25 Sep
|
Deloitte Shared Services India
|
Gurugram
25 Sep
Deloitte Shared Services India
Gurugram
We are seeking cybersecurity professionals with foundational to advanced incident response capability. Candidates should understand or have experience across triage, scoping, evidence collection, containment, eradication, recovery support, root cause analysis, and lessons learned. The ability to operate in time-sensitive situations and collaborate with SOC, engineering, identity, cloud, legal, communications, and infrastructure teams is important.
Candidates should demonstrate an interest in or experience with hands-on investigation beyond dashboards and alerts. Relevant experience may include employment, internships, academic projects, lab work, capture-the-flag exercises, SOC investigations, raw log review, forensic artefact analysis, malware triage, timeline reconstruction, threat hunting, case documentation, stakeholder updates, and post-incident reporting. The depth of expertise and level of ownership expected will be aligned to the candidates experience.
Roles & Responsibilities
- Support or lead end-to-end incident response activities, including triage, scoping, evidence collection, containment, eradication, recovery support, root cause analysis, and post-incident review, based on experience level.
- Investigate security incidents using evidence sources such as EDR telemetry, SIEM alerts, Windows and Linux logs, Sysmon, identity logs, cloud audit logs, network telemetry, mailbox artefacts, SaaS evidence, and forensic artefacts.
- Correlate available evidence to determine the source, impact, timeline, and scope of security incidents and contribute to appropriate containment, mitigation, and remediation actions.
- Investigate phishing, credential compromise, suspicious authentication, malware execution, persistence, privilege abuse, lateral movement, insider activity, ransomware precursors, command-and-control activity, and potential data exfiltration.
- Build and maintain incident timelines, case notes, evidence trackers, query records, decision logs, and structured evidence trails to support technical investigations and reporting.
- Support or lead incident bridge calls, technical discussions, stakeholder updates, and client-facing communications during active response situations, based on experience level.
- Collaborate with SOC, engineering, identity, cloud, legal, communications, and infrastructure teams to obtain evidence, coordinate response actions, and improve investigative workflows, procedures, and playbooks.
- Support or deliver incident response assessments, tabletop exercises, simulations, playbook reviews, and after-action reviews for technical and business audiences.
- Contribute to root cause analysis, lessons learned, control improvement, detection enhancement, and cyber resilience recommendations following incidents.
- Participate in knowledge-sharing and capability development.
Experienced candidates may guide junior team members, review their outputs, and act as technical escalation points for complex investigations.
- Experienced candidates may plan and manage investigation workstreams, allocate tasks, review technical outputs, manage risks and dependencies, mentor team members, and advise senior stakeholders.
- Follow evidence-handling, confidentiality, documentation, quality-review, and client-data protection requirements throughout engagements.
- Prepare and review investigation notes, timelines, evidence maps, indicator lists, malware triage summaries, threat-hunt findings, technical reports, executive summaries, and remediation recommendations.
- Use investigation tools such as Velociraptor, KAPE, Eric Zimmerman tools, Volatility, Wireshark, Zeek, Timesketch, Plaso, Ghidra, x64dbg, PEStudio, CyberChef, Sysinternals, and comparable utilities, based on role requirements and experience.
- Develop, execute, or tune SIEM and EDR queries, threat-hunting logic, Sigma rules, YARA rules, and custom detection content where applicable.
- Conduct threat hunts across EDR, SIEM, DNS, proxy, firewall, VPN, email, cloud, and identity telemetry based on indicators, suspicious behaviours, threat intelligence, and MITRE ATT&CK; techniques.
- Perform malware triage and behavioural analysis using file metadata, hashes, strings, sandbox results, static and energetic analysis, process behaviour, persistence indicators, and network connections.
- Perform forensic triage of Windows and Linux systems, including review of event logs, registry artefacts, prefetch, Shimcache, Amcache, SRUM, scheduled tasks, services, WMI, PowerShell logs, browser artefacts, and process execution evidence.
Required Knowledge
- Relevant cybersecurity experience may range from 0 to 12 years. Candidates may bring experience through employment, internships, academic projects, lab work, SOC operations, incident response, digital forensics, threat hunting, malware analysis, compromise assessment, or security engineering.
- Practical exposure to security monitoring, investigations, or live incident response is preferred. The expected level of independent ownership will be aligned to the candidate’s experience and demonstrated capability.
- Knowledge of Windows, Linux, Active Directory, DNS, networking, authentication, cloud platforms,
and enterprise identity concepts appropriate to the candidate’s experience level.
- Familiarity or hands-on experience with SIEM and EDR platforms such as QRadar, Microsoft Sentinel, Splunk, CrowdStrike, Microsoft Defender, SentinelOne, or equivalent.
- Understanding of the MITRE ATT&CK; framework, cyber kill chain, attacker tradecraft, incident response lifecycle, and adversary-focused investigation methods appropriate to the candidate’s experience.
- Ability or willingness to work beyond dashboards and alerts using endpoint artefacts, identity logs, cloud logs, network evidence, mailbox artefacts, malware indicators, and raw enterprise telemetry.
- Awareness or experience with SOAR technologies, response playbooks, case-management workflows, evidence tracking, and ITSM tools.
- Ability to work in time-sensitive and high-pressure situations with professionalism, structured thinking, attention to detail, sound judgement, and timely escalation.
- Exposure to memory forensics, malware reverse engineering, Active Directory Certificate Services, cloud forensics, detection engineering, YARA, Sigma, or purple teaming is desirable.
- Ability to document observations objectively, distinguish confirmed findings from hypotheses, communicate limitations, and maintain evidence traceability.
- Familiarity with scripting or query languages such as Python, PowerShell, Bash, KQL, SPL, SQL, APIs, or regular expressions for investigation and automation.
- Understanding of identity security concepts, including Kerberos, NTLM, LDAP, privileged groups, authentication logs, delegation, trusts, and common lateral movement techniques.
- Knowledge of network concepts, including TCP/IP, DNS, HTTP and HTTPS, common ports and protocols, proxies, firewalls, VPNs, beaconing, tunnelling, and packet capture analysis.
- Understanding of malware concepts such as hashes, strings, static and dynamic analysis, sandboxing, droppers, loaders, packed binaries, fileless techniques, process injection, and command-and-control behaviour.
- Understanding of Windows security events, PowerShell logs, Sysmon, processes, services, scheduled tasks, registry artefacts, user activity, and common persistence mechanisms.
Required Qualification
Bachelor’s or Master’s degree in Computer Science, Information Security, Cybersecurity, Engineering, Digital Forensics, or a related discipline. Candidates with other educational backgrounds may also be considered where they demonstrate relevant practical capability.
Certifications
Relevant certifications are desirable and may include Security+, CySA+, SC-200, GCIH, GCFA, GCFE, GNFA, GREM, GCIA, ECIH, CHFI, CRTP, CRTE, or relevant Microsoft, Splunk, SIEM, EDR, cloud, or forensic platform certifications. Practical capability and hands-on technical depth will be given significant consideration.
📌 Walk-in || Deloitte_Walk-In Drive_Cyber_Gurgaon_ Incident Response (Gurugram)
🏢 Deloitte Shared Services India
📍 Gurugram