T&T; | Cyber: D&R; I Senior Analyst | SOC Ops | Mumbai
• Job requisition ID : 110004
• Location: Mumbai
• Entity: Deloitte Touche Tohmatsu India LLP
The team
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash current opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity
Your work profile
The SOC Monitoring Analyst is responsible for continuously monitoring security alerts and events generated from various security tools, identifying potential threats, performing initial triage, documenting findings, and escalating verified security incidents to the appropriate teams. The analyst ensures continuous visibility of the organization's security posture while adhering to defined operational procedures and service level agreements (SLAs).
Key responsibilities:
- Shall have 1-2 Years of experience
- Monitor security alerts from SIEM, EDR/XDR, Firewalls, IDS/IPS, Email Security, Web Proxy, Cloud Security, DLP, and other security platforms.
- Continuously monitor dashboards for critical, high, medium, and low severity alerts.
- Identify suspicious or malicious activities based on predefined use cases.
- Perform first-level validation of alerts to determine legitimacy.
- Perform initial analysis of security events.
- Differentiate between true positives and false positives.
- Collect relevant evidence such as source IP, destination IP, usernames, hostnames, timestamps, and affected assets.
- Enrich alerts using internal and external threat intelligence.
- Create and update incidents in the ITSM or ticketing system.
- Classify incidents according to severity and impact.
- Escalate confirmed incidents to SOC L2 or Incident Response teams with complete investigat