T&T | Cyber: D&R | Senior Analyst | SOC - SIEM - Incident Response & Handling| Mumbai, Hyderabad

Deloitte

1–3 yrs Mumbai, Hyderabad Full Time Work from office
Deloitte logo
Posted : 1 week ago
Actively hiring

Job description

Join Deloitte's Cyber team as a Senior Analyst, focusing on Security Operations Center (SOC), SIEM, and Incident Response. We empower organizations to prevent cyberattacks and safeguard critical assets. Our approach emphasizes security, vigilance, and resilience, integrating cyber risk management into strategic development to effectively manage information and technology risks.

Learn more about our Cybersecurity offerings and how we help clients unleash new opportunities by staying secure and resilient against evolving threats.

Responsibilities

Investigate security alerts escalated by SOC L1 using SIEM, EDR, XDR, UEBA, NDR, and Email Security platforms. Conduct in-depth analysis of security events to determine scope, impact, and root cause, validating true positives and eliminating false positives through detailed log analysis.

Classify incidents based on severity and business impact, executing containment, eradication, and recovery activities per incident response procedures. Escalate complex incidents to L2/L3 or Incident Response teams as needed. Analyze indicators of compromise (IOCs) and correlate events across multiple security technologies to identify sophisticated attacks.

Identify malicious behavior using the MITRE ATT&CK framework and Cyber Kill Chain. Investigate various threats including phishing, malware, ransomware, insider threats, privilege misuse, and suspicious authentication activities. Perform endpoint investigations using EDR/XDR platforms.

Qualifications

This role requires 1–3 years of experience in SOC monitoring, security operations, incident triage, or cybersecurity operations. Candidates must be proficient in SIEM technologies (LogRhythm, Splunk, Sentinel, Chronicle) and EDR/XDR solutions (CrowdStrike, Cortex XDR, Microsoft Defender).

Key responsibilities include triaging, analyzing, and responding to SIEM events with clear analysis and guidance. Leverage threat intelligence feeds to detect threats and efficiently utilize log analytics and SIEM for log analysis. Optimize threat detection products, including SIEM, email protection, EDR, antivirus, IDS, firewalls, and proxies.

Collaborate closely with Level 2 & 3 teams for continuous service improvement. Expertise in TCP/IP network traffic and event log analysis is essential. Strong perseverance and effective communication skills for conveying complex technical issues to diverse audiences are required. A Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field is preferred. Relevant certifications like CompTIA Security+, CEH, or ECSA are advantageous. This is an onsite position in Mumbai or Hyderabad.

Essential Skills

SIEMIncident ResponseEDRXDRUEBANDREmail SecurityLog AnalysisMITRE ATT&CKCyber Kill ChainPhishing AnalysisMalware AnalysisRansomware AnalysisInsider Threat DetectionPrivilege Misuse DetectionSuspicious Authentication AnalysisTCP/IP Network Traffic AnalysisLogRhythmSplunkSentinelChronicleCrowdStrikeCortex XDRMicrosoft Defender

Good to Have

CompTIA Security+CEHECSARelevant OEM certification for SIEM or security monitoring tools

Highlights

  • Actively hiring

More Details

RoleT&T | Cyber: D&R | Senior Analyst | SOC - SIEM - Incident Response & Handling| Mumbai, Hyderabad
IndustryInformation Technology & Services
DepartmentCybersecurity
Employment TypeFull Time, Work from office

About the Company

Deloitte logo

Deloitte

Information Technology & Services

T&T | Cyber: D&R | Senior Analyst | SOC - SIEM - Incident Response & Handling| Mumbai, Hyderabad at Deloitte | SkillMX | SkillMX