About this role
As a Senior Consultant on Deloitte’s Cyber Defense & Resilience Automation team, help clients move Security Operations Centers (SOCs) from playbook-driven automation toward AI-augmented, agentic operations. The role supports cyber defense and resilience through improved security operations and incident response.
Responsibilities
- Design and develop automation and orchestration solutions using SOAR platforms. Build AI-assisted SOC workflows for autonomous triage, enrichment and agent-driven playbook use cases.
- Integrate security technologies through APIs, connectors and orchestration platforms. Improve processes to reduce analyst effort and increase response efficiency.
- Manage implementation activities, stakeholder communications and issue resolution across client, vendor and Deloitte teams.
Required qualifications
- 6–10 years developing solutions using Python or JavaScript; experience in a SOC or SIEM operations environment.
- Experience building, testing and maintaining production SOAR playbooks and automations, and integrating systems through APIs in client-server, web or microservices environments.
- Knowledge of TCP/IP, DNS and HTTP; experience with GitHub or another version-control repository.
- Bachelor’s or master’s degree in Cybersecurity, Information Technology, Engineering or a related field.
Preferred qualifications
- Experience integrating AI services, agents or large language model workflows into SOAR or AI-SOC playbooks; 6–10 years in security information or technology engineering support.
- Experience with SIEM, endpoint detection and response, web application firewalls, data loss prevention or threat intelligence platforms; MITRE ATT&CK for threat analysis or mitigation mapping.
- CISSP, GIAC Certified Intrusion Analyst, GIAC Continuous Monitoring, GIAC Certified Incident Handler, Certified Ethical Hacker or equivalent certification; experience building dashboards or widgets with Flask or Django.
The position lists Bangalore, Hyderabad, Pune and Chennai as locations, with general shift timings.
Skills for this role
PythonJavaScriptSecurity Operations Center (SOC)Security Information and Event Management (SIEM)Security OrchestrationAutomationand Response (SOAR)SOAR playbooksAI agentsLarge language modelsAPI integrationMicroservicesTCP/IPDNSHTTPGitHubVersion controlEndpoint Detection and Response (EDR)Web Application Firewall (WAF)Data Loss Prevention (DLP)Threat intelligenceMITRE ATT&CKFlaskDjangoStakeholder communication