Overview In this role you will deliver and operate managed cybersecurity services, analyzing monitoring outputs, validating alerts, and supporting threat hunts. You'll work with cross-functional teams to create detection content, respond to incidents, and help sustain client cyber resilience. The role involves hands-on analysis of network and endpoint data, plus developing runbooks and improving SOC processes. You will be part of a client-centric cyber operations team at Deloitte, contributing to secure and proactive client outcomes. This position offers exposure to advanced threat scenarios and a pathway to leadership within the SOC.
Compensation / Benefits- discretionary annual incentive program
- professional development opportunities
- reasonable accommodations for disabilities
- flexible work arrangements
- opportunities for career growth
- support for certifications
Responsibilities- Analyze monitoring results, validate escalated alerts, and thoroughly investigate events
- Perform root cause analysis and search related to threat intel; assist Threat Hunting with investigations
- Analyze network and endpoint data using SIEM and other tools; examine malware to identify indicators of compromise; create detection signatures
- Advise on detection engineering content and testing; guide response plans based on incident type/severity
- Provide end-to-end event analysis and incident escalations to Shift Lead/Engineering/SDMs and SOC Manager
- Draft and update runbooks/playbooks; maintain processes and templates; track SOC SLAs; pursue certifications and learning requirements
- Support Shift Leads and assume Shift Lead duties in their absence
Key requirements- 2+ years in cybersecurity or security operations
- Experience with SIEM, IDS/IPS, DLP, Proxy, WAF, EDR, Anti-Virus, Sandboxing, firewalls, Threat Intelligence, Penetration Testing
- Knowledge of APT tactics, techniques, and procedures; understanding of attack activities (network probing, DDOS, malware activity)
- Understanding of TCP/IP, DNS, HTTP; knowledge of security architecture and solutions
- Ability to travel 10% and work 24/7 shifts with 50% office time; limited immigration sponsorship may be available
- Ability to work independently and in a team
- Effective written and verbal communication
- Meticulous attention to detail and quality
- Security information and event management (SIEM)
- IDS/IPS, Data Loss Prevention (DLP)
- Proxy, Web Application Firewall (WAF)