Join the Cyber Incident Response team at Deloitte as a Senior Consultant supporting organizations through complex cyber incidents across enterprise, cloud, and hybrid environments. In this role, you will serve as a trusted technical advisor to client stakeholders while helping lead rapid-response incident management, forensic analysis, and threat hunting activities. This position requires sound judgment, immediate responsiveness during active incidents, and the ability to work independently in high-pressure situations.
Work you'll do
As a Senior Consultant on the Cyber Incident Response team, you will be responsible for…
- Lead incident response activities for malware, ransomware, data breach, and insider threat investigations across enterprise, cloud, and hybrid environments
- Perform triage, containment, and forensic analysis across endpoints, networks, cloud environments, and identity infrastructure, including Windows, Linux, and macOS systems
- Conduct threat hunting, log analysis, malware analysis, and investigation activities across security information and event management, endpoint detection and response, and network security platforms
- Document incident timelines, indicators of compromise, attack methodologies, findings, and remediation actions, and prepare post-incident reports and reviews
- Serve as a technical advisor to client stakeholders during active incidents, support tabletop exercises and incident response planning, and contribute to internal playbooks and knowledge assets
The team
Deloitte’s Cyber Incident Response team helps organizations investigate, contain, and recover from complex cyber incidents across enterprise, cloud, and hybrid environments. The team supports clients through forensic analysis, threat hunting, incident management, and recovery planning during high-impact events. Professionals in this practice work across industries to strengthen incident response readiness, improve detection and response capabilities, and reduce the impact of future attacks.
Location: Bengaluru/Hyderabad/Pune/Chennai
Shift Timings: Based on client / project needs
Qualifications
Required:
- Bachelor’s degree in Computer Science, Information Security, or a comparable technical field, or equivalent experience
- 6-10 years of cybersecurity experience, including at least 2+ years of incident response experience
- Experience responding to ransomware, business email compromise, or advanced persistent threat incidents
- Experience supporting enterprise clients in a consulting environment
- Experience with security information and event management platforms such as Splunk, Microsoft Sentinel, QRadar, or Chronicle
- Experience with forensic tools such as Magnet Axiom, EnCase, FTK, Volatility, X-Ways, or Autopsy
- Experience with endpoint detection and response or extended detection and response platforms, network analysis tools, threat intelligence frameworks such as MITRE ATT&CK or STIX/TAXII, scripting in Python, PowerShell, or Bash, and Active Directory attack techniques
Preferred:
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Certified Intrusion Analyst (GCIA)
- Certified Information Systems Security Professional (CISSP) or equivalent certification
- Certified Information Systems Auditor (CISA), Certified Ethical Hacker (CEH), or Offensive Security Certified Professional (OSCP)
#Cyber_Defense & Resilience