The details on this configuration will depend on how the ex is configured but these will be the basic steps.
This would move the bgp from the ex to the srx
Copy the isp interface configuration from the ex to the desired interface on the srx
assign this interface to the untrust zone
Allow host inbound traffic protocols on this zone for bgp
Copy the bgp configuration from the ex to the srx
remove the iterface and bgp upstream configuration from the ex
For the downstream to the ex from the srx, this will all depend on how the ex is configured now for distribution and how you want to control traffic with srx rules.
You could put an srx interface in the same vlan as the upstream is now and connect this layer 2 to the ex so all the downstream peerings still work as they do in the ex now.
Or there are redesign options that will all vary depending on if you are running iBGP or eBGP internally and whether or not there are route reflectors.