Bengaluru, IN

Applications have closed


Für unsere Kunden entwickeln wir integrierte Lösungen. Unsere Services umfassen Wirtschaftsprüfung, Steuerberatung, Financial Advisory und Consulting.

View all jobs at Deloitte

Risk Advisory
Cyber Risk

What impact will you make?

Every day, your work will make an impact that matters, while you thrive in a dynamic culture of
inclusion, collaboration and high performance. As the undisputed leader in professional services,
Deloitte is where you’ll find unrivaled opportunities to succeed and realize your full potential.

The Team
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being
secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks.

Work you’ll do
As a part of our Risk Advisory team, you’ll build and nurture positive working relationships with
teams and clients with the intention to exceed client expectations. The Cyber Risk Services – Cyber Vigilance & Operations practice helps organizations in assessing and establishing their cyber security appetite via the Secure. Vigilant. Resilient. programs, and also in assisting in the ongoing management, maintenance, and adaptation of their programs, as the business and threat
environments change. The Cyber Risk Services – CVO team delivers service to clients through
following key areas of cyber security:

Cyber Threat Management analyst role is to defend client’s network & data by investigating security incidents that have been triaged and escalated by the first level of Analyst in Security Operations Center. This includes performing analysis of indicators of compromise, investigating security incidents by reviewing relevant security data, coordinating with impacted application owners and users and implementing or arranging remediation actions.

Demonstrates proven expertise and success in incident handling, triage of events, network analysis and threat detection, trend analysis. Should have the following skills:
•  Deep understanding of computer intrusion activities, incident response techniques, tools, and procedures
•    Knowledge of Windows, Active Directory, DNS & Linux operating systems,
•    Good Experience in SIEM monitoring (QRadar, Splunk, Arcsight, Sumologic, Azure Sentinel)
•    Knowledge of SOAR technologies, working with playbooks (Cortex, Phantom, Demisto)
•    Working experience and knowledge of ITSM tools for incident management.
•    Must be action oriented and have a proactive approach to solving issues.
•    Knowledge of security logs, log quality review.
•    Knowledge on IT (Operating systems, networking, databases) and IT security knowledge (system and network security) including IT security tools.
•    Good knowledge of office collaboration tools


Responsibilities & Duties

•    Detect, Analyze, Investigate, and report qualified security incidents to the Client as per the defined SLA
•    Provide recommendations to the security incidents reported as per SLA
•    Investigates incidents using various security event sources (FW, IDS, PROXY, AD, EDR, DLP etc.).
•    Investigations into non-standard incidents and execution of standard scenarios.
•    Provide dashboard and data related to Incidents/Offenses for governance reports.
•    Escalates to L2 if investigations uncover unusual or atypical situations.
•    Perform system health check of security monitoring devices & report anomalies to admin/engg team.
•    Escalation to client Management if the incidents are not closed by client as per the escalation metrics
•    Closure of incidents on ITSM tool with accurate resolution comments to determine true positive and false positive classification.
•    Monitoring unhealthy log source/data source and escalate to engineering team to fix them.


•    Overall experience of at least 8+ years in SIEM monitoring and  Cyber security Incident response and Management
•    Hands-on experience with security tools and devices, operating systems, and/or networking devices desired.
•    Proven skills and experience in log analysis, incident investigations 
•    Experience working across diverse teams to facilitate solutions
•    Experience working with Security practitioners

•    Willingness to working 24/7 environment in rotating shifts.

•    Bachelor’s Degree in Engg or equivalent

•    English: Fluent 

•    Certifications like ECSA, ECIH, Security+ & GIAC is preferred

How you’ll grow

At Deloitte, our professional development plan focuses on helping people at every level of their career to identify and use their strengths to do their best work every day. From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities to help build world-class skills in addition to hands-on experience in the global, fast-changing business world. From on-the-job learning experiences to formal development programs at Deloitte University, our professionals have a variety of opportunities to continue to grow throughout their career. Explore Deloitte University, The Leadership Center.

At Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits. Learn more about what working at Deloitte can mean for you.

Our purpose
Deloitte is led by a purpose: To make an impact that matters.
Every day, Deloitte people are making a real impact in the places they live and work. We pride ourselves on doing not only what is good for clients, but also what is good for our people and the communities in which we live and work—always striving to be an organization that is held up as a role model of quality, integrity, and positive change. Learn more about Deloitte's impact on the world

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  2  0  0

Tags: Active Directory ArcSight Azure DNS ECSA EDR GIAC Governance IDS Incident response Linux Log analysis Monitoring Network security QRadar Sentinel SIEM SOAR SOC Splunk Strategy Threat detection Windows

Perks/benefits: Career development Health care Startup environment Team events

Region: Asia/Pacific
Country: India

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.