Job Title: T&T | Cyber: D&R | Deputy Manager | SOC - SIEM - Incident Response & Handling | Mumbai, Hyderabad

T&T | Cyber: D&R | Deputy Manager | SOC - SIEM - Incident Response & Handling | Mumbai, Hyderabad
• Job requisition ID : 112200
• Location: Mumbai
• Entity: Deloitte Touche Tohmatsu India LLP
The team
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity
Your work profile
- Analyse L1/L2 escalations and provide on-call support for critical incidents.
- Lead critical incident response, including containment, eradication, recovery, and post-incident review.
- Should be working in SOC, SIEM technologies (LogRhythm, Splunk, Sentinel, Chronicle)
- Coordinate remediation with infrastructure, network, application, cloud, endpoint, and business teams.
- Develop advanced response strategies, playbooks, and runbooks.
- Collect and analyse evidence, logs, network traffic, endpoint data, and forensic artefacts to identify attack origin and impact.
- Perform malware analysis, threat hunting, and threat-intelligence-led investigations.
- Develop SIEM use cases, correlation rules, signatures, dashboards, and alert logic.
- Perform root-cause analysis; identify security gaps, control weaknesses, and exploited vulnerabilities.
- Recommend security-control enhancements, technologies, automation, and preventive actions.
- Build automation scripts for investigation, enrichment, containment, and reporting.
- Continuously improve playbooks, SOPs, and escalation processes.
- Mentor L1/L2 analysts and provide incident-response training.
- Document findings, evidence, decisions, and actions; prepare incident, RCA, post-incident, and executive reports.
- Communicate incident impact, risks, findings, and recommendations to management and stakeholders.
- Stay current with emerging threats, attack techniques, vulnerabilities, tools, and security best practices.
Key responsibilities:
- 6-10 years of experience.
- Strong knowledge of incident-response frameworks, including NIST and SANS.
- Deep understanding of networking, operating systems, cloud, endpoint and identity security, and core cybersecurity principles.
- Proficiency in SIEM, SOAR, UEBA, EDR/XDR, threat intelligence, network-monitoring, and forensic tools.
- Expertise in advanced incident investigation, digital forensics, malware analysis, and reverse-engineering concepts.
- Ability to analyse complex logs, network traffic, endpoint telemetry, and other security data sources.
- Strong knowledge of attacker tactics, MITRE ATT&CK, lateral movement, persistence, privilege escalation, and data exfiltration.
- Experience in threat hunting, detection engineering, and SIEM use-case development.
- Working knowledge of scripting and automation using Python, PowerShell, or Bash.
- Knowledge of ISO 27001 and applicable security standards and regulatory requirements.
- Strong analytical, troubleshooting, decision-making, communication, and documentation skills.
- Ability to perform effectively under pressure and lead technical response during critical incidents.
- Preferably hold at least one of the following certifications: CISSP, CISM, ITIL,PMP,CISA,CEH
- Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
- Professional is required to work from office
- Job location : Hyderabad, Mumbai
