Walk-in || Deloitte_Walk-In Drive_Cyber_Gurgaon_ Threat Hunter - (Delhi)

Walk-in || Deloitte_Walk-In Drive_Cyber_Gurgaon_ Threat Hunter - (Delhi)

24 Sep
|
Deloitte Shared Services India
|
Delhi

24 Sep

Deloitte Shared Services India

Delhi

Key responsibilities

- Develop risk- and intelligence-led hunting hypotheses mapped to MITRE ATT&CK;, organizational attack surface, control gaps, and recent threat activity.

- Query and correlate large datasets in SIEM, EDR/XDR, network, cloud, identity, and other security analytics platforms.

- Hunt for identity compromise, persistence, lateral movement, defense evasion, command and control, data staging, and exfiltration behaviors.

- Analyze endpoint process trees, authentication patterns, DNS, proxy, firewall, SaaS, cloud control-plane, and workload telemetry to identify anomalies.

- Validate findings, distinguish malicious behavior from legitimate operations, determine impacted entities, and initiate or support incident response.

- Create and tune YARA-L, XQL, Sigma, YARA, IOC, behavioral, and analytics-based detections from validated hunt outcomes.

- Build hunt packages containing objectives, assumptions, data requirements, queries, findings, evidence, gaps, and recommended corrective actions.

- Partner with CTI, detection engineering, purple-team,



vulnerability, cloud, IAM, and endpoint teams to improve coverage and control effectiveness.

- Measure hunt effectiveness through coverage, findings, new detections, telemetry gaps, control improvements, and repeatability.

Essential qualifications and expertise

- 5-8 years of cybersecurity experience with at least 3 years in threat hunting, incident response, detection engineering, DFIR, or advanced SOC analysis.

- Hands-on expertise with SIEM, plus EDR/XDR and one or more cloud, identity, or network analytics platforms.

- Robust knowledge of Windows and Linux internals, Active Directory/Entra ID attacks, malware behavior, network protocols, cloud threats, and MITRE ATT&CK.;

- Ability to write efficient queries and scripts using YARA-L, XQL, KQL/SPL, Python, PowerShell, or equivalent.

Preferred qualifications

- GCIH, GCIA, CISSP, OSCP, or equivalent.

📌 Walk-in || Deloitte_Walk-In Drive_Cyber_Gurgaon_ Threat Hunter - (Delhi)
🏢 Deloitte Shared Services India
📍 Delhi

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: walk-in || deloitte_walk-in drive_cyber_gurgaon_ threat hunter - (delhi) / delhi

Subscribe to this job alert:

Get the latest job offers by email for: walk-in || deloitte_walk-in drive_cyber_gurgaon_ threat hunter - (delhi) / delhi