T&T | Cyber : D&R | Associate Director (SIEM) | Hyderabad
Deloitte
Deloitte
Join Deloitte's Cyber team as an Associate Director, leading critical SIEM transformation and migration programs. You will guide organizations in preventing cyberattacks and protecting valuable assets, ensuring resilience and enabling new opportunities. This role involves embedding cyber risk management into strategic development.
Learn more about Cyber | Deloitte.
Spearhead enterprise-wide SIEM transformations, migrating from legacy systems like Splunk and QRadar to next-generation platforms such as Google SecOps and Microsoft Sentinel. Define migration strategies, operating models, and roadmaps.
Oversee assessment, sizing, onboarding, normalization, enrichment, and optimization of security telemetry. Drive end-to-end implementation of leading SIEM solutions. Establish governance frameworks, delivery milestones, and risk management plans.
Manage multiple concurrent engagements, ensuring adherence to timelines, budgets, and quality standards. Support and manage teams of SOC analysts, incident responders, and engineers in handling client security incidents.
Lead security operations and managed detection & response (MDR) services. Establish and operationalize next-generation SOC capabilities using cloud-native security platforms. Ensure effective monitoring, triage, investigation, response, and remediation across client environments.
Define and manage operational KPIs, SLAs, and security performance metrics. Drive continuous improvement initiatives focused on detection quality, analyst productivity, and response effectiveness. Support the transition from project implementation to business-as-usual operations.
Lead the development and optimization of advanced detection content and threat detection use cases, including detection rules, correlation logic, behavioral analytics, and UEBA.
Drive security orchestration and automation initiatives. Design and implement automated playbooks and workflows for incident response. Integrate security platforms with EDR/XDR, identity, cloud, ticketing, and vulnerability management systems to improve MTTD and MTTR.
A minimum of 13 years in cybersecurity, with at least 5 years in a SOC management or equivalent leadership role is required. Experience in an MSSP or managing security operations for multiple clients is highly preferred.
Demonstrated strong experience with security tools (SIEM, EDR, IDS/IPS), threat intelligence, and incident response is essential. A proven track record of leading teams in a 24/7 SOC environment is also necessary.
Mandatory experience includes proficiency in at least two of the following: Google Security Operations, Microsoft Sentinel, Palo Alto Cortex XSIAM/XDR, SIEM migration/modernization programs, SOC transformation/operating model design, detection engineering/threat hunting, security automation/SOAR, MITRE ATT&CK Framework, or Incident Response/Security Operations.
Relevant certifications such as Google Professional Security Operations Engineer, Palo Alto Networks Certified XSIAM Analyst or Engineer, CISSP, CISM, GIAC (GCIH, GCIA, GSOC), or CompTIA Security+ are advantageous.
Deloitte
Cybersecurity