T&T | Cyber: D&R | Assistant Manager | Network Security | Bengaluru
- Job requisition ID : 110078
- Location: Bengaluru
- Entity: Deloitte Touche Tohmatsu India LLP
The team
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity
Your work profile
The L2 Network Security Operations & Infrastructure Engineer is responsible for advanced troubleshooting, configuration changes, policy management, incident response, and operational support across multiple cybersecurity and network technologies. The role acts as an escalation point for L1, performs RCA, drives change requests, and ensures secure and stable operations of firewalls, IDS/IPS, WAF, EDR/XDR, DLP, CASB, NAC, MDM, PAM, and related infrastructure.
1. Perimeter & Network Security
Firewall Management
- Review and validate firewall change requests (NAT, security rules, objects).
- Implement approved firewall rule changes (Palo Alto / Fortinet / Cisco / Check Point).
- Troubleshoot security policy drops, routing issues, VPN failures.
- Perform log analysis (traffic logs, threat logs, session captures).
- Manage IPsec/SSL VPN configurations and certificate updates.
- Conduct periodic rule reviews, cleanup, and optimization.
IDS/IPS Management
- Fine-tune signatures and suppression rules.
- Analyze and respond to intrusion alerts with contextual investigation.
- Update IPS policies, block malicious IPs/domains as required.
WAF Management
- Configure and tune WAF security rules (SQLi, XSS, bots, API protection).
- Review blocked requests, false positives, and apply exclusions/safe rules.
- Support application onboarding and custom policy creation.
DDoS & Micro segmentation
- Analyze DDoS alerts, traffic patterns, and mitigation actions.
- Support micro segmentation rule creation and policy tuning.
2. Endpoint & Email Security
EDR & XDR
- Perform deep investigations of malware/behavioral alerts.
- Tune detection policies and exclusion rules.
- Validate IOC-based detections and perform threat hunting activities.
- Coordinate remediation—including isolation, containment, and agent repair.
Secure Email Gateway
- Configure policies (anti-spam, anti-phishing, URL protection, attachment sandboxing).
- Investigate email delivery issues and false positives.
- Ensure DMARC/DKIM/SPF compliance.
3. Identity & Access Security
PAM (Privileged Access Management)
- Configure and maintain PAM policies, vaults, and session monitoring.
- Troubleshoot onboarding/offboarding of privileged accounts.
- Create workflow approvals and access rules.
4. Data Protection & Cloud Security
DLP
- Fine-tune DLP policies for endpoint, web, and email channels.
- Configure DLP rules for sensitive data types (PCI, PII, PHI, source code).
- Investigate DLP violations and provide RCA.
CASB
- Configure SaaS policies (Shadow IT, anomaly detection, threat protection).
- Analyze risky apps and user behaviors.
- Integrate CASB with SSO/IdP, DLP, or web gateways.
5. Infrastructure Support
NAC (Forescout / Cisco ISE / Aruba Clear Pass)
- Configure posture checks, VLAN assignments, and device profiling.
- Troubleshoot authentication failures, radius issues, and profiling mismatches.
- Onboard new device types and update classification policies.
Patch Management (Windows/Linux)
- Configure patch baselines and compliance policies.
- Troubleshoot agent issues, patch failures, deployment delays.
- Work with application teams for patch exception handling.
MDM (Intune / Workspace ONE)
- Configure compliance rules, device policies, and app deployment.
- Troubleshoot profile failures, device sync issues, and enrollment errors.
Switch & WiFi Management
- Manage VLAN/port configurations, STP issues, and link flaps.
- Troubleshoot wireless authentication, coverage, and performance problems.
6. Incident Response & Operations
- Act as escalation point for L1 for all security incidents.
- Perform log analysis using SIEM and security tools.
- Conduct incident containment and coordinate with L3 during major incidents.
- Perform RCA (Root Cause Analysis) and create lessons learned.
- Maintain runbooks, SOPs, and technical documentation.
7. Change, Compliance & Reporting
- Raise, review, and implement CRs (Change Requests).
- Participate in internal and external audits.
- Manage policy compliance and control implementation.
- Prepare weekly/monthly KPI and SLA reports.
Key skills required
- 4+ Years experience in Network Security & Infrastructure support.
- Strong knowledge of firewalls, VPNs, NAT, routing, and security zones.
- Good understanding of SIEM, endpoint protection, threat detection.
- Hands-on with EDR, DLP, WAF, PAM, CASB, NAC, and MDM platforms.
- Understanding of Zero Trust and segmentation concepts.
- Ability to read packet captures (Wireshark/TCPDump).
- Knowledge of cloud platforms (Azure/AWS/GCP) is an added advantage.
- Strong analytical and troubleshooting skills.
- Ability to mentor and guide L1 teams.
- Clear communication with clients and stakeholders.
- Good documentation and reporting skills.
- Master's or Bachelor’s degree in Cybersecurity, Information Technology, or related field.