T&T | Cyber : D&R | Consultant | Security Information and Event Management (SIEM) | Delhi (Delhi, IN)
Deloitte
Deloitte
Join our cybersecurity team as a Consultant focused on Security Information and Event Management (SIEM). You will play a crucial role in protecting organizations from cyber threats by monitoring, investigating, and responding to security incidents.
Deloitte's Cybersecurity practice helps organizations build resilience against cyberattacks. We emphasize a proactive approach, integrating cyber risk management into strategic development to effectively manage information and technology risks. Discover more about our Cybersecurity services and how we empower businesses to navigate the digital landscape securely.
Your primary responsibilities will involve monitoring security alerts from SIEM/SOAR and MDE, conducting initial triage and investigation of incidents, and escalating confirmed threats to senior analysts. You'll maintain detailed incident documentation, assist in threat containment, and leverage threat intelligence to enhance detection. This role also includes generating security reports, participating in post-incident reviews, and staying current with evolving security trends.
Additionally, you will perform log analysis, proactive monitoring, and response to network and security incidents. This includes implementing and maintaining security operation policies, particularly within AWS Cloud environments. You'll also proactively hunt for malicious activity using advanced tools and analyze indicators of compromise, and conduct in-depth threat analysis for complex security events. A critical requirement is the willingness to work in a 24x7 rotational shift model, including night shifts.
To be successful in this role, you should possess a B.E/B.Tech degree (Tier 1/2) or a Master's in Computer Science, Information Technology, or a related field, with at least 2 years of relevant experience in cybersecurity.
We are looking for individuals well-versed in core cybersecurity principles and domains such as Endpoint, Network, Database, and Cloud Security technologies. Familiarity with tools and frameworks like IPS, WAF, Firewall, Deception, Cloud Security, AV, EDR, Microsoft Defender, Cortex, Shodan, Qradar, Google SecOps/Chronicle, Microsoft Sentinel, Demisto/XSOAR, and the MITRE Framework is essential. Experience with advanced malware analysis and identifying Indicators of Compromise is also highly valued.
Relevant certifications such as SC 200, Security+, or CEH are a plus. A strong understanding of security event detection and threat analysis for complex scenarios is expected.
Deloitte
Cybersecurity