Consultant – Cyber Security SOC (Incident Triaging L1) | Deloitte India | Bengaluru

October 9, 2025

Job Description

Summary

Join Deloitte Touche Tohmatsu India LLP as a Consultant – Cyber Security SOC (Incident Triaging L1) in Bengaluru (Koramangala) and play a key role in safeguarding enterprise systems against cyber threats.
This role is ideal for cybersecurity professionals with 2–4 years of experience in Security Operations Center (SOC) monitoring, incident triaging, and SIEM tools like Splunk. You’ll monitor, analyze, and respond to security alerts 24/7, ensuring the safety and integrity of critical business environments.

If you’re passionate about cyber defense, incident response, and real-time threat monitoring, this is your opportunity to work with one of the world’s leading cybersecurity teams and grow your career in Cyber Defense & Response (D&R) at Deloitte.


Job Details at a Glance

Job TitleConsultant – Cyber Security SOC (Incident Triaging L1)
CompanyDeloitte Touche Tohmatsu India LLP
Job Requisition ID88791
LocationBengaluru (Koramangala – Ecospace)
Experience Required2–4 years
Position TypeFull-Time / Consultant
DepartmentCyber Risk – Detect & Respond (SOC)
Tools & TechnologiesSIEM, Splunk, SOC Monitoring, Incident Response
Certifications (Preferred)Security+, CEH, ECSA
Work ModeOn-site (Client Location)
Shift24×7 Rotational
Posted OnOctober 8, 2025

About the Role

As a SOC Consultant – Incident Triaging (L1), you’ll be the first line of defense in Deloitte’s Cyber Security Operations Center (SOC).
You’ll monitor, analyze, and triage security alerts to detect potential threats and escalate incidents for containment and response. This role requires a proactive mindset, deep technical awareness, and the ability to react swiftly in high-pressure environments.

You’ll also collaborate with SOC Level 2 Analysts, Incident Response Teams, and Cyber Threat Intelligence units to ensure continuous protection of client environments.


Key Responsibilities

  • Monitor and analyze security alerts generated by SIEM tools (e.g., Splunk) and other security solutions (on-premise and cloud).
  • Conduct 24×7 incident triaging and categorize alerts based on severity and potential impact.
  • Validate alerts to determine true positives and perform initial containment actions.
  • Investigate Indicators of Compromise (IOCs) to determine threat scope and impact.
  • Document all triage activities, findings, and evidence accurately in incident tracking tools.
  • Escalate verified incidents to SOC Level 2 Analysts with complete investigative context.
  • Follow established incident response playbooks, SOPs, and escalation procedures.
  • Execute defined use cases, scripts, and automation tasks to collect additional threat data.
  • Monitor SOC tool health, report anomalies, and ensure continuous system performance.
  • Participate in ongoing cybersecurity training and skill enhancement initiatives.

Required Skills & Experience

  • 2–4 years of experience in SOC operations, incident monitoring, or cybersecurity triaging.
  • Hands-on experience with SIEM tools (preferably Splunk).
  • Strong understanding of networking, security protocols, and attack vectors.
  • Ability to analyze, validate, and document security events and incidents.
  • Excellent problem-solving, analytical, and communication skills.
  • Proficiency in report writing and documentation for audit and compliance tracking.
  • Certifications such as Security+, CEH, or ECSA are preferred.

Preferred Skills

  • Familiarity with threat intelligence platforms and endpoint detection tools.
  • Understanding of incident response frameworks (NIST, SANS).
  • Knowledge of cloud security and SaaS-based monitoring tools.
  • Experience in Agile environments and use of tools like JIRA and Confluence.
  • Strong collaboration and client engagement skills in security operations settings.

Qualifications

  • Education: Bachelor’s degree in Computer Science, Information Security, or related field.
  • Certifications (Preferred): Security+, CEH, or ECSA.
  • Work Environment: On-site (Koramangala – Client Location).

Why Join Deloitte Cyber?

At Deloitte India, you’ll be part of a global network of cybersecurity professionals defending organizations against the world’s most advanced threats.
We combine cutting-edge technology, data-driven intelligence, and industry-leading expertise to help clients become more secure, vigilant, and resilient.

What Deloitte Offers

  • Exposure to global cybersecurity projects and enterprise SOC environments.
  • Continuous learning through internal certifications, labs, and hands-on simulations.
  • A collaborative work culture that promotes innovation and purpose-driven impact.
  • Career growth through structured mentorship and leadership development programs.
  • Access to the latest cyber defense tools and platforms in real-world use cases.

Location & Work Model

  • Base Location: Bengaluru (Koramangala – Ecospace)
  • Work Mode: On-site (Client Location)
  • Shift: 24×7 Rotational SOC Operations
  • Entity: Deloitte Touche Tohmatsu India LLP

Apply Now

Take the next step in your cybersecurity career and become a part of Deloitte’s Cyber Defense & Response Team.
Help protect critical information, detect threats faster, and build resilience across industries.

👉 Apply now through Deloitte’s official careers portal:
Apply Now – Deloitte Careers India