Cyber Operate Detection Engineer - Consultant

Deloitte France

Hartford (CT)

On-site

USD 83,000 - 163,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Deloitte is hiring a Managed Services Engineer II to help develop, test, tune, and maintain cybersecurity detections for client security operations.

Responsibilities include reviewing threat intel, updating detection rules, tuning to reduce false positives, and testing detection logic with various tools and platforms. Collaboration with SOC analysts and client teams is essential.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, or Computer Engineering.
  • 2+ years of experience in cybersecurity, security operations, threat intelligence, networking, or systems administration.
  • Experience reviewing or analyzing authentication events, network traffic, OS activity, vulnerability data, security logs, or alerts.
  • Experience using at least one scripting or query language: Python, PowerShell, SQL, KQL, or SPL.
  • Experience documenting technical findings, test results, configuration changes, or detection logic.
  • Limited immigration sponsorship may be available.

Responsibilities

  • Review threat intelligence, emerging threats, attack techniques, vulnerabilities, and historical incident information to identify detection requirements.
  • Develop, maintain, and update detection rules, queries, signatures, and indicators of compromise for security monitoring platforms.
  • Configure and tune detections; identify false positives; and recommend improvements that maintain effective threat coverage.
  • Test and validate detection rules against known threats and attack scenarios; document test results, configuration changes, and detection logic.
  • Monitor detection performance; investigate gaps or unexpected results; support incident-response research; and collaborate with SOC analysts and client teams.

Skills

Team collaboration
Communication skills
Attention to detail
Project leadership
Prioritization
Deadline oriented
Professional demeanor

Education

Bachelor's degree in Computer Science, Information Technology, or Computer Engineering
CompTIA Security+', 'CySA+', or GIAC Foundational...

Tools

Microsoft Defender
Splunk
Microsoft Sentinel
Git
Cloud platforms (AWS/Azure/Google Cloud)

Job description

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a Managed Services Engineer II on the Cyber Operate Offering team, you will be responsible for helping develop, test, tune, and maintain cybersecurity detections that support client security operations.

  • Review threat intelligence, emerging threats, attack techniques, vulnerabilities, and historical incident information to identify detection requirements.

  • Develop, maintain, and update detection rules, queries, signatures, and indicators of compromise for security monitoring platforms.

  • Configure and tune detections; identify false positives; and recommend improvements that maintain effective threat coverage.

  • Test and validate detection rules against known threats and attack scenarios; document test results, configuration changes, and detection logic.

  • Monitor detection performance; investigate gaps or unexpected results; support incident-response research; and collaborate with security operations center analysts, threat hunters, incident responders, Platform Operations Engineers, and client cybersecurity teams.

A successful candidate would possess these skills:
  • Ability to work independently and collaborate as part of a team

  • Effective written and verbal communication skills

  • Meticulous attention to detail and quality of work product

  • Ability to build and sustain professional relationships

  • Ability to lead projects or workstreams

  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment

  • Strong interpersonal skills and professional demeanor

  • Ability to meet deadlines

  • Ability to provide clear guidance to others

The team

Our Cyber Operate Offering operates clients' critical cyber assets as a fully managed service or working in partnership with clients. Provides talent, leading technologies, and processes to operate client cyber capabilities, including the identity lifecycle, security operations, threat intelligence, application security business transformation, and continuous compliance.

Qualifications
Required:
  • Bachelor's degree in Computer Science, Information Technology, or Computer Engineering.

  • 2+ years of experience in cybersecurity, security operations, threat intelligence, networking, or systems administration.

  • Experience reviewing or analyzing authentication events, network traffic, operating system activity, vulnerability data, security logs, or alerts.

  • Experience using at least one scripting or query language: Python, PowerShell, Structured Query Language (SQL), Kusto Query Language (KQL), or Splunk Processing Language (SPL).

  • Experience documenting technical findings, test results, configuration changes, or detection logic.

  • Limited immigration sponsorship may be available.

Preferred:
  • Hands-on experience in a security operations center, with security information and event management or endpoint detection and response platforms, or in threat hunting, incident response, or detection engineering.

  • Experience using Microsoft Sentinel, Splunk, Google Security Operations, Elastic, CrowdStrike, or Microsoft Defender.

  • Experience creating or modifying Sigma rules, YARA rules, Suricata signatures, Kusto Query Language queries, or Splunk Processing Language queries.

  • Experience using Amazon Web Services, Microsoft Azure, or Google Cloud.

  • Experience using Git, version control systems, detection-as-code practices, or continuous integration/continuous delivery processes.

  • CompTIA Security+, CompTIA Cybersecurity Analyst (CySA+), or Global Information Assurance Certification (GIAC) Foundational Cybersecurity Technologies certification.

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $82,600 to $162,800.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Operate Detection Engineer - Consultant
Cyber Operate Detection Engineer - Consultant

Deloitte France • Stamford (CT)

On-site
USD 83,000 - 163,000
Cyber Operate Detection Engineer - Consultant
Cyber Operate Detection Engineer - Consultant

Deloitte France • Columbus (OH)

On-site
USD 83,000 - 163,000
Cyber Operate Detection Engineer - Consultant
Cyber Operate Detection Engineer - Consultant

Deloitte France • United States

On-site
USD 83,000 - 163,000
Cyber Operate SOC L2 Analyst - Senior Consultant
Cyber Operate SOC L2 Analyst - Senior Consultant

Deloitte France • San Jose (CA)

On-site
USD 105,000 - 208,000
Cyber Operate SOC L2 Analyst - Senior Consultant
Cyber Operate SOC L2 Analyst - Senior Consultant

Deloitte France • Richmond (VA)

On-site
USD 105,000 - 208,000
Cyber Operate SOC L2 Analyst - Senior Consultant
Cyber Operate SOC L2 Analyst - Senior Consultant

Deloitte France • Columbus (OH)

Hybrid
USD 105,000 - 208,000
Cyber Operate SOC L1 Analyst - Consultant
Cyber Operate SOC L1 Analyst - Consultant

Deloitte France • San Jose (CA)

Hybrid
USD 83,000 - 163,000
Cyber Operate Senior Manager- Detect and Respond
Cyber Operate Senior Manager- Detect and Respond

Deloitte France • Chicago (IL)

On-site
USD 163,000 - 322,000
Cyber Operate Senior Manager- Detect and Respond
Cyber Operate Senior Manager- Detect and Respond

Deloitte France • Columbus (OH)

On-site
USD 163,000 - 322,000
Discretionary annual incentive
Cyber Operate Senior Manager- Detect and Respond
Cyber Operate Senior Manager- Detect and Respond

Deloitte France • Las Vegas (NV)

On-site
USD 163,000 - 322,000