Consultant | Security Information and Event Management (SIEM) | Bengaluru | Cyber Defense & Resilien
Deloitte
Deloitte
Join our Cyber Team as a Consultant and play a vital role in safeguarding organizations from cyber threats. You will be instrumental in preventing attacks and protecting valuable assets through vigilance and resilience. This role involves embedding cyber risk management into strategic development to effectively manage information and technology risks.
At Deloitte, we empower you to bring your whole self to work. Collaborate, innovate, and grow within a dynamic environment that shapes the future of technology and business. Unleash your potential alongside leading professionals and organizations.
We believe in fostering a secure, vigilant, and resilient cyber defense posture. Our mission is to not only prevent and respond to attacks but also to manage cyber risk in a way that unlocks new opportunities for our clients. Contribute to building advanced security strategies and solutions.
As a Consultant in our Cyber Team, you will monitor security alerts and events from diverse sources, including QRadar SIEM. You will conduct initial triage and classification of security incidents, investigating alerts to identify potential threats. Confirmed incidents will be escalated to SOC L2 Analysts or the Incident Response Team.
Your responsibilities include documenting incident details, actions taken, and resolutions within the incident management system. You'll assist in containing and mitigating security threats, and leverage threat intelligence feeds to enhance detection capabilities. Generating comprehensive security reports and metrics for stakeholders is also key.
Participate in post-incident reviews to identify process improvements and stay abreast of the latest security trends, vulnerabilities, and attack vectors. A willingness to work in a 24x7 rotational shift model, including nights, is mandatory for this role.
We are seeking individuals with a strong foundation in Cyber Security Principles, experienced in domains such as Endpoint, Network, Database, and Cloud Security technologies. Proficiency with tools like IPS, WAF, Firewalls, Deception technology, Cloud Security, AV, and EDR is essential.
Key requirements include conducting senior-level log analysis, proactive monitoring, and response to network and security incidents. You should be adept at triaging security events and executing incident response procedures. Experience in implementing and maintaining extensive Security Operation Policies and procedures, including those for AWS cloud, is also required.
Candidates should be skilled in proactive threat hunting and research using tools like Cortex, Shodan, and QRadar. Identifying Indicators of Compromise (IoCs) through static and dynamic analysis of malware, and performing advanced security event detection and threat analysis for complex incidents are crucial. Familiarity with QRadar, Demisto/XSOAR, Qualys, and the MITRE Framework is expected.
Deloitte
Cyber Defense & Resilience