Vista previa de la oferta
USI FY27 | Cyber Operate- NG SIEM Sentinel - L35
mid · Technology / Software Development
As an experienced Consultant at Deloitte Consulting, you will be responsible for individually delivering high quality work products within due timelines. Need-basis you will be mentoring and/or directing junior team members/liaising with onsite/offshore teams to understand the functional requirements.
Work you'll do
As a Consultant on the Detect & Respond team, you will be responsible for supporting Security Information and Event Management (SIEM) operations, content development, and platform enhancements.
- Perform SIEM configuration management, troubleshooting, and day-to-day operations support.
- Onboard security log data sources and develop new and custom parsers.
- Conduct SIEM architecture assessments, content baseline assessments, and design reviews.
- Develop, validate, and test SIEM use cases, alerting queries, and content to support detection, triage, investigation, and remediation.
- Review system security plans, network diagrams, vulnerability requirements, and patching requirements, while supporting key risk indicator and key performance indicator monitoring.
- Develop scripts to automate data collection and onboarding tasks, provide on-call support as needed, and coordinate with technical teams and client stakeholders.
The team
Deloitte’s Detect & Respond (D&R) aims to combine sophisticated technologies and human intelligence to help the clients monitor, detect, investigate, and respond to known and unknown attacks. We help our clients to be secure, vigilant, and resilient in the face of an ever-increasing array of cyber threats and vulnerabilities. The Detect and Respond team delivers service to clients through following key areas:
- Threat detection and response
- Attack surface management
- Threat Intelligence
- Threat Hunting
- Data Protection
Location: Bengaluru/Hyderabad/Pune/Chennai
Shift Timings: 24/7 rotational shifts; flexibility for night, weekend, and holiday coverage is essential; on-call support required based on project assignments
Qualifications
Required:
- 3-6 years of experience in security information and/or technology engineering support
- Bachelor's degree in Computer Science, Cyber Security, Information Security, Engineering, Information Technology, or a similar field
- Certification such as Certified Information Systems Security Professional, GIAC Certified Intrusion Analyst, GIAC Continuous Monitoring, Certified Ethical Hacker, or equivalent
- Experience with Security Information and Event Management, Intrusion Detection System/Intrusion Prevention System, Data Loss Prevention, Proxy, Web Application Firewall, Endpoint Detection and Response, Anti-Virus, Sandboxing, firewalls, Threat Intelligence, and Penetration Testing
- Knowledge of Advanced Persistent Threat tactics, techniques, and procedures
- Knowledge of attack activities including network probing, scanning, distributed denial-of-service, and malicious code activity
- Knowledge of network infrastructure devices, networking protocols, and system security architecture, including routers, switches, Transmission Control Protocol/Internet Protocol, Domain Name System, and Hypertext Transfer Protocol
Preferred:
- Experience interpreting, searching, and manipulating data within enterprise logging solutions and Information Technology Service Management tools
- SIEM certifications such as Splunk Architecture, ArcSight, Sentinel, or Chronicle
- Certifications such as Offensive Security Certified Professional, Certified Information Systems Auditor, Certified Information Security Manager, GIAC Certified Incident Handler, GIAC Continuous Monitoring, GIAC Certified Detection Analyst, GIAC Penetration Tester, GIAC Certified Forensic Analyst, or GIAC Cyber Threat Intelligence
#Cyber_Cyber Operate