Deloitte Cyber understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful insights to help our clients navigate the ever-changing threat design and technology as we partner with clients to transform their security posture.
As a Senior Consultant at Deloitte Consulting, you will design, develop, and deploy enterprise-scale software solutions, lead the creation of robust pipelines and manage code deployment across environments. You will collaborate with cross-functional, global teams to translate functional requirements into effective deliverables, independently guiding and mentoring junior team members. Your role spans the full project lifecycle, including estimation, planning, execution, and tracking key metrics for analysis, ensuring high-quality and timely delivery of solutions.
Work you'll do
As a Senior Consultant on the Cyber Operate team, you will be responsible for:
- Serving as a primary point of contact for client stakeholders and supporting security automation strategy and value realization
- Designing, developing, and managing SOAR playbooks for triage, enrichment, investigation, containment, escalation, and remediation
- Leading integrations across security platforms, including security information and event management (SIEM), endpoint detection and response (EDR), identity and access management (IAM), threat intelligence, ticketing, firewall, email, cloud, and endpoint security tools
- Building and optimizing AI-augmented SOAR workflows, including alert triage, contextual enrichment, incident summarization, escalation logic, and governed decisioning
- Defining automation metrics, dashboards, technical documentation, and workflow improvements to enhance reliability, scalability, and security operations maturity
The team
Cyber Operate teams manage clients' critical cyber assets either as a fully managed service or in partnership with clients. They deliver skilled talent, cutting-edge technologies, and robust processes to operate client cyber capabilities. This includes managing the identity lifecycle, security operations, threat intelligence, application security, business transformation, and ensuring continuous compliance. Services include Cyber-as-a-Service, Managed Application Security, and Managed Extended Detect & Respond (MXDR).
Location: Bengaluru/Hyderabad/Pune/Chennai/Gurugram/Kolkata
Shift Timings: 2:00 PM to 11:00 PM IST
Qualifications
Required:
- 6+ years of experience in cybersecurity, SOAR engineering, security automation, or security operations
- Experience with SOAR platforms such as Cortex XSOAR, Splunk SOAR, Swimlane, IBM Resilient, or Tines
- Experience with security operations center processes, security information and event management (SIEM) workflows, and incident response lifecycle activities
- Experience integrating application programming interfaces (APIs), webhooks, and third-party security technologies into automated workflows
- Experience with Python, PowerShell, Bash, JSON, REST APIs, or similar scripting and automation technologies
- Experience designing AI-augmented SOAR workflows that include large language model (LLM)-based reasoning, prompt engineering, output validation, and human-in-the-loop decisioning
- Bachelor's degree in Computer Science, Cyber Security, Information Security, Engineering, or Information Technology
Preferred:
- Experience with multi-cloud security environments across Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP)
- Familiarity with MITRE ATT&CK, detection engineering, and incident response practices
- Experience with information technology service management (ITSM) or case management tools such as ServiceNow or Jira
- Relevant certifications in cybersecurity, cloud security, or SOAR or SIEM platforms
- Experience with AI-assisted playbook generation, machine learning-based alert triage, or automated incident summarization in enterprise SOAR platforms
- Experience architecting Claude-based or equivalent agentic security operations center capabilities, including tool use, Model Context Protocol (MCP), extended reasoning, or structured outputs
#Cyber_Cyber Operate