Job Title: T&T | Cyber : D&R | Deputy Manager | Security Information and Event Management | Delhi

T&T | Cyber : D&R | Deputy Manager | Security Information and Event Management | Delhi
• Job requisition ID : 111201
• Location: Delhi
• Entity: Deloitte Touche Tohmatsu India LLP
The Team
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity
Your Work Profile
• Lead and coordinate the investigation and response to escalated alerts and ensure in-depth technical analysis is conducted.
• Monitor security alerts and logs to identify and counteract potential security threats.
• Coordinate and lead high-level security incidents in our CIRT team, ensuring effective communication with all stakeholders.
• Utilize tools such as Microsoft Defender, Azure Sentinel, and ServiceNow to monitor, analyse, and manage security events.
• Develop new detection use-cases to mature our monitoring and detection landscape, and regular review of production use-cases to curb false positive alerting.
• Contribute to developing and maintaining incident response strategies and update processes, playbooks to align with evolving cybersecurity landscapes.
• Mentor and oversee junior analysts, fostering a culture of continuous learning and professional development.
• Conduct post-incident analysis and present detailed reports to executive management, recommending improvements to security policies and procedures.
• Participate in a rotational on-call support to support our 24x7x365 operations.
• Participate in the design and implementation of new security tools and technologies.
• Any Graduate , Bachelor’s degree in information security, Computer Science, or a related field. A master’s degree in Cybersecurity or Business Management is preferred.
• Generate comprehensive reports on incident findings and response actions for senior management.
Nice to Have
• A minimum of 5 years of experience in a SOC environment, preferably in Financial Services, with at least 2 years in an L2/L3 position.
• Proficient in security solutions like SIEM (Sentinel), intrusion detection/prevention systems, EDR/XDR (Defender), SOAR, and ticketing solution like ServiceNow, etc.
• Proven track record of managing security incidents and working with technical and non-technical stakeholders, with timely delivery of updates and tasks assigned by Incident Manager.
• Experience in network flow and traffic analysis to identify C2 and apply preventative controls to defend.
• Ability to investigate and navigate through complex investigations and leveraging solutions like Sandbox, CyberChef, etc. to identify the end payload and mitigating it.
• Relevant professional certifications like SC-200, CEH, SCS-C02, GCIH, GCIA, etc. are beneficial.
• Experience developing and fine-tuning Detection use-cases using KQL and possess Innovative Mindset to challenge current processes.
• Employ excellent communication skills, both written and verbal, to articulate security concepts, present findings, and engage with diverse stakeholders, including technical and non-technical audiences.
• Demonstrate adaptability to evolving security landscapes, staying updated on industry trends, and proactively integrating new technologies and methodologies into security tooling strategies.
• Programming experience (PowerShell, Bash, Python, JavaScript) to analyse and investigate potentially malicious scripts on both Windows and Linux systems.
