T&T | Cyber: D&R | Consultant | SOC - SIEM - Incident Response & Handling | Mumbai, Hyderabad
Deloitte
Deloitte
Join Deloitte's Cybersecurity team as a Consultant specializing in Security Operations Center (SOC) and Incident Response. You will play a crucial role in protecting organizations from cyber threats, analyzing security alerts, and managing high-impact security incidents.
This role offers the opportunity to work with cutting-edge SIEM and EDR/XDR technologies, contributing to robust cyber defense strategies. You'll be part of a team dedicated to ensuring client security, resilience, and enabling new opportunities through effective risk management.
As a Consultant, you will be responsible for reviewing and triaging security alerts from Level 1 analysts, performing in-depth analysis to determine incident relevance and urgency.
You will act as a Security Incident Handler for critical cyber incidents, following established processes and methodologies like the Cyber Kill Chain. Your duties will include conducting malware analysis, identifying Indicators of Compromise (IOCs), and enhancing incident response workflows.
You will also maintain and update security incident process documentation (Run Books), collaborate with the L4 team to minimize false positives, and contribute to threat hunting and overall SOC operations.
We are seeking individuals with 2-5 years of experience in SOC operations, incident response, threat monitoring, or cybersecurity investigations. A strong understanding of SIEM technologies such as LogRhythm, Splunk, Sentinel, or Chronicle is essential.
Proficiency in EDR/XDR solutions like CrowdStrike, Cortex XDR, or Microsoft Defender is required. You should possess a solid grasp of fundamental security concepts, including cyber-attacks, threat vectors, risk management, and incident management.
A fundamental understanding of network traffic analysis (TCP/IP, routing, switching, protocols) and Windows event log analysis is also necessary. Experience with attack frameworks like Kill Chain and MITRE is highly valued. A Bachelor's or Master's degree in Computer Science, Information Security, or a related field is required. Candidates holding certifications like CompTIA Security+, CEH, or ECSA are preferred. This role requires working from the office.
Deloitte
Information Technology & Services