T&T | Cyber: D&R | Consultant | SOC - SIEM - Incident Response & Handling | Mumbai, Hyderabad
Deloitte
Deloitte
Join our dynamic cybersecurity team as a Consultant, focusing on Security Operations Center (SOC) and SIEM, with a specialization in Incident Response and Handling. You will play a crucial role in protecting organizations from cyber threats and ensuring the resilience of their digital assets. This position offers an exciting opportunity to work with cutting-edge technologies and contribute to impactful security initiatives.
Our team is dedicated to helping clients prevent cyberattacks, safeguard valuable assets, and manage cyber risk effectively. We champion a secure, vigilant, and resilient approach, integrating cyber risk management into strategic development for robust information and technology risk management.
As a Consultant, you will be responsible for reviewing and triaging SIEM alerts, conducting in-depth analysis to identify genuine security incidents, and overseeing security monitoring tools. You will act as a Security Incident Handler for high-impact cyber security incidents and advanced attacks, employing methodologies like the Cyber Kill Chain. Your duties will include conducting malware analysis, identifying Indicators of Compromise (IOCs), and enhancing incident response workflows. You'll also perform log analysis across diverse sources, differentiate between potential intrusions and false alarms, and utilize attack frameworks like MITRE for incident response and reporting.
Key tasks involve maintaining and improving incident process documentation (Run Book), providing analysis and tracking remediation for alerts, and escalating issues as needed. You will also inform the L4 team of proactive and reactive actions to minimize false positives and leverage your understanding of exploits, vulnerabilities, and adversary tactics.
We are seeking professionals with 2-5 years of experience in SOC operations, incident response, threat monitoring, or cybersecurity investigations. A strong working knowledge of SIEM technologies (LogRhythm, Splunk, Sentinel, Chronicle) and EDR/XDR solutions (CrowdStrike, Cortex XDR, Microsoft Defender) is essential. A foundational understanding of security concepts, including cyber-attacks, threat vectors, risk management, and incident management, is required. Proficiency in network traffic analysis (TCP/IP, routing, switching, protocols) and Windows event log analysis is also critical.
Candidates should possess a Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field. Holding at least one of the following certifications is mandatory: CompTIA Security+, CEH, ECSA, or a relevant OEM certification for SIEM or security monitoring tools. This role requires an onsite presence at our office locations in Mumbai or Hyderabad.
Deloitte
Cybersecurity