As an Assistant Manager, Cyber Engineering, you will join Deloitte’s Security Operations Center to help identify, investigate, and respond to advanced cyber threats across complex environments. This role requires deep experience in threat hunting, incident analysis, and security operations, along with the ability to work across network, endpoint, and security monitoring technologies. You will collaborate with cross-functional teams to strengthen detection, improve response, and support ongoing threat mitigation efforts in a 24x7x365 environment.
Work you'll do
As an Assistant Manager, Cyber Engineering on the Security Operations Center and Threat Hunting team, you will be responsible for:
- Research threat actors, attack vectors, and emerging campaigns, and perform proactive threat hunting across multiple environments
- Analyze host, network, and protocol activity to investigate alerts, identify infection vectors, assess scope, and document findings
- Support incident investigations related to vulnerabilities, zero-day activity, and other security events in coordination with incident response teams
- Develop, test, and refine security monitoring content, hunting techniques, automation, and operational procedures
- Mentor junior analysts, present hunt findings to stakeholders, and provide remediation recommendations to improve security posture
The team
Deloitte’s Cyber Engineering professionals help organizations strengthen their security posture through monitoring, threat detection, investigation, and response capabilities. The team works across complex environments to identify threats, improve operational resilience, and support the ongoing evolution of security operations. Team members collaborate closely with threat intelligence, incident response, and engineering stakeholders to address emerging risks and enhance detection and response outcomes.
Location: Hyderabad
Shift Timings: 11 AM to 8 PM
Qualifications
Required:
- 5+ years of experience in security operations, threat hunting, incident response, or threat intelligence
- 5+ years of hands-on experience with Splunk or another security information and event management (SIEM) platform
- Experience with endpoint detection and response (EDR), intrusion detection systems and intrusion prevention systems (IDS/IPS), firewalls, antivirus tools, data loss prevention (DLP), web proxies, and malware analysis tools
- Experience analyzing network and web traffic, including Internet Protocol (IP), Domain Name System (DNS), Hypertext Transfer Protocol (HTTP), Hypertext Transfer Protocol Secure (HTTPS), File Transfer Protocol (FTP), and Simple Mail Transfer Protocol (SMTP)
- Experience with Windows or Unix administration and security architecture concepts
- Bachelor’s degree in Computer Science, Information Management, Cybersecurity, or another technical discipline
- Ability to work in a 24x7x365 Security Operations Center environment, including flexible schedules and holiday coverage
Preferred:
- One or more industry certifications, such as GIAC Certified Intrusion Analyst, GIAC Continuous Monitoring, Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or GIAC Certified Incident Handler (GCIH)
- Experience with Windows PowerShell, Windows Management Instrumentation (WMI), Python, Java, or Ruby
- Experience developing or testing SIEM detection content
- Experience documenting chain of custody and investigation actions
- Experience presenting technical findings to stakeholders
- Experience mentoring analysts or delivering technical training sessions