T&T | Cyber: D&R | Assistant Manager | SOC - SIEM - Incident Response & Handling | Mumbai, Hyderabad
Deloitte
Deloitte
Join our Cybersecurity team as an Assistant Manager specializing in Security Operations Center (SOC) and Security Information and Event Management (SIEM), focusing on Incident Response and Handling. You will play a crucial role in protecting organizations from cyber threats and ensuring resilience. This position involves embedding cyber risk management into strategic development for effective information and technology risk mitigation.
Deloitte is dedicated to helping organizations prevent cyberattacks and safeguard their valuable assets. We prioritize security, vigilance, and resilience, not just in responding to threats but in managing cyber risk to enable new opportunities.
Your primary responsibilities will include reviewing and triaging security alerts, conducting in-depth analysis, and determining appropriate remediation steps. You will escalate issues as needed and maintain thorough documentation of security incident processes and protocols. This role demands acting as a Security Incident Handler for high-impact incidents and advanced attacks, utilizing methodologies like the Cyber Kill Chain.
Key duties also involve performing malware analysis, identifying Indicators of Compromise (IOCs), and enhancing incident response workflows. You will analyze logs from various sources, differentiate between genuine threats and false alarms, and leverage attack frameworks like Kill Chain & MITRE for effective incident response and reporting. A fundamental understanding of network traffic and security concepts is essential.
We are seeking professionals with 4-6 years of experience in SOC incident response and handling, proficiency in SIEM technologies such as LogRhythm, Splunk, Sentinel, or Chronicle, and experience with EDR/XDR solutions like CrowdStrike, Cortex XDR, or Microsoft Defender. A strong grasp of security concepts, threat vectors, risk management, and incident management is required.
Ideal candidates possess a solid understanding of Windows event log analysis, network traffic analysis, and various attack frameworks. Experience with Recorded Future Fusion and Brand Protection cloud services is beneficial. A Bachelor's or Master's degree in Computer Science, Information Security, or a related field is necessary. Possession of certifications like CompTIA Security+, ECSA, GCFA, GCFE, or CISSP is a plus. This role requires a commitment to working from the office.
Deloitte
Cybersecurity