Job Title:  T&T | Cyber: D&R | Deputy Manager | SOC - SIEM - Incident Response & Handling | Mumbai, Hyderabad

T&T | Cyber: D&R | Deputy Manager | SOC - SIEM - Incident Response & Handling | Mumbai, Hyderabad
Job requisition ID : 112200 
Location: Mumbai
Entity: Deloitte Touche Tohmatsu India LLP 

 

The team  

 

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity  

 

Your work profile 

 

  • Manage large Security Operation Centers projects.
  • Responsible for adherence of SLA for all tickets and deliverables in the project 
  • Advise and tracks remediation of issues found during an incident or vulnerability that is required to conclude a security investigation 
  • Responsible for the validation and analysis of investigations within Security Operations Center (SOC) done by L1/L2
  • Good understanding of SOC concepts and log review from various sources such as IBM QRadar SIEM, Palo Alto and SOAR 
  • Responsible for completing the documentation of the investigation; determine the validity and priority of the activity and Carry out Level 3 triage of incoming issues and escalate to L4 if needed
  • Creation of SOPs and run book and maintain it.
  • Provide communication and escalation support to L1/L2 throughout the incident per the SOC guidelines.

 

Key responsibilities:

 

  • 6-10 years of experience.
  • Strong knowledge of incident-response frameworks, including NIST and SANS.
  • Deep understanding of networking, operating systems, cloud, endpoint and identity security, and core cybersecurity principles.
  • Proficiency in SIEM, SOAR, UEBA, EDR/XDR, threat intelligence, network-monitoring, and forensic tools.
  • Expertise in advanced incident investigation, digital forensics, malware analysis, and reverse-engineering concepts.
  • Ability to analyse complex logs, network traffic, endpoint telemetry, and other security data sources.
  • Strong knowledge of attacker tactics, MITRE ATT&CK, lateral movement, persistence, privilege escalation, and data exfiltration.
  • Experience in threat hunting, detection engineering, and SIEM use-case development.
  • Working knowledge of scripting and automation using Python, PowerShell, or Bash.
  • Knowledge of ISO 27001 and applicable security standards and regulatory requirements.
  • Strong analytical, troubleshooting, decision-making, communication, and documentation skills.
  • Ability to perform effectively under pressure and lead technical response during critical incidents.
  • Preferably hold at least one of the following certifications: CISSP, CISM, ITIL,PMP,CISA,CEH
  • Bachelor’s or Master’s degree in Computer Science, Information Security, or related field. 
  • Professional is required to work from office  
  • Job location : Hyderabad, Mumbai