Level: Senior Consultant
As a Senior Consultant at Deloitte Consulting, you will design, develop, and deploy enterprise-scale software solutions, lead the creation of robust pipelines and manage code deployment across environments. You will collaborate with cross-functional, global teams to translate functional requirements into effective deliverables, independently guiding and mentoring junior team members. Your role spans the full project lifecycle, including estimation, planning, execution, and tracking key metrics for analysis, ensuring high-quality and timely delivery of solutions.
Work you'll do
As a Senior Consultant on the Cyber Operate team, you will be responsible for designing, developing, and optimizing security orchestration and automation solutions that improve security operations outcomes.
- Serve as a primary point of contact for senior client stakeholders, understand security strategies, influence technology decisions, and drive value realization.
- Design, develop, and manage advanced SOAR playbooks to automate alert triage, enrichment, investigation, containment, escalation, and remediation activities.
- Lead integration of the SOAR platform with Security Information and Event Management, Endpoint Detection and Response, Identity and Access Management, threat intelligence, ticketing, firewall, email, cloud, and endpoint security tools.
- Partner with Security Operations Center analysts, incident responders, and engineering teams to identify automation opportunities, develop reusable frameworks, and improve response workflows.
- Support and enhance incident response capabilities through automated decisioning, response orchestration, case management integration, technical documentation, and workflow optimization.
- Lead AI-augmented SOAR workflow design, evaluate emerging automation capabilities, define automation metrics and reporting, ensure alignment with security policies and compliance requirements, and mentor junior engineers and analysts.
The team
Cyber Operate teams manage clients' critical cyber assets either as a fully managed service or in partnership with clients. They deliver skilled talent, cutting-edge technologies, and robust processes to operate client cyber capabilities. This includes managing the identity lifecycle, security operations, threat intelligence, application security, business transformation, and ensuring continuous compliance. Services include Cyber-as-a-Service, Managed Application Security, and Managed Extended Detect & Respond (MXDR).
Location: Bengaluru/Hyderabad/Pune/Chennai
Shift Timings: 2:00 PM to 11:00 PM IST, with on-call and after-hours support for critical security incidents, escalations, and operational needs, and flexibility to collaborate with global teams across time zones
Qualifications
Required:
- 6+ years of experience in cybersecurity, SOAR engineering, security automation, or security operations
- Experience with SOAR platforms such as Cortex XSOAR, Splunk SOAR, Swimlane, IBM Resilient, or Tines
- Experience with Security Operations Center processes, Security Information and Event Management workflows, and the incident response lifecycle
- Experience integrating application programming interfaces, webhooks, and third-party security technologies into automated workflows
- Experience with Python, PowerShell, Bash, JavaScript Object Notation, and Representational State Transfer application programming interfaces
- Experience across enterprise security domains including endpoint, email, cloud, identity, network, and threat intelligence
- Bachelor’s degree in Computer Science, Cyber Security, Information Security, Engineering, or Information Technology
Preferred:
- Experience with Amazon Web Services, Microsoft Azure, and Google Cloud Platform security environments
- Experience with MITRE ATT&CK, detection engineering, and incident response practices
- Experience with ServiceNow or Jira
- Certification in cybersecurity, cloud security, or SOAR/SIEM platforms
- Experience leading automation initiatives or mentoring technical teams
- Experience with AI-augmented SOAR capabilities, including AI-assisted playbook generation, machine learning-based alert triage, and automated incident summarization.
#Cyber_Cyber Operate