About this role
Deloitte Cyber seeks a Consultant in its Cyber Defense & Resilience practice to help clients modernize Security Operations Centers (SOCs). The role focuses on automation, orchestration and AI-assisted workflows that improve cyber detection, triage and response, reduce analyst workload and strengthen resilience. Locations are Bangalore, Hyderabad, Pune and Chennai, India; shift timings are general.
Responsibilities
- Develop and maintain automation and orchestration playbooks using SOAR platforms such as Tines, Splunk SOAR, Swimlane, Palo XSOAR or Google SOAR.
- Build AI-assisted and agentic workflows for SOC triage, enrichment and response. Design integrations across security tools using APIs, connectors and orchestration platforms.
- Support testing, implementation, stakeholder communication and operational improvements. Work with Deloitte, client and vendor teams to identify automation opportunities and improve secure service delivery.
Required qualifications
- 3–6 years of experience developing solutions in Python or JavaScript; hands-on experience in a SOC or SIEM operations environment and building, testing and maintaining SOAR playbooks.
- Experience integrating systems through APIs in client-server, web or microservices architectures; using SQL, NoSQL or PostgreSQL; and using Git-based version control such as GitHub.
- A bachelor’s or master’s degree in Cybersecurity, Information Technology, Engineering, Computer Science or Information Systems.
Preferred qualifications
- Experience building AI integrations, agents or agentic workflows for security operations; experience with SIEM, IDS/IPS, DLP, WAF, EDR or threat intelligence tools; and 3+ years in security information or technology engineering support.
- Familiarity with MITRE ATT&CK or enterprise threat mitigation frameworks; CISSP, GIAC Certified Intrusion Analyst, GIAC Continuous Monitoring, GIAC Certified Incident Handler or Certified Ethical Hacker certification; or Flask or Django experience for dashboards or widgets.
Skills for this role
Security Operations Center (SOC)Security OrchestrationAutomationand Response (SOAR)TinesSplunk SOARSwimlanePalo XSOARGoogle SOARAI agentsAgentic workflowsPythonJavaScriptAPIsMicroservicesSQLNoSQLPostgreSQLGitGitHubSecurity Information and Event Management (SIEM)Intrusion Detection Systems (IDS)Intrusion Prevention Systems (IPS)Data Loss Prevention (DLP)Web Application Firewall (WAF)Endpoint Detection and Response (EDR)Threat intelligenceMITRE ATT&CKFlaskDjangoStakeholder communication