Join Deloitte’s Cyber Incident Response team as a Manager and help organizations respond to complex cyber incidents across enterprise, cloud, and hybrid environments. In this role, you will lead incident response activities, advise client stakeholders during high-impact events, and help drive forensic analysis, threat hunting, and recovery efforts. This position requires strong technical judgment, responsiveness during active incidents, and the ability to lead teams in fast-paced environments.
Work you'll do
As a Manager on the Cyber Incident Response team, you will be responsible for leading incident response engagements and supporting clients through complex cyber investigations and recovery efforts.
- Lead incident response engagements involving malware, ransomware, data breach, and insider threat investigations across enterprise, cloud, and hybrid environments
- Direct triage, containment, and forensic analysis activities across endpoints, networks, cloud environments, and identity infrastructure, including Windows, Linux, and macOS systems
- Oversee threat hunting, log analysis, malware analysis, and investigative activities across security information and event management, endpoint detection and response, and network security platforms
- Advise client stakeholders during active incidents, support tabletop exercises and incident response planning, and contribute to development of internal playbooks and knowledge assets
- Document incident timelines, indicators of compromise, attack methodologies, findings, remediation actions, and post-incident reviews for client delivery
The team
Deloitte’s Cyber Incident Response team helps organizations investigate, contain, and recover from complex cyber incidents across enterprise, cloud, and hybrid environments. The team supports clients through forensic analysis, threat hunting, incident management, and recovery planning during high-impact events. Professionals in this practice work across industries to strengthen incident response readiness, improve detection and response capabilities, and reduce the impact of future attacks.
Location: Bengaluru, Hyderabad, Pune, Chennai
Shift Timings: Based on client / project needs
Qualifications
Required:
- 9+ years of experience in cybersecurity, including 2+ years of experience in incident response
- Experience responding to ransomware, business email compromise, or advanced persistent threat incidents
- Experience supporting enterprise clients in a consulting environment
- Experience with security information and event management platforms such as Splunk, Microsoft Sentinel, QRadar, or Chronicle
- Experience with forensic tools such as Magnet Axiom, EnCase, FTK, Volatility, X-Ways, or Autopsy
- Experience with endpoint detection and response or extended detection and response platforms, network analysis tools, threat intelligence frameworks such as MITRE ATT&CK or STIX/TAXII, scripting in Python, PowerShell, or Bash, and Active Directory attack techniques
- Bachelor’s degree in Computer Science, Information Security, or a comparable technical field, or equivalent experience
Preferred:
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Certified Intrusion Analyst (GCIA)
- Certified Information Systems Security Professional (CISSP) or equivalent certification
- Certified Information Systems Auditor (CISA), Certified Ethical Hacker (CEH), or Offensive Security Certified Professional (OSCP)
- Experience leading incident response teams, client communications, or post-incident recovery planning