Assistant Manager – Cybersecurity | SOC & SIEM Operations | Deloitte | Gurgaon / Delhi

October 8, 2025

Job Description

Summary

Join Deloitte Touche Tohmatsu India LLP as an Assistant Manager – Cyber Defense (SOC & SIEM Operations) in Gurgaon / Delhi.
In this role, you’ll help build and manage world-class Security Operations Center (SOC) capabilities, leading incident detection, analysis, and threat response using advanced tools and frameworks.

As a cybersecurity professional at Deloitte, you’ll work with cutting-edge SIEM technologies, apply MITRE ATT&CK frameworks, and strengthen digital defenses for leading global clients.
This is your opportunity to advance your cybersecurity career, work alongside top cyber experts, and make an impact that matters.


Job Details at a Glance

Job TitleAssistant Manager – Cybersecurity (SOC, SIEM Operations)
DepartmentCyber Risk – Detection & Response
EntityDeloitte Touche Tohmatsu India LLP
Job Requisition ID88247
LocationGurgaon / Delhi
Experience Required2+ years in SOC or Cyber Threat Detection
Preferred Tools & SkillsSIEM, MITRE ATT&CK, Sigma Rules, SQL, Python, OSQuery
EducationB.E. / B.Tech (Computer Science / IT or related field)
Work ModeHybrid / 24×7 Operations Support
Posted OnOctober 7, 2025

About the Team

Deloitte’s Cyber Risk Services help organizations defend, detect, and respond to the most sophisticated cyber threats.
Our Detection & Response (D&R) team designs and operates next-generation SOCs that combine analytics, automation, and intelligence to proactively safeguard businesses.
We believe in being Secure, Vigilant, and Resilient — managing cyber risks in ways that fuel innovation and enable opportunity.


Key Responsibilities

Security Operations & Threat Monitoring

  • Manage and maintain SOC platforms for real-time monitoring and detection.
  • Validate and analyze security threats, anomalies, and incidents based on defined procedures.
  • Categorize events according to threat taxonomy and severity levels.
  • Perform advanced threat detection and correlation using MITRE ATT&CK TTPs.

Incident Response & Analysis

  • Investigate security alerts, perform root cause analysis, and escalate incidents as needed.
  • Generate and deliver technical reports and dashboards (tables, graphs, insights).
  • Lead Level 2 escalations and guide the L1 operations team for resolution.
  • Draft new procedures and runbooks for emerging incident types.

Reporting & Communication

  • Create and present incident reports, KPIs, and performance summaries for clients.
  • Support client communication and technical discussions during active incidents.
  • Maintain health-check practices to ensure continuous monitoring and uptime.

SOC Platform Management

  • Operate and maintain SIEM tools and related cybersecurity infrastructure.
  • Support continuous improvements, tuning, and automation within the SOC ecosystem.
  • Collaborate with cross-functional cyber teams to strengthen incident response capabilities.

Required Skills & Expertise

  • 2+ years of SOC experience with exposure to security monitoring and incident handling.
  • Proficient in SIEM tools (Splunk, QRadar, ArcSight, etc.).
  • Strong understanding of the MITRE ATT&CK framework for threat investigation.
  • Familiar with Sigma rules, IDS signatures, and incident management processes.
  • Hands-on with SQL queries, OSQuery, and Python scripting for data analysis.
  • Ability to triage, investigate, and resolve L2 incidents independently.
  • Excellent communication and client-handling skills in a 24×7 SOC setup.

Preferred Qualifications

  • B.E./B.Tech in Computer Science, IT, or related field (Tier 1/2 preferred).
  • Familiarity with open-source tools like Zeek/Zee and advanced analytics platforms.
  • Certifications such as CEH, CompTIA Security+, Splunk Certified Specialist, or GCIA are an advantage.

Your Role as an Assistant Manager

As an Assistant Manager – SOC Operations, you are expected to:

  • Lead a team of cybersecurity professionals focused on real-time detection and response.
  • Ensure incident accuracy, timely escalation, and service quality.
  • Apply strategic and analytical thinking to enhance threat visibility.
  • Mentor SOC analysts and contribute to process and tool improvements.

Why Join Deloitte?

At Deloitte, cybersecurity isn’t just about protection — it’s about enabling innovation securely.
You’ll gain access to:

  • Global cyber expertise and leading-edge tools.
  • A collaborative environment that encourages continuous learning.
  • Flexible hybrid work models and career mobility opportunities.
  • A culture that celebrates inclusivity, integrity, and leadership at every level.

Growth & Development

  • Work with global clients tackling complex cybersecurity challenges.
  • Expand your knowledge across threat intelligence, automation, and cloud security.
  • Access Deloitte’s learning ecosystem for certifications and leadership development.

Inclusion & Wellbeing

At Deloitte, every individual is valued, respected, and empowered.
We create an environment that promotes balance, growth, and inclusivity, supporting your career and personal wellbeing through flexible policies and meaningful work.


Interview Tips

To prepare for your interview:

  • Review Deloitte’s Cyber & Risk Services and understand the Detection & Response framework.
  • Refresh key concepts on SOC operations, incident lifecycle, and MITRE ATT&CK.
  • Explore Deloitte’s official career page for success stories and preparation resources.

Apply Now

Ready to strengthen the world’s cybersecurity posture with Deloitte?
👉 Apply Now on the Official Deloitte Careers Page
Be part of a global cyber team that detects, responds, and defends against tomorrow’s threats — today.