> Markdown version of [/jobs/ext/3654001-cyber-security-engineer](https://www.wearedevelopers.com/jobs/ext/3654001-cyber-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer - **Company:** EXOS, LLC - **Location:** United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Cisco PIX, Configuration Management, CompTIA Security+, Cyber Security, Dynamic Host Configuration Protocol, Domain Name System (DNS), Intrusion Detection and Prevention, Python (Programming Language), Linux System Administration, Windows Servers, Networking Basics, Routing, Windows PowerShell, Ansible, Kusto Query Language, TCP/IP, Virtual Local Area Networks, Scripting, National Institute of Standards and Technology Cybersecurity Framework, Falcon Platform, Information Technology, CIS Benchmarks, Firepower, Restful APIs, Terraform, Splunk, SentinelOne Expertise, Cisco, Servicenow - **Published:** October 9, 2026 - **Apply:** https://www.thejobnetwork.com/job/c76a236d-91cd-436b-bc19-367d046cc730/cyber-security-engineer ## About the Role · 5+ years in IT or security, including 3+ years engineering or administering security platforms such as EDR, SIEM, XDR, SOAR, firewalls, IPS, Web Proxies, email security, etc. \n · Administration of DNS-layer and email security platforms such as Cisco Umbrella, DNSFilter, and Avanan. \n · Solid networking fundamentals, including TCP/IP, routing, switching, VLANs, DNS, DHCP, and proxy concepts. \n · Working knowledge of Windows Server, Active Directory, Entra ID, Microsoft 365, and Linux administration. \n · Scripting in PowerShell and/or Python, and comfort working with REST APIs. \n · Experience running change management, testing, and documentation for production security systems. \n · The ability to assess a control environment, spot gaps, and write clear recommendations with priority, effort, and business impact. \n · Clear communication with analysts, managers, and client IT teams, including written change notices and post-change summaries. \n · Relevant certifications such as CompTIA Security+, CySA+, Cisco CCNA, or equivalent experience., n · Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline. Equivalent military training or certifications considered. \n · Prior MSP or MSSP experience in a multi-tenant model, including a multi-tenant PSA or ticketing platform (ConnectWise, Autotask, ServiceNow, or similar). \n · Multi-site and multi-tenant deployment experience, including managing agents and policies across many client consoles or a parent and child tenant structure. \n · Vendor certifications such as Splunk Core Certified Power User or Admin, CrowdStrike CCFA, SentinelOne platform certifications, or Cisco CCNP Security. \n · Advanced security certifications such as GIAC GSEC, GCIA, or GCDA, or CISSP. \n · Detection engineering experience with SPL, Sigma rules, KQL, or SentinelOne query syntax. \n · Experience with SOAR or rules-based automation, and comfort operationalizing playbooks alongside an AI Automation Engineer. \n · Exposure to the rest of our toolset, including Blumira, Velociraptor, ConnectSecure, and NodeZero. \n · Configuration management or infrastructure-as-code experience (Ansible, Terraform, or similar). \n · Experience aligning security controls to frameworks such as CIS Controls, NIST CSF, SOC 2, HIPAA, or CMMC. ## Description The Cybersecurity Engineer at EXOS owns the security stack that powers our SOC. You keep our detection and prevention tools healthy, current, and tuned across every client environment, and you find coverage gaps early. You report to the Security Operations Manager and serve as the engineering escalation point for Cybersecurity Analysts I, II, and III., This is a hands-on builder role. You will deploy, upgrade, and integrate tools, measure how well they protect each client, and bring clear recommendations on what to improve next. The role is built for an engineer with 5+ years in security or infrastructure engineering who enjoys making a multi-tenant stack run cleanly at scale. \n · Own administration and health of the SOC security stack, including security tools like SentinelOne, CrowdStrike, Splunk, Cisco Firepower, Cisco ASA, Cisco Umbrella, DNSFilter, Avanan, and our security awareness training platform. \n · Plan and deliver platform updates, agent upgrades, policy changes, and version lifecycles across client tenants. Every change goes through change control with testing, a maintenance window, and a rollback plan. \n · Deploy and onboard security tooling for new clients, including agent rollout, log source integration, policy baselines, and handoff documentation for the SOC. \n · Onboard log sources, maintain parsing and field extractions, monitor for stalled or missing sources, and keep license and storage use on target.