Job Title:  T&T | Cyber: D&R I Manager | Incident Response & Handling | Bengaluru

T&T | Cyber: D&R I Manager | Incident Response & Handling | Bengaluru
Job requisition ID : 111010 
Location: Bengaluru
Entity: Deloitte Touche Tohmatsu India LLP 

 

The team  

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity  

 

Your work profile 

As Manager in our Cyber Team, you’ll build and nurture positive working relationships with teams and clients with the intention to exceed client expectations: -  

  • Serve as the L3 technical escalation point for complex and high-severity cyber security incidents within the SOC.
  • Lead end-to-end investigation, containment, eradication, recovery and resolution of P1/P2 and complex security incidents.
  • Perform advanced security investigations across Microsoft Sentinel, Palo Alto Cortex XSOAR and Microsoft Defender XDR/EDR.
  • Conduct advanced KQL-based investigation and threat hunting across endpoint, identity, cloud, network and application telemetry.
  • Correlate security events across multiple security controls to establish attack timelines, scope, impact and root cause.
  • Develop, tune and optimize SIEM detection rules, correlation logic and threat-hunting use cases.
  • Design, develop and optimize XSOAR playbooks and automated incident response workflows to improve SOC efficiency and reduce MTTR.
  • Perform proactive threat hunting based on MITRE ATT&CK, threat intelligence, emerging threats and attacker TTPs.
  • Drive detection engineering and MITRE ATT&CK coverage improvement across the SOC.
  • Provide technical expertise and guidance to L1/L2 SOC analysts, including investigation reviews and escalation support.
  • Lead technical response activities during major security incidents and cyber crisis situations.
  • Perform detailed Root Cause Analysis (RCA) and define corrective and preventive actions following major incidents.
  • Collaborate with Network, Infrastructure, Cloud, IAM, Application, Endpoint and ITSM teams to coordinate containment and remediation.
  • Identify opportunities to automate repetitive SOC activities using XSOAR, APIs, Python and PowerShell.
  • Translate incident and threat-hunting findings into new detections, playbooks, use cases and security improvements.
  • Contribute to continuous improvement of SOC processes, detection capabilities, response effectiveness and operational maturity.
  • Ensure incident investigations and response activities comply with defined SLA, security, governance and documentation requirements.

   

Key Skills Required:

  • 10 to 12 years of relevant experience in Cyber 
  • Strong KQL skills for advanced investigation, correlation and threat hunting.
  • Advanced hands-on experience with Microsoft Defender XDR / Defender for Endpoint.
  • Strong expertise in Incident Response, Major Incident Management and RCA.
  • Strong Threat Hunting capabilities using MITRE ATT&CK, threat intelligence and attacker TTPs.
  • Experience in Detection Engineering, use-case development, tuning and MITRE ATT&CK mapping.
  • Strong understanding of Identity & Cloud Security, particularly Microsoft Entra ID and Azure.
  • Experience with Threat Intelligence, IOC enrichment and STIX/TAXII.
  • Working knowledge of Python / PowerShell, REST APIs, JSON and automation.
  • Strong understanding of network, endpoint, identity, cloud and application security telemetry.
  • Ability to correlate events across Sentinel + Defender + XSOAR to investigate complex attacks.
  • Experience developing automated investigation and response workflows.
  • Ability to mentor and provide technical guidance to L1/L2 SOC analysts.
  • Strong analytical, problem-solving, documentation and stakeholder communication skills.
  • Ability to work effectively under pressure during P1/P2 and major security incidents.
  • Education: B.E./B.Tech (Tier 1/2) or Master’s degree in Information Security, Computer Science, or a related field.
  • Preferred Certifications: GCIH/ECIH (preferred), SC-200 (Microsoft Security Operations Analyst)