24 Sep
|
Deloitte Shared Services India
|
Delhi
24 Sep
Deloitte Shared Services India
Delhi
Key responsibilities
- Monitor, triage, investigate, and resolve security alerts using evidence from SIEM, EDR/XDR, identity, network, email, cloud, and application sources.
- Create and tune correlation rules, behavioral analytics, searches, dashboards, reports, watchlists, and thresholds across supported SIEM platforms.
- Use platform query languages such as SPL, KQL, YARA-L, and XQL to investigate suspicious activity and establish incident scope and timeline.
- Perform log-source onboarding validation, parser and field-mapping checks, use-case testing, and data-quality troubleshooting with engineering teams.
- Lead L2 investigations, escalate confirmed incidents with clear evidence and recommendations, and support containment, eradication, and recovery.
- Map detections to MITRE ATT&CK;, identify coverage gaps, and contribute recent use cases based on threats, incidents, vulnerabilities, and business risk.
- Execute threat hunts, false-positive reviews, alert-quality reviews, backlog reduction, and continuous use-case optimization.
- Create and maintain runbooks, investigation guides, case records, handover notes, knowledge articles, and customer-facing reports.
- Support shift operations,
major incidents, audits, service reviews, and KPI tracking for MTTD, MTTR, SLA, quality, and alert disposition.
Essential qualifications and expertise
- 5-8 years of cybersecurity experience, including at least 3 years in SOC operations, incident response, SIEM administration, or detection engineering.
- Hands-on expertise in at least three leading enterprise SIEM technologies, with preferred platforms including Google Security Operations, Palo Alto Networks Cortex XSIAM, Microsoft Sentinel, and Splunk Enterprise Security.
- Proficiency in at least two relevant query languages, such as YARA-L, XQL, KQL, or SPL, and the ability to interpret raw security telemetry.
- Strong understanding of incident response, MITRE ATT&CK;, Windows/Linux, identity, networking, endpoint, cloud, and common attacker techniques.
Preferred qualifications
- Security+, CySA+, GCIH, GCIA, SC-200, OEM certification, or equivalent.
- Experience with SOAR, Python/API automation, cloud security, threat intelligence, vulnerability management, and managed SOC delivery.
📌 Walk-in || Deloitte_Walk-In Drive_Cyber_Gurgaon_ General SOC (Delhi)
🏢 Deloitte Shared Services India
📍 Delhi