Manager | Cloud Security | Across Locations | Enterprise Security | Cloud Security

Deloitte

6–10 yrs Pune Full Time Hybrid (office + remote)
Deloitte logo
Posted : today
Actively hiring

Job description

Seeking a highly skilled L3 Security Specialist / Incident Response Lead to serve as the ultimate technical escalation point for critical and complex security incidents within a 24x7 CERT service model. This expert-level role involves advanced threat investigation, technical leadership during severe security events, impact assessment, specialized analysis, and strategic guidance for containment. You will also contribute to improving detection and response maturity, acting as a technical mentor to L1/L2 teams and strengthening operational capabilities over time. This position is crucial for managing major security risks and enhancing service resilience.

Responsibilities

Lead in-depth technical investigations for complex, high-severity security incidents that go beyond standard L2 analysis. Conduct advanced incident scoping to precisely define the extent of compromise, affected systems, attack sequences, and potential threat progression. Review escalations involving suspicious privileged activity, recurring compromise patterns, container/runtime anomalies, high-risk infrastructure alerts, or evidence of coordinated attacks. Provide expert-level recommendations for containment and remediation, balancing risk, business criticality, threat behavior, and operational feasibility. Support high-priority incident communications by clearly translating technical findings into stakeholder-ready updates. Collaborate closely with internal resolver groups, infrastructure/application owners, incident managers, and service management stakeholders during critical investigations. Identify systemic weaknesses and recurring root causes, proposing long-term improvements in detection use cases, process maturity, SOPs, playbooks, and escalation models. Guide security analysts on advanced analysis techniques, evidence handling, incident scoping, and response decision-making. Participate actively in incident reviews, governance reporting, and continuous service improvement discussions with a strong focus on risk trends and service resilience.

Qualifications

Possess deep expertise in incident response, advanced threat investigation, attack analysis, containment strategy, and operational decision-making during live incidents. Demonstrate strong experience with SIEM/SOAR platforms, focusing on investigation workflows, offense analysis, data correlation, and high-fidelity case handling. Exhibit a solid understanding of security telemetry across logs, authentication systems, network activity, endpoint behavior, container/runtime monitoring, and threat advisories. Capable of assessing business impact versus technical severity to advise on containment actions while prioritizing continuity requirements. Possess strong knowledge of incident lifecycle management, escalation governance, reporting, knowledge management, and service improvement practices. Ability to craft clear executive and technical summaries for senior stakeholders and operational teams is essential. A Bachelor’s Degree in Cybersecurity, Computer Science, Information Security, or a related field is preferred. Typically requires 6-10+ years of experience in incident response, CERT/SOC engineering, advanced threat analysis, or senior security operations roles, with proven experience handling critical/high-severity security investigations and guiding cross-functional technical responses. Certifications such as GCIA, GCIH, GCFA, CISSP, SC-200, or equivalent SIEM vendor certifications are advantageous.

Essential Skills

Incident ResponseThreat InvestigationAttack AnalysisSIEMSOARLog AnalysisNetwork SecurityEndpoint SecurityContainer SecurityRisk ManagementSecurity OperationsKnowledge ManagementStakeholder Communication

Good to Have

GCIAGCIHGCFACISSPSC-200SIEM Vendor Certifications

Highlights

  • Actively hiring

More Details

RoleManager | Cloud Security | Across Locations | Enterprise Security | Cloud Security
IndustryInformation Technology & Services
DepartmentSecurity, Information Security
Employment TypeFull Time, Hybrid (office + remote)

About the Company

Deloitte logo

Deloitte

Information Technology & Services

Manager | Cloud Security | Across Locations | Enterprise Security | Cloud Security at Deloitte | SkillMX | SkillMX