Cyber Operate SOC L3 Analyst / Shift Lead - Senior Consultant

Deloitte France

United States

Hybrid

USD 105,000 - 208,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Deloitte is seeking a Managed Services Engineer III for its Cyber Operate Offering to drive security operations for client environments. You will coordinate across SDMs, Cyber Managed Services Engineering, Threat Hunting, and SOC analysts to ensure timely investigations and effective runbooks.

The role requires 4+ years in cybersecurity, strong client-facing communication, and the ability to work rotating 24/7 shifts.

Qualifications

  • Bachelor's degree in CS/IT/CE or related field
  • 4+ years in cybersecurity or security operations
  • Ability to work rotating 24/7 shifts
  • Experience with SIEM, IDS/IPS, DLP, proxies, WAF, EDR, antivirus
  • Knowledge of APT tactics, MITRE, and cyber kill chain
  • Networking basics: TCP/IP, DNS, HTTP
  • Certifications such as CISSP/GIAC/CEH or equivalent
  • Programming experience in one or more languages
  • Willingness to travel and in-office time of 50% of work
  • Sponsorship availability may be limited

Responsibilities

  • Act as main interface between SDMs, Cyber Managed Services Eng, Threat Hunting, and SOC analysts
  • Escalation point for L2 security escalations
  • Perform in-depth threat analysis across host and network traffic
  • Review threat intel to update ongoing hunts and response
  • Analyze network and endpoint data using SIEM and tools

Skills

Team leadership
Client communication
Decision making
Prioritization
Coaching
Stakeholder relations
Quality assurance
Process improvement
Incident leadership

Education

Bachelor's degree in CS/IT/CE

Tools

SIEM
IDS/IPS
DLP
WAF
EDR
Threat Intelligence
Penetration Testing
Firewalls

Job description

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a Managed Services Engineer III on the Cyber Operate Offering team, you will be responsible for…

  • Act as main interface point between Service Delivery Managers (SDMs), Cyber Managed Services Engineering, Threat Hunting teams and SOC analysts
  • Act as escalation point for all advanced security escalations from L2 analysts
  • Perform in-depth analysis and triage of threat activity across host and network layers traffic and protocol analysis to identify infection vectors, scope of compromise, and impact.
  • Review threat intelligence and open-source information to maintain awareness of new patterns, activity, and tactics associated with advanced threat actors, and incorporate this into ongoing hunt activity.
  • Analyze network and endpoint data in both structured and unstructured methods using the SIEM and specialized tooling; remain tool-agnostic concepts and methods are key, the tool is only a means.
  • Interface with Threat Intelligence to raise questions, share escalations, and mine reporting for actionable threat behaviors.
  • Analyze malware (executables, scripts, documents) to determine indicators of compromise, and create signatures for future detection of similar samples
  • Provide guidance on process and procedures specific to client’s environment
  • Responsible for meeting SLA requirements
  • Ensure quality standards are being met by doing ticket audits and reviewing and completing shift turnover logs
  • Conduct continuous improvement and on the job training (OJT)
  • Coordinates with Service Delivery Managers to enforce specific client requests and provide monitoring updates
  • Coordinate with clients to process and complete continuous improvement activities
  • Monitor and provide feedback/guidance on incident tickets on trends, patterns and anomalies
  • Act as the Point of escalation for operations/security issues
  • Attend client meetings, as and when needed, to assist SDMs with dissemination of security and event information
  • Ensure SOC metrics are met
  • Review reports and deliverables before they leave the SOC
  • Manage security event investigations, partnering with other departments as needed
  • Maintain individual certifications and learning requirements

A successful candidate would possess these skills:

  • Proven ability to lead and coordinate a team of analysts across shifts
  • Strong client-facing communication skills, including delivering findings and updates to SDMs and clients
  • Ability to make sound, timely decisions during high-severity or ambiguous incidents
  • Ability to manage competing priorities across ticket queues, escalations, and personnel needs
  • Strong coaching and mentoring skills to develop L1 and L2 Analysts
  • Ability to build and sustain professional relationships across client and internal stakeholder groups
  • Meticulous attention to quality, demonstrated through ticket audits and QA reviews
  • Ability to lead process-improvement initiatives and own runbook/playbook governance
  • Ability to remain composed and provide clear direction during critical incidents
The team

