EngineerJobs.io
← Back to all jobs

Job Description

Deloitte’s Cyber Defense & Resilience team helps clients defend against advanced threats by strengthening security operations, monitoring technology, data analytics, and threat intelligence. You’ll support efforts to manage and protect dynamic attack surfaces, and help enable rapid crisis and cyber incident response so clients can be ready for, respond to, and recover from business disruptions.

What you’ll do

As a Cyber Exploitation Analyst and Incident Responder, you will analyze threat activity and investigate incidents across enterprise environments. You’ll monitor networks, systems, and applications for indicators of compromise and use threat data to identify malicious activity and patterns.

  • Monitor networks, systems, and applications for indicators of compromise and analyze threat data to identify malicious activity.
  • Investigate security incidents by collecting and analyzing logs and artifacts, including memory and network traffic; support containment, eradication, and recovery activities.
  • Identify and assess vulnerabilities across systems, networks, and applications, then recommend remediation actions based on risk and exploitability.
  • Analyze malware, exploits, and adversary tools, including reverse engineering malicious code and simulating adversary techniques in controlled environments.
  • Produce technical reports, briefings, and documentation that summarize findings, methodologies, and recommendations for stakeholders.

Skills and qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
  • Active Top-Secret Clearance.
  • 2+ years of experience in cyber exploitation analysis, threat intelligence, or incident response.
  • Experience analyzing advanced persistent threats (APTs), malware, exploitation techniques, and reverse engineering tools such as IDA Pro or Ghidra.
  • Experience performing vulnerability assessments, penetration testing, or red team activities.
  • Hands-on experience with network traffic analysis, log analysis, and digital forensics, including Windows, Linux, and macOS, common network protocols, and scripting languages such as Python, PowerShell, or Bash.
  • Experience with security monitoring tools such as SIEM, IDS, IPS, and EDR.
  • Ability to travel up to 20% on average based on work, clients, and industries/sectors served.
  • Ability to work at client onsite or a Deloitte office for up to 5 days a week.
  • Must have industry certifications such as GIAC, CISSP, or CompTIA Security+ (required).
  • Must be legally authorized to work in the United States without employer sponsorship, now or in the future.

Preferred qualifications

  • Experience supporting incident response in government, defense, intelligence, or large enterprise environments.
  • Experience analyzing packet captures, memory dumps, and host-based forensic artifacts.
  • Experience mapping threat activity to the MITRE ATT&CK framework.
  • Experience developing or tuning detections for SIEM or EDR platforms.
  • Industry certifications such as GIAC, CISSP, or CompTIA Security+.

Technologies you may work with

  • IDA Pro, Ghidra, Python, PowerShell, Bash
  • SIEM, IDS, IPS, EDR
  • Windows, Linux, macOS
  • MITRE ATT&CK, Global Information Assurance Certification (GIAC), Certified Information Systems Security Professional (CISSP), CompTIA Security+

Location: Baltimore, MD (onsite)
Compensation: USD 102,500 - 188,900 per year

Similar Jobs