Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

EXOS

Cybersecurity Lead

Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
55
out of 100
Average of individual scores

Were these scores useful?

Job Description

Job Description Our Company In 2009 EXOS established itself as an IT consulting and staff augmentation firm. We specialize in focusing on what the client needs and adapting to how our client works. Our number one goal is to deliver the RIGHT solution, with the RIGHT resource, for the RIGHT price at the RIGHT time. The Company has three areas of focus:
Professional Services and Consulting:
As a full-service IT consulting firm, we offer a wide array of services to adapt to our clients' businesses. No matter what is needed, we have a solution that fits. Whether it be custom application development or providing highly specialized IT resources to run a project, we assist our clients to ensure their IT initiatives cross the finish line.
Staffing:
Our solutions foster stronger relationships with customers, suppliers, and partners, which greatly improve our clients' productivity, while reducing overall IT costs.
Managed Services:
We realize our clients don't have the time to worry about the most important tools that its people use--technology. We take care of our client's network and service its system. Our Values We are Empowering At EXOS we empower our clients by providing them with essential strategic IT guidance, reliable service, and the talent necessary to achieve their business goals. We empower our team by living a culture of collaboration, trust, and learning, creating growth opportunities, and charting a clear career path for all our team members. We are Connected At EXOS we are connected to our clients and their purpose. We are not just a talent and technology partner; we are an extension of your business. We seek to understand where leadership is driving the company, and we connect across all aspects of the business necessary to make that goal a reality. We are connected to the communities we serve and invested in organizations that make them great places to live. As the EXOS team, we are connected through our common commitment to our cultural imperatives: the "Three Ps" - Be Positive, Be Productive and Be Progressive in the since that we are always challenging each other to learn and grow. We are Trusted For more than fifteen years EXOS has been a trusted partner in providing Talent, IT and Cybersecurity solutions for our clients. Whether it's servicing large-scale enterprise clients or start up professional firms, our team is there to help solve pain points and provide strategic direction. The trust we have with one another as a team is earned. We live a culture of accountability with a goal of excellence. We are invested in one another's success, personally and professionally. We are a trust first, learn together and celebrate collectively team. What You Will Do The Cybersecurity Lead at
EXOS CYBER
is the on-site owner of cybersecurity delivery for our Evansville, Indiana client environment. You are the person in the building: the day-to-day security authority the client's leadership and IT staff turn to, the technical escalation point for the analysts and engineers supporting the environment, and the bridge between what our SOC sees remotely and what is actually happening on the ground. When something needs a decision or a plan, it comes to you. Beyond running operations, you set the direction. You own the client's security roadmap, translate risk into business-language recommendations that get funded, and lead a small team of EXOS cybersecurity professionals with a hands-on, mentor-first style. This is a senior, player-coach role designed for someone with 8+ years in cybersecurity (including 2+ years leading people or programs) who is ready to run a real-world security program end to end, on site, inside an environment that matters to the community it serves. Serve as the on-site cybersecurity lead and primary point of contact for the Evansville client. Own the relationship with client leadership and IT staff, run the recurring security cadence (weekly operational syncs, monthly reporting, quarterly roadmap reviews), and make sure the client always knows where they stand and what comes next. Lead and develop the EXOS cybersecurity team supporting the environment: set priorities, assign work, coach analysts and engineers, run regular one-on-ones and performance conversations, and build a clear growth path for each team member in partnership with the EXOS Cyber leadership team. Own the client's security program and roadmap. Assess the environment against any compliance and regulatory controls and, where applicable, CJIS and other regulatory requirements; identify gaps; and drive a prioritized, plan that moves the client forward each quarter with measurable outcomes. Serve as the senior technical escalation point for confirmed incidents in the environment, including but not limited to ransomware, business email compromise, account takeover, lateral movement, and data exfiltration. Lead scoping and impact assessment, containment through the EDR platform, identity isolation and credential rotation in the identity platform, eradication and recovery guidance, evidence preservation, root-cause analysis, and client communication through resolution. Coordinate with the EXOS SOC and MDR partners on detection and response for the environment. Review escalations, confirm