Our Cyber Operate Offering operates clients’ critical cyber assets as a fully managed service or working in partnership with clients. Provides talent, leading technologies, and processes to operate client cyber capabilities, including the identity lifecycle, security operations, threat intelligence, application security business transformation, and continuous compliance

Qualifications

Required:

  • Bachelor's degree, preferably in Computer Science, Information Technology, Computer Engineering, or related IT discipline; or equivalent experience
  • 4+ years of experience in cybersecurity or security operations
  • Able to work shifts on a rotating basis for 24/7 support of clients
  • Experience in security technologies such as: Security information and event management (SIEM), IDS/IPS, Data Loss Prevention (DLP), Proxy, Web Application Firewall (WAF), Endpoint detection and response (EDR), Anti-Virus, Sandboxing, network- and host- based firewalls, Threat Intelligence, Penetration Testing, etc.
  • Extensive knowledge of Advanced Persistent Threats (APT) tactics, technics and procedures
  • Understanding of possible attack activities such as network probing/ scanning, DDOS, malicious code activity, etc.
  • A deep understanding of the Cyber Kill Chain and MITRE tactics and technically detailed knowledge of basic attack techniques such as buffer overflows, SQL injections, XSS, common vulnerabilities, and memory allocation basics
  • Possess technically detailed knowledge of important threat campaigns and perform hunt activities as directed by Hunt Lead, or Service Lead
  • Understanding of networking protocols such as TCP/IP, DNS, HTTP
  • Extensive knowledge in system security architecture and security solutions
  • Certified Information Systems Security Professional (CISSP), Certification in Certified Intrusion Analyst (GIAC), Continuous Monitoring (GMON), Certified Ethical Hacker (CEH) or equivalent
  • Programming experience in one or more languages
  • Ability to work 50% of their time from a Deloitte office
  • Ability to travel 10%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Experience in a client-facing delivery role
  • Experience in Detection Engineering or Vulnerability Management

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Operate SOC L2 Analyst - Senior Consultant
Cyber Operate SOC L2 Analyst - Senior Consultant

Deloitte France • San Jose (CA)

On-site
USD 105,000 - 208,000
Cyber Operate SOC L2 Analyst - Senior Consultant
Cyber Operate SOC L2 Analyst - Senior Consultant

Deloitte France • Columbus (OH)

Hybrid
USD 105,000 - 208,000
Cyber Operate SOC L2 Analyst - Senior Consultant
Cyber Operate SOC L2 Analyst - Senior Consultant

Deloitte France • Richmond (VA)

On-site
USD 105,000 - 208,000
Cyber Operate SOC L1 Analyst - Consultant
Cyber Operate SOC L1 Analyst - Consultant

Deloitte France • United States

Hybrid
USD 83,000 - 163,000
Cyber Operate SOC L1 Analyst - Consultant
Cyber Operate SOC L1 Analyst - Consultant

Deloitte France • Columbus (OH)

Hybrid
USD 83,000 - 163,000
Cyber Operate SOC L1 Analyst - Consultant
Cyber Operate SOC L1 Analyst - Consultant

Deloitte France • Raleigh (NC)

Hybrid
USD 83,000 - 163,000
Cyber Operate SOC L1 Analyst - Consultant
Cyber Operate SOC L1 Analyst - Consultant

Deloitte France • San Jose (CA)

Hybrid
USD 83,000 - 163,000
Cyber Operate Detection Engineer - Consultant
Cyber Operate Detection Engineer - Consultant

Deloitte France • United States

On-site
USD 83,000 - 163,000
Cyber Operate Senior Manager- Detect and Respond
Cyber Operate Senior Manager- Detect and Respond

Deloitte France • Bellevue (WA)

On-site
USD 163,000 - 322,000
Cyber Operate Senior Manager- Detect and Respond
Cyber Operate Senior Manager- Detect and Respond

Deloitte France • Hartford (CT)

On-site
USD 163,000 - 322,000