Proven ability to lead and develop a small team of security professionals, including setting priorities, coaching, giving kind and direct feedback, and building growth paths.
  • Demonstrated ability to independently lead complex investigations and confirmed incidents to resolution across endpoint, identity, email, and network telemetry, and to direct others through them under pressure.
  • Advanced command of an EDR platform and working experience with a SIEM, including query, pivot, and detection-tuning skills.
  • Strong hands-on knowledge of enterprise identity and endpoint security, including directory services, conditional access, MFA, privileged access, and productivity suite security controls.
  • Practical experience with vulnerability management programs, including scanning, prioritization, remediation coordination with IT teams, and risk acceptance tracking.
  • Working fluency with security frameworks and standards such as CIS Controls, NIST CSF, and ISO/IEC 27001, and the ability to assess an environment against them and turn gaps into a prioritized plan. Familiarity with CJIS or public-sector requirements is a strong plus.
  • Strong command of the incident response lifecycle, escalation criteria, evidence handling, and coordination with legal, insurance, and breach-notification stakeholders.
  • Excellent written and verbal communication, with the ability to brief executives, boards, or councils, produce client-ready reports and roadmaps, and explain complex technical topics to non-technical audiences.
  • Comfort operating as the senior security presence on site: making sound decisions independently, managing competing priorities, and knowing when to elevate to EXOS Cyber leadership.
  • Solid fundamentals in networking protocols, Windows and Linux internals, cloud and SaaS security, and identity and access management.
  • Relevant certifications such as CISSP, CISM, GIAC GCIH/GCIA/GCFA, or equivalent demonstrated experience.
  • Ability to work on site in Evansville, Indiana, five days a week, with occasional travel to EXOS headquarters in the Indianapolis area.
Preferred Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline. Equivalent military training or certifications considered.
  • Advanced certifications such as CISSP, CISM, CISA, or GIAC GSLC, GCIH, GCFA, or GCTI; offensive-informed credentials (OSCP, CRTO) a plus.
  • Prior MSSP or MSP experience in a multi-tenant model, including a PSA/ticketing platform and co-managed IT delivery.
  • Experience working with or inside public-sector, municipal, or regulated environments, including CJIS, HIPAA, or PCI DSS.
  • Hands-on experience running an MDR service, an ITDR platform, and a SIEM in a managed services environment.
  • Detection engineering and threat hunting experience, including converting hunt findings into durable detections.
  • Experience with SOAR or rules-based automation and operationalizing playbooks alongside an AI Automation Engineer.
  • Experience building or maturing a security program from the ground up, including policies, standards, incident response plans, and security awareness programs.
  • Experience supporting cyber insurance applications, audits, and client-facing compliance attestations.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst
Cybersecurity Analyst

EXOS • Indianapolis (IN)

On-site
USD 90,000 - 120,000
Assistant Vice President Cybersecurity - Offensive Security Lead
Assistant Vice President Cybersecurity - Offensive Security Lead

EXL • Jersey City (NJ)

On-site
USD 125,000 - 150,000
Competitive salary
Comprehensive health benefits
Flexible work environment
Principle Network Engineer
Principle Network Engineer

EXOS • Evansville (IN)

On-site
USD 90,000 - 130,000
Service Delivery Manager
Service Delivery Manager

EXOS • Evansville (IN)

On-site
USD 90,000 - 130,000
Security Operations & Engineering Lead
Security Operations & Engineering Lead

Jobtailor • Brea (CA)

On-site
USD 170,000 - 250,000
Principle Systems Administrator
Principle Systems Administrator

EXOS • Evansville (IN)

On-site
USD 110,000 - 160,000
Lead, Cybersecurity Architecture & Operations
Lead, Cybersecurity Architecture & Operations

Culligan International • Northern (KY)

Hybrid
USD 140,000 - 180,000
Assistant Vice President Cybersecurity (Healthcare & Life Sciences)
Assistant Vice President Cybersecurity (Healthcare & Life Sciences)

EXL • Jersey City (NJ)

On-site
USD 125,000 - 160,000
Comprehensive benefits package
Mentorship opportunities
Sr. Cyber Security Engineer, Exposure Management
Sr. Cyber Security Engineer, Exposure Management

CHS Corporate • United States

On-site
USD 140,000 - 190,000
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000