Security Engineer III, Exploitation Analyst / Incident Responder
Job Description
Deloitte is hiring a Security Engineer III focused on cyber exploitation analysis and incident response for work in Rosslyn, VA.
Responsibilities
- Monitor networks, systems, and applications for indicators of compromise and analyze threat data to identify malicious activity
- Investigate security incidents by collecting and analyzing logs, memory artifacts, and network traffic
- Support containment, eradication, and recovery activities during incident response
- Identify and assess vulnerabilities across systems, networks, and applications
- Recommend remediation actions based on risk and exploitability
- Analyze malware, exploits, and adversary tools, including reverse engineering malicious code
- Simulate adversary techniques in controlled environments
- Produce technical reports, briefings, and documentation covering findings, methods, and recommendations for stakeholders
Requirements
- Ability to work independently and collaborate with a team
- Strong written and verbal communication skills
- Meticulous attention to detail and commitment to quality output
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast paced, dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or related technical field
- Active Top-Secret Clearance
- 2+ years of experience in cyber exploitation analysis, threat intelligence, or incident response
- Experience analyzing APTs, malware, exploitation techniques, and reverse engineering tools such as IDA Pro or Ghidra
- Experience performing vulnerability assessments, penetration testing, or red team activities
- Experience with network traffic analysis, log analysis, digital forensics, and operating systems including Windows, Linux, and macOS
- Experience with common network protocols, scripting languages including Python, PowerShell, and Bash, and security monitoring tools including SIEM, IDS, IPS, and EDR
- Ability to travel up to 20% on average
- Willingness to work client onsite or at a Deloitte office up to 5 days a week
- Industry certifications such as GIAC, CISSP, or CompTIA Security+ is required
- Legally authorized to work in the United States without employer sponsorship, now or in the future
Technologies
- IDA Pro
- Ghidra
- Python
- PowerShell
- Bash
- SIEM
- IDS
- IPS
- EDR
- Windows
- Linux
- macOS
- MITRE ATT&CK
Team
- Deloitte Cyber Defense & Resilience helps clients defend against advanced threats through security operations transformation, monitoring technology, data analytics, and threat intelligence
- Supports management and protection of dynamic attack surfaces and provides rapid crisis and cyber incident response to help clients prepare for, respond to, and recover from business disruptions
Preferred
- Experience supporting incident response in government, defense, intelligence, or large enterprise environments
- Experience analyzing packet captures, memory dumps, and host-based forensic artifacts
- Experience mapping threat activity to the MITRE ATT&CK framework
- Experience developing or tuning detections for SIEM or EDR platforms
- Industry certifications such as GIAC, CISSP, or CompTIA Security+
Location and Compensation
- Location: Rosslyn, VA (onsite)
- Estimated wage range: $102,500 - $188,900 per year
Incentive Program
- May be eligible for a discretionary annual incentive program
- Award, if any, depends on individual and organizational performance