T&T | Cyber: D&R | Assistant Manager | Security Information and Event Management (SIEM) | Bengaluru
Deloitte
Deloitte
Join Deloitte's Cyber Team as an Assistant Manager in Bengaluru, focusing on Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR).
This role offers an exceptional opportunity to leverage your expertise in cybersecurity to prevent attacks, protect valuable assets, and manage cyber risk effectively. You will collaborate with leading organizations, contributing to shaping the future of technology and security.
Deloitte is committed to fostering a culture where your whole self can thrive. We encourage innovation, collaboration, and growth, providing a perfect platform to make a significant impact.
As an Assistant Manager in our Cyber Team, you will:
- Translate security team requirements into SIEM use cases, design, implement, and test them. - Optimize use cases for improved detection accuracy and reduced false positives. - Develop and implement SIEM rules, correlation logic, and tune alerts for actionability. - Create and maintain parsers/connectors in SIEM and SOAR, setting appropriate alert thresholds. - Ensure data normalization and enrichment for effective correlation and analysis. - Document SIEM use cases, generate performance reports, and collaborate with stakeholders. - Design and develop automated SOAR workflows, playbooks, and scripts to address security operations tasks. - Automate alert enrichment, integrate security tools, and optimize workflow performance. - Monitor SOAR platform health, document automation processes, and develop overall SOAR architecture.
To excel in this role, you should possess:
- Proficiency with SIEM and SOAR solutions, with experience in configuration, management, and optimization. - Strong scripting skills in Python, PowerShell, or JavaScript for automation. - Experience utilizing RESTful APIs for inter-tool communication. - Ability to convert MITRE ATT&CK TTPs into misuse cases for enhanced detection and response. - Expertise in SOC Operations, SIEM Use Case development, and SOAR Automation, specifically with Splunk and Palo Alto. - A Bachelor's degree (B.E/B.Tech) in Computer Science, Information Technology, or a related field. - 6 to 8 years of relevant experience, with proposed OEM certifications being a plus. - The role requires working from the Koramangala, Bengaluru office.
Deloitte
Technology