Job Title:  Manager | Cloud Security | Across Locations | Enterprise Security | Cloud Security

Manager | Cloud Security | Across Locations | Enterprise Security | Cloud Security
Job requisition ID : 109937 
Location: Pune
Entity: Deloitte Touche Tohmatsu India LLP 

Job Description – L3 Security Specialist / Incident Response Lead

Role Type: Expert-Level Technical Escalation / Advanced Incident Response

Function: Highest-Level Technical Investigation, Complex Security Incident Handling, Threat-Led Analysis, Advanced Containment Recommendation, Stakeholder Advisory, & Strategic Improvement of Detection & Response Maturity

Job Summary

The L3 Security Specialist / Incident Response Lead Acts as the Highest Technical Escalation Point for Critical & Complex Security Incidents in the 24x7 CERT Service Model This Role is Responsible for Advanced Threat Investigation, Technical Leadership During Severe Incidents, Scoping of Impact, Specialist Analysis, Strategic Containment Advice, Improvement of Runbooks/Detections, & Support to Service Governance for Major Security Risks. The Role also Acts as a Technical Mentor for L1/L2 Teams & Helps Strengthen Operational Maturity Over Time

Key Responsibilities

Lead Technical Investigation of Complex, High-Severity, or Escalated Security Incidents Beyond Standard L2 Analysis

Perform Advanced Incident Scoping to Determine Extent of Compromise, Impacted Systems/Accounts, Attack Sequence, & Likely Threat Progression

Review Escalations Involving Suspicious Privileged Activity, Repeated Compromise Patterns, Container/Runtime Anomalies, High-Risk Infrastructure Alerts, or Evidence of Coordinated Attack Behavior

Provide Expert-Level Containment & Remediation Recommendations Based on Risk, Business Criticality, Threat Behavior, & Operational Constraints

Support High-Priority Incident Communications by Translating Technical Findings into Structured Stakeholder-Ready Updates

Work Closely with Internal Resolver Groups, Infrastructure/Application Owners, Incident Managers, & Service Management Stakeholders During Critical Investigations

Identify Systemic Weaknesses & Recurring Root Causes, & Recommend Longer-Term Improvements in Detection Use Cases, Process Maturity, SOPs, Playbooks, & Escalation Models

Guide Security Analysts on Advanced Analysis Methods, Evidence Handling, Incident Scoping, & Response Decision-Making

Participate in Weekly Incident Reviews, Monthly Governance Reporting, & Continuous Service Improvement Discussions with a Strong Focus on Risk Trends & Service Resilience

Strengthen Knowledge Management Through Development of Advanced Use Cases, Threat Investigation Patterns, Specialized Runbooks, & Lessons Learned Documentation

Required Technical Skills

Deep Expertise in Incident Response, Advanced Threat Investigation, Attack Analysis, Containment Strategy, & Operational Decision-Making in Live Incidents

Strong Experience with SIEM/SOAR Platforms, Especially Investigation Workflows, Offense Analysis, Data Correlation, & High-Fidelity Case Handling

Strong Understanding of Security Telemetry Across Logs, Authentication Systems, Network Activity, Endpoint Behavior, Container/Runtime Monitoring, & Threat Advisories

Ability to Assess Business Impact vs Technical Severity & Advise on Containment Actions Without Losing Sight of Continuity Requirements

Strong Knowledge of Incident Lifecycle Management, Escalation Governance, Reporting, Knowledge Management, & Service Improvement Practices

Ability to Write Clear Executive & Technical Summaries for Senior Stakeholders & Operational Teams

Required Experience / Qualification

Bachelor’s Degree in Cybersecurity, Computer Science, Information Security, or Related Field Preferred

Typically 6–10+ Years of Experience in Incident Response, CERT/SOC Engineering, Advanced Threat Analysis, or Senior Security Operations Roles

Proven Experience Handling Critical/High-Severity Security Investigations & Guiding Cross-Functional Technical Response

  • Certifications such as GCIA, GCIH, GCFA, CISSP, SC-200, Vendor SIEM Certifications, or Equivalent Advanced Credentials would be Advantageous