Cyber
Deloitte Cyber understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful insights to help our clients navigate the ever-changing threat design, and technology as we partner with clients to transform finance.
Position Summary
Level: Senior Solution Advisor
Work you’ll do:
Incident Response Leadership
- Lead response to sophisticated, enterprise-wide security incidents including nation-state attacks, supply chain compromises, and coordinated ransomware campaigns
- Execute complex forensic investigations across hybrid cloud and on-premises environments
- Make critical decisions on containment strategies that balance security requirements with business continuity
- Coordinate multi-team response efforts involving internal resources, client teams, law enforcement, and third-party vendors
- Serve as incident commander for high-severity events requiring executive escalation
- Senior on-call responsibilities including primary escalation point for critical incidents with expectation of rapid response (30-60 minutes) for major incidents
Technical Excellence & Innovation
- Perform advanced memory forensics, malware analysis, and adversary infrastructure mapping
- Develop custom tools, scripts, and automation to enhance investigation efficiency
- Lead threat hunting campaigns to identify advanced persistent threats and zero-day exploits
- Reverse engineer sophisticated malware including rootkits, bootkits, and custom frameworks
- Contribute to threat intelligence development and adversary tracking initiatives
Team Leadership & Development
- Mentor and develop Consultant-level incident responders and junior team members
- Lead technical review and quality assurance of incident reports and deliverables
- Design and deliver training programs on advanced response techniques and emerging threats
- Serve as escalation point for complex technical challenges during active incidents
Practice Development
- Contribute to methodology development, standard operating procedures, and playbook creation
- Participate in pre-sales activities including scope, technical demonstrations, and proposal development
- Identify opportunities for expanded services and long-term client relationships
- Stay at the forefront of industry trends and integrate emerging technologies into service delivery
The Team:
Cyber Defense & Resilience teams help clients defend against sophisticated threats by transforming security operations, leveraging technology, data analytics, and threat intelligence for continuous monitoring and rapid incident response. They manage dynamic attack surfaces and support business continuity through services such as operational resilience, crisis and incident response, and security operations center transformation.
Resilience as a Practice focuses on preparing organizations to anticipate, withstand, and recover from disruptions—including cyberattacks, natural disasters, and operational failures—by embedding resilience into processes, technology, and culture. Deloitte’s Resilience Team combines technical, operational, and strategic expertise to deliver integrated solutions for business continuity, disaster recovery, and risk management, ensuring organizations meet regulatory demands and maintain stakeholder trust during crises.
Qualifications
Must Have Skills/Project Experience/Certifications:
- 7+ years of progressive experience in cybersecurity, with at least 5 years in SOC L2/L3 and IR roles
- Experience across multiple industry verticals (financial services, healthcare, manufacturing, retail, etc.)
- Demonstrated ability to manage client relationships and deliver services.
- Expert-level proficiency with forensic analysis across Windows, Linux, macOS, and mobile platforms
- Advanced knowledge of cloud security and forensics in AWS, Azure, and Google Cloud Platform
- Deep understanding of attack lifecycles, adversary tradecraft, and advanced persistent threat operations
- Expertise in analyzing complex malware including fileless attacks, living-off-the-land techniques, and supply chain compromises
- Strong programming/scripting skills (Python, PowerShell, C/C++, Go) for tool development and automation
Certifications (Required/Strongly Preferred)
- GCFA (GIAC Certified Forensic Analyst) - Strongly Preferred
- GREM (GIAC Reverse Engineering Malware) - Strongly Preferred
- One of: CISSP, CISM, or equivalent senior security certification
- Additional certifications such as GCTI, GPEN, OSCP, or vendor-specific certifications (CrowdStrike, Microsoft, Splunk) are advantageous
Education:
- Bachelor’s degree or higher in Computer Science, or equivalent experience.
Location:
- Hyderabad/Bangalore/Pune/Chennai