T&T | Cyber: D&R | Deputy Manager | SOC - SIEM - Incident Response & Handling | Mumbai (Mumbai, IN)
Deloitte
Deloitte
Join Deloitte's Cyber Risk team as a Deputy Manager in our SOC team, focusing on SIEM and Incident Response in Mumbai. You'll play a critical role in defending organizations against cyber threats, ensuring resilience, and protecting valuable assets. This is an opportunity to embed robust cyber risk management into strategic development and manage information and technology risks effectively.
As a Deputy Manager, you will analyze escalations and provide on-call support for critical incidents. You will lead incident response efforts, including containment, eradication, and recovery. Your role involves coordinating remediation with various IT teams, developing advanced response strategies, and analyzing evidence, logs, and network traffic to identify attack origins. You will also perform malware analysis, threat hunting, and develop SIEM use cases and correlation rules. Recommending security enhancements, building automation scripts, and continuously improving processes are key. Mentoring junior analysts and documenting findings for management and stakeholders are also essential.
- Analyze L1/L2 escalations and provide critical incident support. - Lead and manage critical incident response activities. - Coordinate remediation efforts across IT domains. - Develop advanced response playbooks and runbooks. - Analyze forensic data, logs, and network traffic. - Perform threat hunting, malware analysis, and intelligence-led investigations. - Develop and optimize SIEM use cases and alert logic. - Conduct root-cause analysis and identify security gaps. - Recommend security control enhancements and automation. - Build automation scripts for investigation and reporting. - Enhance playbooks, SOPs, and escalation processes. - Mentor L1/L2 analysts and provide training. - Document findings and prepare comprehensive reports. - Communicate incident impact and recommendations to stakeholders. - Stay updated on emerging threats and security best practices.
This role requires 6-10 years of experience in cybersecurity, with a strong foundation in incident response frameworks like NIST and SANS. You should possess a deep understanding of networking, operating systems, cloud, endpoint, and identity security. Proficiency in SIEM, SOAR, UEBA, EDR/XDR, threat intelligence, and forensic tools is essential. Expertise in advanced incident investigation, digital forensics, malware analysis, and reverse engineering is expected. You must be adept at analyzing complex logs and security data, with a strong grasp of attacker tactics and MITRE ATT&CK. Experience in threat hunting, detection engineering, and SIEM use-case development is crucial. Working knowledge of scripting languages like Python, PowerShell, or Bash is required. Familiarity with ISO 27001 and relevant regulatory standards is beneficial. Excellent analytical, troubleshooting, decision-making, communication, and documentation skills are a must, along with the ability to perform under pressure.
- 6-10 years of relevant experience. - Strong knowledge of incident-response frameworks (NIST, SANS). - Deep understanding of core cybersecurity principles and technologies. - Proficiency in SIEM, SOAR, EDR/XDR, and related tools. - Expertise in advanced investigation, forensics, and malware analysis. - Ability to analyze complex security data and logs. - Strong knowledge of attacker tactics and MITRE ATT&CK. - Experience in threat hunting and detection engineering. - Working knowledge of scripting (Python, PowerShell, Bash). - Knowledge of ISO 27001 and compliance. - Excellent analytical and communication skills. - Ability to lead technical response during critical incidents. - Bachelor's or Master's degree in Computer Science, Information Security, or a related field. - Professional certifications (CISSP, CISM, etc.) are preferred. - Role requires working from the office in Mumbai.
Deloitte
Cybersecurity