T&T | Cyber : D&R | Director | Incident Response & Handling | Delhi
Deloitte
Deloitte
Join Deloitte Touche Tohmatsu India LLP's Cyber team as a Director, specializing in Incident Response & Handling. We empower organizations to prevent cyberattacks and safeguard their critical assets by adopting a secure, vigilant, and resilient approach. Our expertise lies not only in preventing and responding to threats but also in managing cyber risk to unlock new business opportunities. We help integrate cyber risk management into strategic development for effective information and technology risk oversight.
Learn more about Cyber | Deloitte.
Lead client engagements focused on incident response and investigation, acting as the primary point of contact. You will provide expert subject matter guidance and project management. Assist in scoping client incident calls and actively participate from kickoff through full containment and remediation.
Analyze large datasets to extract actionable insights for reporting, threat hunting, and anomaly detection. Recommend and document specific countermeasures and controls, providing post-incident analysis findings. Develop detailed and accurate reports and presentations tailored for both technical and executive audiences.
Conduct Digital Forensic and Incident Response (DFIR) analysis, including network log and PCAP analysis, malware triage, and other investigative activities. Supervise DFIR staff, contributing to performance reviews and mentoring cybersecurity professionals. Mature the Security Incident Response process to meet evolving client needs and interact with client CSIRT teams for continuous and ad-hoc incident response services.
Possess the credibility to serve as an expert witness. Engage in business development activities, supporting pre-sales teams in identifying and developing new business opportunities. Assist with research and distribution of cyber threat intelligence derived from incident response activities. Research, develop, and recommend infrastructure needs for DFIR, enhancing existing methodologies to improve our practice.
A Bachelor’s degree in Information Security, Computer Science, or a related field is required. A Master’s degree in Cybersecurity or Business Management is preferred. A minimum of 15 years of experience in Information Security is necessary, with at least 8 years dedicated to Incident Response.
A strong understanding of MITRE ATT&CK, the NIST cyber incident response framework, and the Cyber Kill Chain is essential. Familiarity with Threat Hunting and Threat Intelligence concepts and technologies is also key.
Demonstrated experience with tools such as CyLR, Redline, KAPE, Skadi, FlareVM, SIFT, MDE, and Crowdstrike Sandboxing is expected. Proficiency in modern SIEM and EDR platforms, deriving hypotheses, and conducting complex, advanced investigations is crucial.
Relevant certifications such as CISSP, ECIH v2, GCFA, GCIH, or EnCE are highly regarded. Experience with enterprise-level cloud infrastructures like AWS, MS Azure, G Suite, and O365 is required. Proficiency with industry-standard forensic toolsets (e.g., EnCase, Axiom/IEF, Cellebrite/UFED, Nuix, FTK) and deep experience with common operating systems (Windows, MacOS, Linux, Android, iOS) and their file systems (ext3.4, NTFS, HFS+, APFS, exFAT) are necessary.
Deloitte
IT Consulting