EngineerJobs.io
← Back to all jobs

Job Description

The Security Engineer III, Exploitation Analyst / Incident Responder role sits on Deloitte's Cyber Defense & Resilience team, focusing on monitoring for indicators of compromise, investigating incidents, assessing vulnerabilities, and analyzing malware to strengthen security across enterprise environments for clients with a TS clearance.

Responsibilities

  • Monitor networks, systems, and applications for indicators of compromise and analyze threat data to identify malicious activity.
  • Investigate security incidents, collect and analyze logs, memory artifacts, and network traffic, and support containment, eradication, and recovery efforts.
  • Identify and assess vulnerabilities in systems, networks, and applications and recommend remediation actions based on risk and exploitability.
  • Analyze malware, exploits, and adversary tools, including reverse engineering malicious code and simulating adversary techniques in controlled environments.
  • Prepare technical reports, briefings, and documentation that summarize findings, methodologies, and recommendations for stakeholders.

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
  • Active Top-Secret Clearance with SCI eligibility
  • 2+ years of experience in cyber exploitation analysis, threat intelligence, or incident response
  • 2+ years of experience analyzing advanced persistent threats, malware, exploitation techniques, and reverse engineering tools such as IDA Pro or Ghidra
  • 2+ years of experience performing vulnerability assessments, penetration testing, or red team activities
  • 2+ years of experience with network traffic analysis, log analysis, digital forensics, Windows, Linux, macOS, common network protocols, scripting languages (Python, PowerShell, or Bash), and security monitoring tools (SIEM, IDS, IPS, or EDR)
  • Ability to travel up to 20 percent, on average
  • Willingness to work onsite at a client location or Deloitte office up to five days per week
  • Industry certifications such as GIAC, CISSP, or CompTIA Security+ are required
  • Must be legally authorized to work in the United States without sponsorship now or in the future

Technologies

  • IDA Pro
  • Ghidra
  • Python
  • PowerShell
  • Bash
  • SIEM
  • IDS
  • IPS
  • EDR
  • Windows
  • Linux
  • macOS
  • MITRE ATT&CK

Benefits

  • Discretionary annual incentive program, subject to rules governing the program, based on individual and organizational performance.

The Team

The Deloitte Cyber Defense & Resilience practice helps clients defend against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. It supports managing dynamic attack surfaces and delivers rapid crisis management and cyber incident response to enable readiness, response, and recovery from disruptions.

The Wage Range

The wage range for this role accounts for a broad set of factors used in compensation decisions, including skill sets, experience and training, licensure and certifications, and other business needs. The disclosed range has not been adjusted for geographic differential related to the location of the position.

Preferred

  • Experience supporting incident response in government, defense, intelligence, or large enterprise environments
  • Experience analyzing packet captures, memory dumps, and host-based forensic artifacts
  • Experience mapping threat activity to the MITRE ATT&CK framework
  • Experience developing or tuning detections for SIEM or EDR platforms
  • Industry certifications such as GIAC, CISSP, or CompTIA Security+

Similar Jobs