the environment-specific context the remote team does not have, and close the loop so tuning, coverage gaps, and lessons learned make it back into detections and playbooks. Lead vulnerability and exposure management for the environment: run the scanning cadence, work directly with client system owners and the EXOS IT team to get findings fixed, track risk acceptance decisions, and report progress in terms leadership understands. Partner with the client's IT staff and EXOS IT for identity and access management security for the environment, including MFA and conditional access posture, privileged account hygiene, on-boarding/off-boarding/current account reviews, and identity threat detection and response (ITDR). Plan and lead security projects and control implementations from design through documentation and handoff, including new tooling rollouts, hardening initiatives, and platform migrations, delivering on time and with the client informed at every step. Run and assist with the client's security awareness, phishing simulation, and tabletop exercise program, and lead incident response plan development, testing, and annual review with client leadership.
Author the client-facing narrative:
monthly security reports, post-incident reports, after-action reviews, and board- or council-ready summaries covering what we saw, what it means, and what we recommend, in language a non-technical decision maker can act on. Serve as a trusted advisor to client leadership on cybersecurity strategy, technology investments, cyber insurance requirements, and risk management, and stay current on emerging threats, vulnerabilities, and industry trends so the guidance you give stays sharp. Contribute back to
EXOS Cyber:
share runbooks, playbooks, and lessons learned with the broader practice, support pre-sales and scoping conversations for similar engagements when asked, and help set the standard for what on-site cybersecurity leadership looks like at EXOS. Job Requirements What You Have Done 8+ years of experience in cybersecurity roles spanning security operations, incident response, engineering, or program leadership, with at least 2 years leading people, projects, or a security program. MSP/MSSP or multi-client experience strongly preferred. Proven ability to lead and develop a small team of security professionals, including setting priorities, coaching, giving kind and direct feedback, and building growth paths. Demonstrated ability to independently lead complex investigations and confirmed incidents to resolution across endpoint, identity, email, and network telemetry, and to direct others through them under pressure. Advanced command of an EDR platform and working experience with a SIEM, including query, pivot, and detection-tuning skills. Strong hands-on knowledge of enterprise identity and endpoint security, including directory services, conditional access, MFA, privileged access, and productivity suite security controls. Practical experience with vulnerability management programs, including scanning, prioritization, remediation coordination with IT teams, and risk acceptance tracking. Working fluency with security frameworks and standards such as CIS Controls, NIST CSF, and ISO/IEC 27001, and the ability to assess an environment against them and turn gaps into a prioritized plan. Familiarity with CJIS or public-sector requirements is a strong plus. Strong command of the incident response lifecycle, escalation criteria, evidence handling, and coordination with legal, insurance, and breach-notification stakeholders. Excellent written and verbal communication, with the ability to brief executives, boards, or councils, produce client-ready reports and roadmaps, and explain complex technical topics to non-technical audiences. Comfort operating as the senior security presence on site: making sound decisions independently, managing competing priorities, and knowing when to escalate to EXOS Cyber leadership. Solid fundamentals in networking protocols, Windows and Linux internals, cloud and SaaS security, and identity and access management. Relevant certifications such as
CISSP, CISM, GIAC
GCIH/GCIA/GCFA, or equivalent demonstrated experience. Ability to work on site in Evansville, Indiana, five days a week, with occasional travel to EXOS headquarters in the Indianapolis area. Preferred Qualifications Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline. Equivalent military training or certifications considered. Advanced certifications such as CISSP, CISM, CISA, or GIAC GSLC, GCIH, GCFA, or GCTI; offensive-informed credentials (OSCP, CRTO) a plus. Prior MSSP or MSP experience in a multi-tenant model, including a PSA/ticketing platform and co-managed IT delivery. Experience working with or inside public-sector, municipal, or regulated environments, including CJIS, HIPAA, or PCI DSS. Hands-on experience running an MDR service, an ITDR platform, and a SIEM in a managed services environment. Detection engineering and threat hunting experience, including converting hunt findings into durable detections. Experience with SOAR or rules-based automation and operationalizing playbooks alongside an AI Automation Engineer. Experience building or maturing a security program from the ground up, including policies, standards, incident response plans, and security awareness programs. Experience supporting cyber insurance applications, audits, and client-facing compliance attestations. Already have an account? Log in here