Job Title:  T&T | Cyber: D&R | Assistant Manager I Security Information and Event Management (SIEM) I Bangalore

T&T | Cyber: D&R | Assistant Manager I Security Information and Event Management (SIEM) I Bangalore
• Job requisition ID : 112969 
• Location: Bengaluru
• Entity: Deloitte Touche Tohmatsu India LLP 

The team  

 

 

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity  

 

 

Your work profile

 

 

 

  

 

 

  • Monitor security alerts and events from various sources, through SIEM.  
  • Perform initial triage and classification of incidents and handling to alerts escalated by L1s.
  • Investigate alerts to identify potential security incidents.  
  • Escalate confirmed incidents to SOC L2 Analysts and/or Incident Response Team.  
  • Document incident details, actions taken, and resolution steps in the incident management system.  
  • Assist in the containment and mitigation of security threats.  
  • Utilize threat intelligence feeds and tools to enhance detection capabilities.  
  • Generate and deliver security reports and metrics to stakeholders.  
  • Participate in post-incident reviews to identify gaps and improvements in the SOC processes.  
  • Correlated data from multiple sources to identify and respond to security events.
  • Escalating the critical incidents to L3 or other senior incident responders.
  • Should have the capabilities of threat hunting and communicating the results with stakeholders.
  • Stay updated with the latest security trends, vulnerabilities, and attack vectors.  
  • Suggesting the new use cases to improve threat detection coverage.  
  • Willingness to work in a 24x7 rotational shift model, including night shifts at client location mandatorily (WFO only).

  

 

  

Key skills required 

 

 

  • Sound Cyber Security Principles and well versed in security domains of Endpoint , Network, Database, Cloud Security technologies like IPS, WAF, Firewall, Deception, Cloud Security, AV, EDR, .  
  • Conduct senior level log analysis, proactive monitoring, mitigation & response to network & security incidents. Triage security events and carry out incident response steps.  
  • Implement & Maintain Extensive Security Operation Policies and procedures documentation including AWS cloud  
  • Proactively Hunt & research potential malicious activity using tool like Cortex, Shodan, Qrdar etc.  
  • Identify Indicator of Compromise through static & dynamic analysis of commodity and 0-day malware  
  • Perform advanced security event detection and threat analysis for complex and/or escalated security events.  
  • QRadar, Demisto/XSOAR , Qualys, MITRE Framework Attack Methodology.  
  • Education B.E / B.Tech (Tier 1/2) in Computer Science, Information Technology or related fields 
  • 5+ Years of relevant experience in Cyber security with strong networking and security fundamentals.
  • Must be holding at least one of the following certifications: Security+/ECSA/GCFA/GCFE/Any SIEM certification  
  • Base location: Mumbai/Navi Mumbai  
  • Professional is required to work from office