T&T | Cyber: D&R I Manager | Incident Response & Handling | Bengaluru
Deloitte
Deloitte
Join Deloitte's esteemed Cyber team as a Manager, where you will be instrumental in safeguarding organizations from cyber threats. We focus on building secure, vigilant, and resilient environments. This role offers the opportunity to integrate cyber risk management into strategic development, enabling clients to navigate the evolving threat landscape and seize new opportunities.
As a key member of our Cybersecurity practice, you will foster strong client relationships and deliver exceptional service. Your expertise will be crucial in managing and mitigating cyber risks effectively.
Serve as the primary technical escalation point (L3) for high-severity cyber security incidents within the Security Operations Center (SOC).
Lead comprehensive investigations, containment, eradication, recovery, and resolution of critical security incidents (P1/P2).
Conduct advanced investigations using tools like Microsoft Sentinel, Palo Alto Cortex XSOAR, and Microsoft Defender XDR/EDR.
Perform sophisticated KQL-based threat hunting across various telemetry sources including endpoint, identity, cloud, network, and applications.
Correlate security events from multiple controls to reconstruct attack timelines, determine scope, impact, and root causes.
Develop, refine, and optimize SIEM detection rules, correlation logic, and threat-hunting use cases.
Design, build, and enhance XSOAR playbooks and automated incident response workflows to boost SOC efficiency and reduce Mean Time To Respond (MTTR).
Drive proactive threat hunting initiatives leveraging MITRE ATT&CK frameworks, threat intelligence, and emerging threat actor tactics, techniques, and procedures (TTPs).
Spearhead detection engineering efforts and improve MITRE ATT&CK coverage across the SOC.
Provide technical mentorship and guidance to L1/L2 SOC analysts, including case reviews and escalation support.
Lead technical response efforts during major security incidents and cyber crisis situations.
Conduct detailed Root Cause Analysis (RCA) and define corrective and preventive actions post-incident.
Collaborate with cross-functional teams such as Network, Infrastructure, Cloud, IAM, Application, Endpoint, and ITSM for coordinated containment and remediation.
Identify opportunities to automate routine SOC tasks using XSOAR, APIs, Python, and PowerShell.
Translate incident and threat-hunting findings into actionable detections, playbooks, use cases, and security enhancements.
Contribute to the ongoing enhancement of SOC processes, detection capabilities, response effectiveness, and overall operational maturity.
Ensure all incident investigations and response activities adhere to defined Service Level Agreements (SLAs), security policies, governance requirements, and documentation standards.
We are seeking a Manager with 10 to 12 years of extensive experience in the cybersecurity domain.
Proficiency in KQL for advanced investigation, correlation, and threat hunting is essential.
Demonstrated hands-on expertise with Microsoft Defender XDR and Microsoft Defender for Endpoint is required.
Strong understanding and practical experience in Incident Response, Major Incident Management, and Root Cause Analysis (RCA).
Advanced threat hunting capabilities utilizing MITRE ATT&CK, threat intelligence, and attacker TTPs are necessary.
Experience in detection engineering, developing use cases, tuning rules, and mapping to MITRE ATT&CK.
A solid grasp of Identity and Cloud Security, specifically with Microsoft Entra ID and Azure.
Familiarity with Threat Intelligence, IOC enrichment, and STIX/TAXII protocols.
Working knowledge of Python, PowerShell, REST APIs, JSON, and automation techniques.
Comprehensive understanding of security telemetry from network, endpoint, identity, cloud, and application sources.
Ability to correlate events across Sentinel, Defender, and XSOAR to investigate complex attack scenarios.
Proven experience in developing automated investigation and response workflows.
Capacity to mentor and provide technical leadership to L1/L2 SOC analysts.
Exceptional analytical, problem-solving, documentation, and stakeholder communication skills.
Ability to perform effectively under pressure during critical P1/P2 and major security incidents.
Education: A Bachelor of Engineering (B.E.) or Bachelor of Technology (B.Tech) from a Tier 1/2 institution, or a Master's degree in Information Security, Computer Science, or a related field is required.
Deloitte
Information Technology & Services