Join Deloitte Cyber as a Consultant supporting cyber incident response engagements across enterprise, cloud, and hybrid environments. In this role, you will help organizations respond to and recover from complex cyber incidents while serving as a trusted technical advisor to client stakeholders. You will support rapid-response incident management, forensic analysis, and threat hunting activities in high-pressure situations that require sound judgment and clear communication.
Work you'll do
As a Consultant on the Cyber Incident Response team, you will be responsible for…
- Lead response activities for cybersecurity incidents, including ransomware, malware, data breach, and insider threat investigations
- Perform triage, containment, and forensic analysis across endpoints, networks, cloud environments, and identity infrastructure
- Conduct threat hunting, log analysis, and investigation activities across security information and event management, endpoint detection and response, and network security platforms
- Document incident timelines, indicators of compromise, findings, and remediation actions, and support post-incident reviews
- Partner with client stakeholders to provide technical updates, support recovery efforts, and contribute to incident response planning and readiness activities
The team
Deloitte’s Cyber Incident Response team helps organizations investigate, contain, and recover from cyber incidents across enterprise, cloud, and hybrid environments. The team supports clients through technical response, forensic analysis, threat hunting, and recovery planning during high-impact events. Professionals in this practice work across industries to help strengthen incident response capabilities, improve readiness, and reduce the impact of future attacks.
Location: Bengaluru/Hyderabad/Pune/Chennai
Shift Timings: Based on client / project needs
Qualifications
Required:
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Engineering, or a comparable technical field
- 3-6 years of cybersecurity experience, including 2+ years of incident response experience
- Experience responding to ransomware, business email compromise, or advanced persistent threat incidents
- Experience with security information and event management platforms such as Splunk, Microsoft Sentinel, QRadar, or Chronicle
- Experience with forensic tools such as Magnet Axiom, EnCase, FTK, Volatility, X-Ways, or Autopsy
- Experience with endpoint detection and response or extended detection and response platforms such as CrowdStrike, SentinelOne, Microsoft Defender, or Carbon Black
- Experience with network analysis, threat intelligence frameworks such as MITRE ATT&CK or STIX/TAXII, and scripting in Python, PowerShell, or Bash
Preferred:
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Certified Intrusion Analyst (GCIA)
- Certified Information Systems Security Professional (CISSP)
- Certified Information Systems Auditor (CISA), Certified Ethical Hacker (CEH), or Offensive Security Certified Professional (OSCP)
#Cyber_Defense & Resilience