T&T | Cyber: D&R | Deputy Manager | SOC - SIEM - Incident Response & Handling | Mumbai, Hyderabad (Mumbai, IN)
Deloitte
Deloitte
Join Deloitte's Cyber team as a Deputy Manager specializing in SOC and SIEM, focusing on Incident Response and Handling. This role offers a crucial opportunity to protect organizations from cyber threats, ensuring security, vigilance, and resilience. You will be instrumental in managing cyber risk, enabling new opportunities, and embedding security into strategic development. Learn more about our cutting-edge Cybersecurity initiatives.
This position is based in Mumbai or Hyderabad and requires a strong commitment to on-site work.
This role involves analyzing L1/L2 escalations and providing on-call support for critical incidents. You will lead incident response efforts, including containment, eradication, and recovery. Key duties include coordinating remediation with various teams, developing advanced response strategies, and analyzing evidence, logs, and network traffic. You will also perform malware analysis, threat hunting, develop SIEM use cases, and recommend security enhancements.
Further responsibilities include building automation scripts, continuously improving processes, mentoring junior analysts, and documenting findings. Effective communication of incident impact and recommendations to management is essential. Staying updated on emerging threats and security best practices is also a core part of this role.
We are seeking professionals with 6-10 years of experience in incident response, deeply familiar with frameworks like NIST and SANS. A strong understanding of networking, operating systems, cloud, endpoint, and identity security is vital. Proficiency in SIEM, SOAR, UEBA, EDR/XDR, threat intelligence, and forensic tools is required.
Expertise in advanced incident investigation, digital forensics, malware analysis, and threat hunting is expected. You should be adept at analyzing complex data sources, understanding attacker tactics (MITRE ATT&CK), and developing SIEM use cases. Working knowledge of scripting languages like Python, PowerShell, or Bash is necessary. Familiarity with ISO 27001 and relevant regulations is a plus.
Essential skills include strong analytical, troubleshooting, communication, and documentation abilities, with the capacity to perform under pressure. Holding a CISSP, CISM, CISA, or CEH certification is mandatory. A Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field is required. This position is designated for on-site work in Mumbai or Hyderabad.
Deloitte
Information Technology & Services