Job Title:  T&T | Cyber: D&R | Senior Analyst | SOC - SIEM - Incident Response & Handling| Mumbai, Hyderabad

T&T | Cyber: D&R | Senior Analyst | SOC - SIEM - Incident Response & Handling| Mumbai, Hyderabad
Job requisition ID : 112199 
Location: Mumbai
Entity: Deloitte Touche Tohmatsu India LLP 

 

The team 

 

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity  

 

Your work profile 

  • Investigate security alerts escalated by SOC L1 using SIEM, EDR, XDR, UEBA, NDR, Email Security, and other security platforms.

  • Perform in-depth analysis of security events to determine scope, impact, and root cause.

  • Validate true positives and eliminate false positives through detailed log analysis.

  • Classify incidents based on severity and business impact.

  • Execute containment, eradication, and recovery activities as per incident response procedures.

  • Escalate complex incidents to L2/ L3 or Incident Response teams when required.

  • Analyze indicators of compromise (IOCs) including IPs, URLs, domains, file hashes, and email artifacts.

  • Correlate events across multiple security technologies to identify sophisticated attacks.

  • Identify malicious behavior using the MITRE ATT&CK framework and Cyber Kill Chain.

  • Investigate phishing, malware, ransomware, insider threats, privilege misuse, and suspicious authentication activities.

  • Perform endpoint investigations using EDR/XDR platforms.    

 

 

Key responsibilities:

  • 1-2 years of experience in SOC Incident response and handling.

  • Should be working in SOC, SIEM technologies (LogRhythm, Splunk, Sentinel, Chronicle)

  • EDR/XDR solutions (CrowdStrike, Cortex XDR, Microsoft Defender)

  • Triage, analyze & respond to SIEM events with articulate analysis and clear response guidance/questions to other teams through established collaboration mechanisms (Ticketing systems, Mails)

  • Leverage the Operational & Tactical Threat Intel data from the established feeds & sources to detect Threats

  • Ability to efficiently utilize to log analytics and usage of SIEM for analyzing & filtering logs. Recorded Future Fusion, Brand protection cloud side.

  • Optimizes threat detection products for data security information and event management (SIEM), advanced email protection, endpoint detection and response (EDR), antivirus, intrusion detection systems, firewalls, proxies, and other industry standard security technologies.

  • Works closely with Level 2 & Level 3 team towards the continuous improvement of the service

  • Should have expertise on TCP/IP network traffic and event log analysis.

  • Having strong perseverance to keep the Incident response actions focused & progressed.

  • Ability to effectively communicate (orally & written) complex technical issues to a diverse set of audience that include technical, non-technical & executive level staff.

  •  Bachelor’s or Master’s degree in Computer Science, Information Security, or related field. 

  • Professional is required to work from office  

  • Job location : Hyderabad, Mumbai