T&T | Cyber | D&R | Director - Incident Response & Handling (Bengaluru, IN)
Deloitte
Deloitte
Join our dynamic cybersecurity team as a Director of Incident Response and Handling. In this pivotal role, you will drive enterprise-wide SIEM transformation initiatives, modernizing our security infrastructure to combat evolving cyber threats. You'll lead the design and implementation of next-generation security operations centers (SOCs) and managed detection and response (MDR) services, ensuring robust protection for our clients.
This is an opportunity to shape the future of cyber defense, leveraging cutting-edge technologies and leading a talented team. If you are passionate about proactive threat mitigation and resilient security strategies, we encourage you to apply.
Lead major SIEM transformation and migration programs from legacy systems to advanced platforms like Google SecOps and Microsoft Sentinel. Develop comprehensive migration strategies, operating models, and implementation roadmaps. Oversee the assessment, onboarding, and optimization of security telemetry and data. Manage multiple concurrent engagements, ensuring adherence to timelines, budgets, and quality standards. Lead and mentor a team of SOC analysts, incident responders, and engineers. Establish and operationalize next-generation SOC capabilities, ensuring effective monitoring, investigation, and response. Define and manage key performance indicators (KPIs) and service level agreements (SLAs). Drive continuous improvement in detection quality, analyst productivity, and response effectiveness. Develop and optimize advanced detection content, threat detection use cases, and behavioral analytics. Lead security orchestration and automation initiatives, including the design of automated playbooks and workflows. Integrate various security platforms to enhance incident response capabilities and reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
Possess a Bachelor’s degree in Information Security, Computer Science, or a related field, with a Master’s degree in Cybersecurity or Business Management being a strong preference. Offer a minimum of 13 years of experience in cybersecurity, including at least 5 years in a SOC management or equivalent leadership capacity. Demonstrate strong experience with security tools such as SIEM, EDR, IDS/IPS, alongside expertise in threat intelligence and incident response. Have a proven track record of leading teams within a 24/7 SOC environment. Experience in an MSSP or managing security operations for multiple clients is highly desirable. Relevant certifications such as Google Professional Security Operations Engineer, Palo Alto Networks Certified XSIAM Analyst or Engineer, CISSP, CISM, GIAC, or CompTIA Security+ are advantageous.
Deloitte
Information Technology & Services