Level: Senior Consultant
As a SOAR Automation Developer, you need to possess an understanding of Indicators of Compromise, characterization and forensic engineering of compromised systems, operations security, compliance, mitigation, and analysis through tools that detect advanced threats.
Work you'll do
As a Senior Consultant on the Detect & Respond team, you will be responsible for designing, developing, and supporting security orchestration and automation solutions for security operations environments.
- Develop automation playbooks using Security Orchestration, Automation, and Response platforms such as Tines, Splunk SOAR, Swimlane, and Palo XSOAR.
- Design and develop integrations with security technologies including Exabeam, Chronicle, CrowdStrike, and Splunk Enterprise Security by using SOAR platforms and application programming interfaces.
- Test, customize, and maintain integrations and automation workflows for security and information technology tools.
- Manage in-scope implementation and integration projects, coordinate with vendors and client stakeholders, and analyze issues to recommend solutions aligned to client needs.
- Support operational improvements for Deloitte Cyber services, follow internal security policies, and contribute to team process and infrastructure improvements.
The team
Deloitte’s Detect & Respond (D&R) aims to combine sophisticated technologies and human intelligence to help the clients monitor, detect, investigate, and respond to known and unknown attacks. We help our clients to be secure, vigilant, and resilient in the face of an ever-increasing array of cyber threats and vulnerabilities. The Detect and Respond team delivers service to clients through following key areas:
- Threat detection and response
- Attack surface management
- Threat Intelligence
- Threat Hunting
- Data Protection
Location: Bengaluru/Hyderabad/Pune/Chennai
Shift Timings: 24/7 rotational shifts; flexibility for night, weekend, and holiday coverage is essential; on-call support required based on project assignments
Qualifications
Required:
- 6+ years of work experience as a Python or JavaScript developer
- Experience developing automation playbooks on Security Orchestration, Automation, and Response platforms
- Experience designing integrations with security tools by using application programming interfaces
- Experience with Structured Query Language, NoSQL, or PostgreSQL
- Experience using code repositories and version control tools, including GitHub
- Understanding of networking protocols and infrastructure, including Transmission Control Protocol/Internet Protocol, Domain Name System, Hypertext Transfer Protocol, routers, and switches
- Bachelor’s degree in Computer Science, Cyber Security, Information Security, Engineering, Information Technology, or a similar field
Preferred:
- 6+ years of experience in security information or technology engineering support
- Certification such as Certified Information Systems Security Professional, GIAC Certified Intrusion Analyst, GIAC Continuous Monitoring, GIAC Certified Incident Handler, Certified Ethical Hacker, or equivalent
- Experience with security operations technologies including Security Information and Event Management, Intrusion Detection System/Intrusion Prevention System, Data Loss Prevention, Web Application Firewall, Endpoint Detection and Response, and Threat Intelligence tools
- Knowledge of threat analysis and mitigation frameworks such as MITRE
- Experience with web application frameworks such as Flask or Django
- Knowledge of cyber threats, defenses, and incident investigation techniques
#Cyber_Cyber Operate