Job Title: T&T | Cyber: D&R | Consultant | SOC - SIEM - Incident Response & Handling | Mumbai, Hyderabad

T&T | Cyber: D&R | Consultant | SOC - SIEM - Incident Response & Handling | Mumbai, Hyderabad
• Job requisition ID : 112202
• Location: Mumbai
• Entity: Deloitte Touche Tohmatsu India LLP
The team
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity
Your work profile
- Knowledge of security concepts such as cyber-attacks and techniques, threat vectors, risk management, incident management etc.
- Fundamental understanding of network traffic analysis including TCP/IP, routing, switching, protocols, etc.
- Reviews the most recent SIEM alerts to see their relevance and urgency. Carries out triage to ensure that a genuine security incident is occurring. Oversees and configures security monitoring tools.
- Maintain, manage, improve and update security incident process and protocol documentation (Run Book).
- Strong understanding of Windows event log analysis, Recorded Future Fusion, Brand protection cloud side..
- Acts as Security Incident Handler for high-impact cyber security incidents and advanced attacks in accordance with Cyber Kill Chain methodology and incident response process.
- Conducts malware analysis and identification of Indicators of Compromise (IOCs) to evaluate incident scope and associated impact.
- Enhances workflow and processes driving incident response and mitigation efforts.
- Practical understanding of exploits, vulnerabilities, computer network intrusions, adversary tactics, exfiltration techniques and common knowledge.
- Demonstrate proficiency in the Incident Response Process as well as the performance of threat hunting and SOC operations.
- Log analysis across disparate log sources, prioritize and differentiate between potential intrusion attempts and false alarms.
- Sound understanding of different attack frameworks like Kill Chain & MITRE & ability to utilize them for incident response & reporting.
Key responsibilities:
-
2-5years of experience - SOC operations, incident response, threat monitoring, or cybersecurity investigations.
-
Should be working in SOC, SIEM technologies (LogRhythm, Splunk, Sentinel, Chronicle)
-
EDR/XDR solutions (CrowdStrike, Cortex XDR, Microsoft Defender)
-
Review and triage information security alerts worked by L1, provide analysis, determine and track remediation, and escalate as appropriate.
-
Desirable to have experience of SOC Monitoring and tirage using SIEM technologies (LogRhythm, Splunk, Sentinel, Chronicle)
-
Knowledge on XDR can be an added advantage
-
Knowledge of security concepts such as cyber-attacks and techniques, threat vectors, risk management, incident management etc.
-
Fundamental understanding of network traffic analysis including TCP/IP, routing, switching, protocols, etc.
-
Reviews the most recent SIEM alerts to see their relevance and urgency. Carries out triage to ensure that a genuine security incident is occurring. Oversees and configures security monitoring tools.
-
Strong understanding of Recorded Future Fusion, Brand protection cloud side..
-
Inform L4 team of proactive and reactive actions to minimize false positives.
-
Maintain, manage, improve and update security incident process and protocol documentation (Run Book).
-
Strong understanding of Windows event log analysis.
-
Acts as Security Incident Handler for high-impact cyber security incidents and advanced attacks in accordance with Cyber Kill Chain methodology and incident response process.
-
Conducts malware analysis and identification of Indicators of Compromise (IOCs) to evaluate incident scope and associated impact.
-
Enhances workflow and processes driving incident response and mitigation efforts.
-
Practical understanding of exploits, vulnerabilities, computer network intrusions, adversary tactics, exfiltration techniques and common knowledge.
-
Demonstrate proficiency in the Incident Response Process as well as the performance of threat hunting and SOC operations.
-
Log analysis across disparate log sources, prioritize and differentiate between potential intrusion attempts and false alarms.
-
Sound understanding of different attack frameworks like Kill Chain & MITRE & ability to utilize them for incident response & reporting.
-
Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
-
Preferably possess at least one of the following certifications:
-
CompTIA Security+, ECSA,GCFA,GCFE, CISSP
-
Relevant OEM certification for SIEM, EDR/XDR, SOAR, or security monitoring platforms
-
Professional is required to work from office
- Job location : Hyderabad, Mumbai
