T&T | Cyber : D&R | Director | Incident Response & Handling | Delhi

Deloitte

15+ yrs New Delhi Full Time Work from office
Deloitte logo
Posted : 1 week ago
Actively hiring

Job description

Join Deloitte Touche Tohmatsu India LLP's Cyber team as a Director, specializing in Incident Response & Handling. We empower organizations to prevent cyberattacks and safeguard their critical assets by adopting a secure, vigilant, and resilient approach. Our expertise lies not only in preventing and responding to threats but also in managing cyber risk to unlock new business opportunities. We help integrate cyber risk management into strategic development for effective information and technology risk oversight.

Learn more about Cyber | Deloitte.

Responsibilities

Lead client engagements focused on incident response and investigation, acting as the primary point of contact. You will provide expert subject matter guidance and project management. Assist in scoping client incident calls and actively participate from kickoff through full containment and remediation.

Analyze large datasets to extract actionable insights for reporting, threat hunting, and anomaly detection. Recommend and document specific countermeasures and controls, providing post-incident analysis findings. Develop detailed and accurate reports and presentations tailored for both technical and executive audiences.

Conduct Digital Forensic and Incident Response (DFIR) analysis, including network log and PCAP analysis, malware triage, and other investigative activities. Supervise DFIR staff, contributing to performance reviews and mentoring cybersecurity professionals. Mature the Security Incident Response process to meet evolving client needs and interact with client CSIRT teams for continuous and ad-hoc incident response services.

Possess the credibility to serve as an expert witness. Engage in business development activities, supporting pre-sales teams in identifying and developing new business opportunities. Assist with research and distribution of cyber threat intelligence derived from incident response activities. Research, develop, and recommend infrastructure needs for DFIR, enhancing existing methodologies to improve our practice.

Qualifications

A Bachelor’s degree in Information Security, Computer Science, or a related field is required. A Master’s degree in Cybersecurity or Business Management is preferred. A minimum of 15 years of experience in Information Security is necessary, with at least 8 years dedicated to Incident Response.

A strong understanding of MITRE ATT&CK, the NIST cyber incident response framework, and the Cyber Kill Chain is essential. Familiarity with Threat Hunting and Threat Intelligence concepts and technologies is also key.

Demonstrated experience with tools such as CyLR, Redline, KAPE, Skadi, FlareVM, SIFT, MDE, and Crowdstrike Sandboxing is expected. Proficiency in modern SIEM and EDR platforms, deriving hypotheses, and conducting complex, advanced investigations is crucial.

Relevant certifications such as CISSP, ECIH v2, GCFA, GCIH, or EnCE are highly regarded. Experience with enterprise-level cloud infrastructures like AWS, MS Azure, G Suite, and O365 is required. Proficiency with industry-standard forensic toolsets (e.g., EnCase, Axiom/IEF, Cellebrite/UFED, Nuix, FTK) and deep experience with common operating systems (Windows, MacOS, Linux, Android, iOS) and their file systems (ext3.4, NTFS, HFS+, APFS, exFAT) are necessary.

Essential Skills

Incident ResponseDigital ForensicsMITRE ATT&CKNIST Cyber Incident Response FrameworkCyber Kill ChainThreat HuntingThreat IntelligenceCyLRRedlineKAPESkadiFlareVMSIFTMDECrowdstrike SandboxingSIEMEDRAWSMS AzureG SuiteO365EnCaseAxiomIEFCellebrite UFEDNuixFTKWindowsMacOSLinuxAndroidiOSExt3.4NTFSHFS+APFSexFAT

Good to Have

CISSPECIH v2GCFAGCIHEnCE

Highlights

  • Actively hiring

More Details

RoleT&T | Cyber : D&R | Director | Incident Response & Handling | Delhi
DepartmentCybersecurity
Employment TypeFull Time, Work from office

About the Company

Deloitte logo

Deloitte

IT Consulting