Security Engineer III, Exploitation Analyst / Incident Responder
Job Description
On Deloitte’s Cyber Defense & Resilience team, the Security Engineer III will serve as a cyber exploitation analyst and incident responder, supporting enterprise security activities from threat analysis through incident investigation and reporting. This role focuses on understanding attacker behavior, assessing vulnerabilities, and translating technical findings into practical recommendations.
Key Responsibilities
- Monitor networks, systems, and applications for indicators of compromise and analyze threat data to identify malicious activity.
- Investigate security incidents by collecting and analyzing logs, memory artifacts, and network traffic, and support containment, eradication, and recovery efforts.
- Identify and evaluate vulnerabilities across systems, networks, and applications, then recommend remediation actions based on risk and exploitability.
- Analyze malware, exploits, and adversary tools, including reverse engineering malicious code and simulating adversary techniques in controlled environments.
- Produce technical reports, briefings, and documentation that summarize findings, methodologies, and recommendations for stakeholders.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
- Active Top-Secret Clearance.
- 2+ years of experience in cyber exploitation analysis, threat intelligence, or incident response.
- Experience analyzing advanced persistent threats (APTs), malware, exploitation techniques, and reverse engineering tools such as IDA Pro or Ghidra.
- Experience performing vulnerability assessments, penetration testing, or red team activities.
- Experience with network traffic analysis, log analysis, digital forensics, and operating systems including Windows, Linux, and macOS, as well as common network protocols.
- Experience scripting with Python, PowerShell, or Bash.
- Experience using security monitoring tools including SIEM, IDS, IPS, and EDR.
- Ability to travel up to 20% on average based on work, clients, and sectors served.
- Ability to work client onsite or at Deloitte office for up to 5 days a week.
- Industry certifications such as GIAC, CISSP, or CompTIA Security+ are required.
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or in the future.
Technologies and Frameworks
- IDA Pro, Ghidra
- Python, PowerShell, Bash
- SIEM, IDS, IPS, EDR
- Windows, Linux, macOS
- MITRE ATT&CK
Additional Skills
- Ability to work independently and collaborate as part of a team.
- Effective written and verbal communication skills.
- Meticulous attention to detail and ability to deliver high-quality work products.
- Ability to build and sustain professional relationships.
- Ability to lead projects or workstreams.
- Ability to manage and prioritize multiple tasks in a fast-paced environment.
- Strong interpersonal skills and professional demeanor.
- Ability to meet deadlines.
- Ability to provide clear guidance to others.
Preferred Experience
- Experience supporting incident response in government, defense, intelligence, or large enterprise environments.
- Experience analyzing packet captures, memory dumps, and host-based forensic artifacts.
- Experience mapping threat activity to the MITRE ATT&CK framework.
- Experience developing or tuning detections for SIEM or EDR platforms.
- Industry certifications such as GIAC, CISSP, or CompTIA Security+.
Location and Compensation
Location: Rosslyn, VA 22209 (onsite).
Compensation: USD 102,500 - 188,900 per year.
Minimum Experience
2+ years of relevant experience.