T&T | Cyber: D&R | Deputy Manager | Security Information and Event Management (SIEM) | Delhi

Deloitte

5+ yrs New Delhi Full Time Work from office
Deloitte logo
Posted : today
Actively hiring

Job description

Join Deloitte's Cyber Defense & Response team as a Deputy Manager specializing in Security Information and Event Management (SIEM). This role is pivotal in protecting organizations from cyber threats by monitoring, analyzing, and responding to security events. You will be instrumental in maintaining a vigilant and resilient security posture, enabling our clients to confidently pursue new opportunities while managing cyber risks effectively.

We focus on embedding cyber risk management into the core of strategic development, ensuring robust protection of information and technology assets. This is an opportunity to contribute to a leading cybersecurity practice and make a significant impact.

Responsibilities

Monitor and triage security alerts from SIEM/SOAR and Microsoft Defender for Endpoints, conducting initial incident classification. Investigate potential security incidents, escalating confirmed threats to L2 Analysts or the Incident Response Team. Document all incident details and actions taken within the incident management system.

Assist in the containment and mitigation of security threats, leveraging threat intelligence feeds to enhance detection. Generate security reports and metrics for stakeholders, and participate in post-incident reviews to identify process improvements. Stay abreast of the latest security trends, vulnerabilities, and attack vectors. This role requires flexibility to work in a 24x7 rotational shift model, including nights.

Qualifications

Possess a strong understanding of Cyber Security Principles and expertise in domains like Endpoint, Network, Database, and Cloud Security technologies, including IPS, WAF, Firewalls, Deception, Cloud Security, AV, EDR, and Microsoft Defender. You should be adept at log analysis, proactive monitoring, and incident response for network and security events.

Experience in implementing and maintaining Security Operation Policies and procedures, particularly within AWS Cloud environments, is essential. The ability to proactively hunt for malicious activity using tools like Cortex, Shodan, Qradar, and Microsoft Defender is crucial. Identifying Indicators of Compromise through static and dynamic malware analysis, and performing advanced threat analysis for complex security events are key functions.

Familiarity with Google SecOps/Chronicle, Microsoft Sentinel, Demisto/XSOAR, and the MITRE Framework Attack Methodology is required. A Bachelor's or Master's degree in Computer Science, Information Technology, or a related field, coupled with 5+ years of relevant Cyber experience, is necessary. Relevant certifications such as SC 200, Security+, or CEH are highly valued.

Essential Skills

SIEMSOARMicrosoft Defender for EndpointsCybersecurityEndpoint SecurityNetwork SecurityDatabase SecurityCloud SecurityIPSWAFFirewallDeception TechnologyAntivirusEDRLog AnalysisIncident ResponseThreat IntelligenceAWS CloudCortexShodanQradarMalware AnalysisGoogle SecOpsChronicleMicrosoft SentinelDemistoXSOARMITRE Framework

Good to Have

SC 200Security+CEH

Highlights

  • Actively hiring

More Details

RoleT&T | Cyber: D&R | Deputy Manager | Security Information and Event Management (SIEM) | Delhi
IndustryInformation Technology & Services, Cybersecurity
DepartmentOperations
Employment TypeFull Time, Work from office

About the Company

Deloitte logo

Deloitte

Information Technology & Services

T&T | Cyber: D&R | Deputy Manager | Security Information and Event Management (SIEM) | Delhi at Deloitte | SkillMX | SkillMX