Job Title: T&T | Cyber : D&R | Consultant | Security Information and Event Management (SIEM) | Delhi

T&T | Cyber : D&R | Consultant | Security Information and Event Management (SIEM) | Delhi
• Job requisition ID : 112406
• Location: Delhi
• Entity: Deloitte Touche Tohmatsu India LLP
The Team
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity
Your Work Profile
- Monitor security alerts and events from various sources, including alerts in SIEM/SOAR and from MDE (Microsoft Defender for Endpoints).
- Perform initial triage and classification of incidents.
- Investigate alerts to identify potential security incidents.
- Escalate confirmed incidents to SOC L2 Analysts and/or Incident Response Team.
- Document incident details, actions taken, and resolution steps in the incident management system.
- Assist in the containment and mitigation of security threats.
- Utilize threat intelligence feeds and tools to enhance detection capabilities.
- Generate and deliver security reports and metrics to stakeholders.
- Participate in post-incident reviews to identify gaps and improvements in the SOC processes.
- Stay updated with the latest security trends, vulnerabilities, and attack vectors.
- Willingness to work in a 24x7 rotational shift model, including night shifts, is mandatory.
- Sound Cyber Security Principles and well versed in security domains of Endpoint , Network, Database, Cloud Security technologies like IPS, WAF, Firewall, Deception, Cloud Security, AV, EDR, Microsoft Defender.
- Conduct log analysis, proactive monitoring, mitigation & response to network & security incidents. Triage security events and carry out incident response steps.
- Implement & Maintain Extensive Security Operation Policies and procedures documentation including AWS cloud
- Proactively Hunt & research potential malicious activity using tool like Cortex, Shodan, Qrdar, Microsoft Defender etc.
- Identify Indicator of Compromise through static & dynamic analysis of commodity and 0-day malware
- Perform advanced security event detection and threat analysis for complex and/or escalated security events.
- Google Secops/Chronicle, Microsoft Sentinel, Demisto/XSOAR , MITRE Framework Attack Methodology.
Nice to Have
- Education B.E / B.Tech (Tier 1/2) in Computer Science, Information Technology or related fields
- 2+ Years of relevant experience in Cyber
- SC 200 certification.
- Security+, CEH, or other relevant security certifications.
