Security Engineer III, Exploitation Analyst / Incident Responder
Job Description
Work onsite in Rosslyn, VA as part of Deloitte Cyber Defense & Resilience, supporting cyber exploitation analysis and incident response.
Responsibilities
- Continuously monitor networks, systems, and applications for indicators of compromise and analyze threat data to identify malicious activity
- Investigate security incidents by collecting and analyzing logs, memory artifacts, and network traffic, and support containment, eradication, and recovery activities
- Identify and assess vulnerabilities across systems, networks, and applications; recommend remediation actions based on risk and exploitability
- Analyze malware, exploits, and adversary tools, including reverse engineering malicious code and simulating adversary techniques in controlled environments
- Produce technical reports, briefings, and documentation summarizing findings, methodologies, and recommendations for stakeholders
Requirements
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced, dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
- Active Top-Secret Clearance
- 2+ years of experience in cyber exploitation analysis, threat intelligence, or incident response
- Experience analyzing APTs, malware, exploitation techniques, and reverse engineering tools such as IDA Pro or Ghidra
- Experience performing vulnerability assessments, penetration testing, or red team activities
- Experience with network traffic analysis, log analysis, digital forensics, Windows, Linux, macOS, common network protocols
- Scripting experience with Python, PowerShell, or Bash
- Experience using security monitoring tools such as SIEM, IDS, IPS, or EDR
- Ability to travel up to 20% on average
- Must be willing to work client onsite or Deloitte office up to 5 days a week
- Industry certifications such as GIAC, CISSP, or CompTIA Security+ is required
- Must be legally authorized to work in the United States without employer sponsorship, now or in the future
Technologies
- IDA Pro
- Ghidra
- Python
- PowerShell
- Bash
- SIEM
- IDS
- IPS
- EDR
- Windows
- Linux
- macOS
- MITRE ATT&CK
The Team
- Deloitte Cyber Defense & Resilience helps clients defend against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence
- Supports protection and management of dynamic attack surfaces and provides rapid crisis and cyber incident response, enabling clients to be ready for, respond to, and recover from business disruptions
Preferred
- Experience supporting incident response in government, defense, intelligence, or large enterprise environments
- Experience analyzing packet captures, memory dumps, and host-based forensic artifacts
- Experience mapping threat activity to the MITRE ATT&CK framework
- Experience developing or tuning detections for SIEM or EDR platforms
- Industry certifications such as GIAC, CISSP, or CompTIA Security+
Location
- Rosslyn, VA (onsite)
Compensation
- USD 102,500 - 188,900 per year
You may also be eligible to participate in a discretionary annual incentive program; any award depends on individual and organizational performance and other factors.