T&T | Cyber: D&R | Assistant Manager I Security Information and Event Management (SIEM) I Bangalore (Bengaluru, IN)
Deloitte
Deloitte
Join a leading cybersecurity team focused on protecting organizations from cyber threats and safeguarding critical assets. We are committed to building secure, vigilant, and resilient systems by proactively managing cyber risk and enabling new opportunities.
This role offers a chance to be at the forefront of cyber defense, working with cutting-edge technologies to manage information and technology risks effectively.
As an Assistant Manager in Security Information and Event Management (SIEM), you will be instrumental in monitoring security alerts, performing initial incident triage, and investigating potential security incidents. Your role involves escalating confirmed threats, documenting incident details meticulously, and assisting in the containment and mitigation of security breaches.
You will also leverage threat intelligence, generate security reports, and participate in post-incident reviews to enhance our Security Operations Center (SOC) processes. A key part of this position includes correlating data from various sources, conducting threat hunting, and proactively identifying malicious activity. Staying abreast of the latest security trends, vulnerabilities, and attack vectors is crucial, as is suggesting new use cases to improve threat detection capabilities. This position requires willingness to work in a 24x7 rotational shift model, including night shifts, at the client location.
We are seeking candidates with a strong foundation in cybersecurity principles and extensive knowledge across various security domains, including Endpoint, Network, Database, and Cloud Security technologies. Proven experience in conducting senior-level log analysis, proactive monitoring, and responding to network and security incidents is essential. You should be adept at triaging security events and executing incident response steps, along with implementing and maintaining robust Security Operation Policies and procedures, particularly within AWS cloud environments.
Proficiency in threat hunting using tools like Cortex, Shodan, and Qradar, identifying Indicators of Compromise through static and dynamic malware analysis, and performing advanced security event detection are vital. Experience with QRadar, Demisto/XSOAR, Qualys, and the MITRE Framework is expected. A Bachelor's degree (B.E./B.Tech) in Computer Science, Information Technology, or a related field, coupled with 5+ years of relevant cybersecurity experience and strong networking fundamentals, is required. Holding at least one of the specified certifications (Security+/ECSA/GCFA/GCFE/Any SIEM certification) is mandatory. This is a Work From Office (WFO) role based in Bengaluru, with a professional requirement to work from the office.
Deloitte
Cybersecurity