CybersecurityJobs.io
← Back to all jobs

Job Description

Deloitte’s Cyber Defense & Resilience team helps protect enterprise environments by turning real threat activity into measurable improvements. As a Cyber Exploitation Analyst and Incident Responder, you will combine analysis, investigation, and security engineering to strengthen security posture across complex systems, while preparing clear technical reporting for stakeholders. The role is onsite in Rosslyn, VA, with an expected up to 5 days a week at a client site or Deloitte office.

This position offers a salary range of USD 102,500 - 188,900 per year. You will work within a team that monitors for malicious activity, investigates incidents, evaluates vulnerabilities, and supports remediation planning based on risk and exploitability.

Responsibilities

  • Monitor networks, systems, and applications for indicators of compromise and analyze threat data to identify malicious activity.
  • Investigate security incidents by collecting and analyzing logs, memory artifacts, and network traffic, supporting containment, eradication, and recovery activities.
  • Identify and assess vulnerabilities across systems, networks, and applications, recommending remediation actions informed by risk and exploitability.
  • Analyze malware, exploits, and adversary tools, including reverse engineering malicious code and simulating adversary techniques in controlled environments.
  • Prepare technical reports, briefings, and documentation that summarize findings, methodologies, and recommendations for stakeholders.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
  • Active Top-Secret Clearance.
  • 2+ years of experience in cyber exploitation analysis, threat intelligence, or incident response.
  • Experience analyzing APTs, malware, exploitation techniques, and reverse engineering tools such as IDA Pro or Ghidra.
  • Experience performing vulnerability assessments, penetration testing, or red team activities.
  • Experience with network traffic analysis, log analysis, digital forensics, and operating systems including Windows, Linux, and macOS, along with common network protocols.
  • Scripting and security tooling experience, including Python, PowerShell, or Bash, and security monitoring tools such as SIEM, IDS, IPS, or EDR.
  • Ability to travel up to 20%, on average.
  • Ability to work client onsite or at Deloitte office up to 5 days a week.
  • Industry certification such as GIAC, CISSP, or CompTIA Security+ is required.
  • Must be legally authorized to work in the United States without employer sponsorship, now or in the future.

Technology & Frameworks

  • IDA Pro, Ghidra, Python, PowerShell, Bash
  • SIEM, IDS, IPS, EDR
  • Windows, Linux, macOS
  • MITRE ATT&CK

What a Successful Candidate Demonstrates

  • Ability to work independently while collaborating as part of a team.
  • Effective written and verbal communication skills.
  • Meticulous attention to detail and quality-focused work output.
  • Ability to build and sustain professional relationships.
  • Ability to lead projects or workstreams and manage/prioritize multiple tasks in a fast-paced environment.
  • Strong interpersonal skills and professional demeanor, with the ability to meet deadlines.
  • Ability to provide clear guidance to others.

Preferred

  • Experience supporting incident response in government, defense, intelligence, or large enterprise environments.
  • Experience analyzing packet captures, memory dumps, and host-based forensic artifacts.
  • Experience mapping threat activity to the MITRE ATT&CK framework.
  • Experience developing or tuning detections for SIEM or EDR platforms.
  • Industry certifications such as GIAC, CISSP, or CompTIA Security+.

Similar Jobs