Join Deloitte Cyber’s Cyber Defense & Resilience practice as a Consultant supporting the evolution of modern Security Operations Centers. In this role, you will help clients design, build, and scale automation, orchestration, and AI-assisted workflows that improve cyber detection, triage, and response. The ideal candidate brings Security Operations Center experience, hands-on SOAR development capabilities, and a strong foundation in scripting, integrations, and security operations. You will work across Deloitte, client, and vendor teams to reduce analyst toil, improve operational efficiency, and strengthen cyber resilience.
Work you'll do
As a Consultant on the Cyber Defense & Resilience team, you will be responsible for:
- Develop and maintain automation and orchestration playbooks using SOAR platforms such as Tines, Splunk SOAR, Swimlane, Palo XSOAR, or Google SOAR
- Build AI-assisted and agentic workflows that support triage, enrichment, and response use cases within Security Operations Center environments
- Design and develop integrations across the security technology stack using application programming interfaces, connectors, and orchestration platforms
- Support solution delivery activities, including testing, implementation, stakeholder communication, and operational improvement initiatives
- Apply Security Operations Center knowledge across people, process, and technology to identify automation opportunities and support secure service delivery
The team
Cyber Defense & Resilience teams assist clients in defending against advanced threats by transforming security operations, and by monitoring technology, data analytics, and threat intelligence. They help manage and protect dynamic attack surfaces and provide rapid crisis and cyber incident response, thereby ensuring that clients can be ready for, respond to, and recover from business disruptions. Examples of work include Operational Resilience, Crisis & Incident Response, and Security Operations Center Transformation. As part of Deloitte’s Cyber Defense & Resilience portfolio, our SecOps teams’ partner with clients to strengthen security operations and cyber resilience. We deliver end-to-end services—from strategic assessments and innovation workshops to implementing next-generation SIEM and AI-SOC solutions—enabling proactive risk identification and mitigation across digital environments. Leveraging advanced analytics, AI-driven detection, agentic automation, and optimized data management, we provide continuous monitoring and rapid response to emerging threats. This integrated approach empowers organizations to build robust, future-ready security postures and confidently navigate an evolving cyber threat landscape.
Location: Bangalore, Hyderabad, Pune, Chennai
Shift Timings: General
Qualifications
Required:
- 3-6 years of experience developing solutions in Python or JavaScript
- Hands-on experience in a Security Operations Center or Security Information and Event Management operations environment
- Hands-on experience building, testing, and maintaining playbooks in Security Orchestration, Automation, and Response platforms
- Experience integrating systems through application programming interfaces in client-server, web, or microservices architectures
- Experience using SQL, NoSQL, or PostgreSQL
- Experience using Git-based version control platforms such as GitHub
- Bachelor’s or Master’s degree in Cybersecurity, Information Technology, Engineering, Computer Science, or Information Systems
Preferred:
- Experience building AI integrations, agents, or agentic workflows for security operations use cases
- Experience with Security Information and Event Management, Intrusion Detection Systems/Intrusion Prevention Systems, Data Loss Prevention, Web Application Firewall, Endpoint Detection and Response, or threat intelligence tools
- 3+ years of experience in security information or technology engineering support
- Experience using MITRE ATT&CK or enterprise threat mitigation frameworks
- Certified Information Systems Security Professional, GIAC Certified Intrusion Analyst, GIAC Continuous Monitoring, GIAC Certified Incident Handler, or Certified Ethical Hacker certification
- Experience using Flask or Django for dashboard or widget development
#Cyber_Defense & Resilience