Our Company
In 2009 EXOS established itself as an IT consulting and staff augmentation firm. We specialize in focusing on what the client needs and adapting to how our client works. Our number one goal is to deliver the RIGHT solution, with the RIGHT resource, for the RIGHT price at the RIGHT time.
The Company has three areas of focus:
Professional Services and Consulting: As a full-service IT consulting firm, we offer a wide array of services to adapt to our clients' businesses. No matter what is needed, we have a solution that fits. Whether it be custom application development or providing highly specialized IT resources to run a project, we assist our clients to ensure their IT initiatives cross the finish line.
Staffing: Our solutions foster stronger relationships with customers, suppliers, and partners, which greatly improve our clients' productivity, while reducing overall IT costs.
Managed Services: We realize our clients don't have the time to worry about the most important tools that their people use: technology. We take care of our clients' networks and service their systems.
We are Empowering
At EXOS we empower our clients by providing them with essential strategic IT guidance, reliable service, and the talent necessary to achieve their business goals. We empower our team by living a culture of collaboration, trust, and learning, creating growth opportunities, and charting a clear career path for all our team members.
We are Connected
At EXOS we are connected to our clients and their purpose. We are not just a talent and technology partner; we are an extension of your business. We seek to understand where leadership is driving the company, and we connect across all aspects of the business necessary to make that goal a reality. We are connected to the communities we serve and invested in organizations that make them great places to live. As the EXOS team, we are connected through our common commitment to our cultural imperatives, the “Three Ps”: Be Positive, Be Productive and Be Progressive, in the sense that we are always challenging each other to learn and grow.
We are Trusted
For more than fifteen years EXOS has been a trusted partner in providing Talent, IT and Cybersecurity solutions for our clients. Whether it's servicing large-scale enterprise clients or start up professional firms, our team is there to help solve pain points and provide strategic direction. The trust we have with one another as a team is earned. We live a culture of accountability with a goal of excellence. We are invested in one another's success, personally and professionally. We are a trust first, learn together and celebrate collectively team.
What You Will Do
The Security Operations Center (SOC) Manager at EXOS leads the SOC. You own how we detect, respond to, and report on threats across every client environment we protect. You also lead the team that does that work every day: Cybersecurity Analysts at Tiers 1, 2, and 3, and a Cybersecurity Engineer who owns our security tooling.
This is a player-coach role. You will step into the hardest investigations, run incident response when it matters most, and bring a forensics and offensive security mindset to how we build and validate detections. You will also hire, coach, and grow the team, and partner with EXOS Cyber leadership on service strategy. The role is built for a leader with 8+ years in security operations and incident response who enjoys building a team as much as closing a hard case.
· Lead day-to-day SOC operations across a multi-tenant client base. Own queue health, shift coverage, escalation paths, and SLA performance for response, escalation, and client communication.
· Serve alongside the incident commander for major incidents, including ransomware, business email compromise, account takeover, and data exfiltration. Assist with scoping, containment, eradication, recovery, and client communication through resolution.
· Assist in after-action reviews that turn every significant incident into concrete improvements in detections, playbooks, and client guidance.
· Guide timeline reconstruction, evidence preservation, and chain of custody. Support breach notification, legal, and cyber insurance coordination when an incident calls for it.
· Lead purple team and adversary emulation exercises with the Analyst III and Cybersecurity Engineer, and turn attacker TTPs into detections we validate end to end.
· Lead and develop the SOC team. Hire, onboard, coach, and run one-on-ones and performance reviews for the Cybersecurity Engineer and Analysts I, II, and III. Build clear development plans that support our promote-from-within, tier-based career path.
· Set direction for the security stack with the Cybersecurity Engineer. Prioritize tooling updates, gap assessments, and recommendations across tools such as SentinelOne, CrowdStrike, Splunk, Cisco Firepower, Cisco ASA, Cisco Umbrella, DNSFilter, Avanan, and our security awareness training platform.
· Own detection strategy at the program level. Track coverage against MITRE ATT&CK, prioritize tuning and new use cases, and partner with the AI Automation Engineers to operationalize playbooks through automation.
· Build SOC process maturity through runbooks, playbooks, investigation standards, QA reviews, and shift handoffs. Report on the metrics that show how the service is performing, including MTTA, MTTR, escalation accuracy, and false positive rate.
· Lead security reviews and QBRs, present monthly reporting on what we saw, what it means, and what we recommend, and translate technical findings into business decisions.
· Partner with Account Management, Service Delivery, and EXOS leadership on client onboarding, capacity planning, and scoping for new managed security engagements.
What You Have Done
8+ years in security operations, incident response, or MSP/ MSSP security roles, including 3+ years leading a SOC, IR team, or security engineering team.
· Proven experience as incident commander on confirmed incidents such as ransomware, business email compromise, and account compromise, from first alert through recovery and after-action review.
· Hands-on digital forensics and incident response background, including host, memory, and network forensics, timeline reconstruction, and evidence handling.
· Penetration testing, red team, or adversary emulation experience, and the ability to apply that attacker perspective to detection and defense.
· Advanced command of an EDR (SentinelOne, CrowdStrike, or Defender for Endpoint) and a SIEM (Splunk, Sentinel, Blumira, or QRadar) at the query, pivot, and detection-authoring level.
· Working knowledge of network and perimeter controls, including next-generation firewalls (Cisco Firepower, Cisco ASA), DNS-layer security (Cisco Umbrella, DNSFilter), and cloud email security (Avanan or similar).
· Experience building SOC processes from the ground up: runbooks, playbooks, escalation criteria, QA programs, and operational metrics.
· A track record of hiring, coaching, and developing analysts and engineers, with the ability to give kind and direct feedback and grow people into their next role.
· Strong fluency in the incident response lifecycle, MITRE ATT&CK, and frameworks such as NIST CSF, NIST SP 800-61, and CIS Controls.
· Excellent written and verbal communication, including executive-ready incident reports and the steadiness to guide client leadership through a major incident.
· Comfort owning SLAs and priorities across many clients at once, and availability to lead the team through after-hours incidents.
· CISSP or CISM, plus GIAC GCIH (or an equivalent incident handling certification).
· Bachelor's or master's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline. Equivalent military training or certifications considered.
· CISSP, CISM, SANS LDR/MGT551
· Forensics certifications such as GIAC GCFA, GCFE, or GNFA, and offensive credentials such as OSCP, GPEN, or PNPT.
· Prior MSP or MSSP experience in a multi-tenant model, including a multi-tenant PSA or ticketing platform (ConnectWise, Autotask, ServiceNow, or similar).
· Experience leading security operations across multiple sites and client tenants, including distributed or multi-location SOC teams.
· Direct experience with our stack: SentinelOne, CrowdStrike, Splunk, Cisco Firepower, Cisco ASA, Cisco Umbrella, DNSFilter, Avanan, and security awareness training platforms.
· Experience with SOAR or automation-driven SOC operations, and comfort working alongside an AI Automation Engineer.
· DFIR tooling depth (Velociraptor or comparable) and experience working with legal counsel, cyber insurance carriers, and breach coaches during major incidents.
· Experience supporting clients with compliance requirements such as SOC 2, HIPAA, PCI DSS, or CMMC.
· Experience building SOC training programs and tiered analyst career paths.
| Location | Indianapolis, IN |
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder