TT | Cyber: DR | Assistant Manager | SIEM Sentinel | Gurgaon
Job requisition ID : 101085
Location: Delhi
Entity: Deloitte Touche Tohmatsu India LLP
The Team
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash current opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity
Key Responsibilities:
Investigate and respond to escalated security incidents from L1 analysts.
Perform in-depth analysis of alerts and events using Microsoft Sentinel and other security platforms.
Execute incident response activities including containment, eradication, and recovery.
Correlate data from multiple sources: Firewalls, IDS/IPS, EDR, Azure AD, endpoints, and cloud environments.
Conduct root cause analysis and identify attack vectors and impacted assets.
Develop and fine-tune detection rules, analytics, and hunting queries in Microsoft Sentinel.
Utilize KQL (Kusto Query Language) to perform advanced threat hunting and log analysis.
Work with SOAR capabilities to automate response actions and improve efficiency.
Create and maintain incident response playbooks, SOPs, and runbooks.
Provide detailed incident reports and technical briefings to stakeholders.
Assist L1 analysts in triage and provide mentorship and guidance.
Monitor and ensure health and integrity of log ingestion pipelines.
Participate in threat hunting and proactive detection initiatives.
Collaborate with cross-functional teams (IT, Cloud, Security Engineering).
Required Skills Expertise
Experience: 4+ years in SOC operations, incident response, or cybersecurity monitoring.
SIEM Expertise: Strong hands-on experience with Microsoft Sentinel and other SIEM tools.