T&T | Cyber: D&R | Manager | Security Information and Event Management (SIEM) | Delhi (Delhi, IN)
Deloitte
Deloitte
Join our esteemed Cybersecurity team at Deloitte Touche Tohmatsu India LLP as a Manager specializing in Security Information and Event Management (SIEM). We empower organizations to proactively defend against cyberattacks and safeguard critical assets, fostering resilience and enabling new opportunities through robust cyber risk management. This role is integral to embedding security principles from the outset of strategic planning.
Your role will involve diligent monitoring of security alerts and events from diverse sources, including SIEM/SOAR platforms and Microsoft Defender for Endpoints. You will conduct initial incident triage, classification, and in-depth investigation to identify potential security breaches. Confirmed incidents will be escalated to our SOC L2 Analysts or Incident Response Team. Responsibilities also include meticulous documentation of incident details, actions taken, and resolutions within the incident management system, assisting in threat containment and mitigation, and leveraging threat intelligence to enhance detection. Generating insightful security reports and metrics for stakeholders, participating in post-incident reviews to refine SOC processes, and staying abreast of the latest security trends and vulnerabilities are key aspects of this position. A mandatory requirement is the willingness to work in a 24x7 rotational shift model, including nights.
We are seeking candidates with a strong foundation in Cyber Security principles, expertise in domains such as Endpoint, Network, Database, and Cloud Security technologies (including IPS, WAF, Firewalls, Deception, Cloud Security, AV, EDR, Microsoft Defender). Proficiency in log analysis, proactive monitoring, mitigation, and response to network and security incidents is essential. You should be adept at triaging security events and executing incident response steps. Experience in implementing and maintaining extensive Security Operation Policies and procedures, including those for AWS cloud environments, is required. The ability to proactively hunt for and research potential malicious activity using tools like Cortex, Shodan, Qrdar, and Microsoft Defender is crucial. Identifying Indicators of Compromise through static and dynamic analysis of malware, performing advanced security event detection, and threat analysis for complex incidents are expected. Familiarity with Google SecOps/Chronicle, Microsoft Sentinel, Demisto/XSOAR, and the MITRE Framework Attack Methodology is advantageous. A B.E/B.Tech (Tier 1/2) or Master's degree in Computer Science, Information Technology, or a related field, coupled with 8+ years of relevant experience in Cyber, is mandatory. Relevant certifications such as SC 200, Security+, or CEH are highly desirable.
Deloitte
Cybersecurity