Security Engineer III, Exploitation Analyst / Incident Responder
Job Description
Deloitte’s Cyber Defense & Resilience team helps clients defend against advanced threats by modernizing security operations, monitoring technology, data analytics, and threat intelligence. The work supports protecting dynamic attack surfaces and delivering rapid crisis and cyber incident response so organizations can be ready for, respond to, and recover from business disruptions.
Onsite in Baltimore, MD, you will join a team that emphasizes practical analysis and actionable recommendations across enterprise environments. This role combines cyber exploitation analysis with incident response, giving you a direct path to drive improvements in security posture while supporting complex investigations.
Responsibilities
- Monitor networks, systems, and applications for indicators of compromise, and analyze threat data to identify malicious activity.
- Investigate security incidents by collecting and analyzing logs and artifacts, including memory artifacts and network traffic, and support containment, eradication, and recovery activities.
- Identify and assess vulnerabilities across systems, networks, and applications, then recommend remediation actions based on risk and exploitability.
- Analyze malware, exploits, and adversary tools, including reverse engineering malicious code and simulating adversary techniques in controlled environments.
- Prepare technical reports, briefings, and documentation that summarize findings, methodologies, and recommendations for stakeholders.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
- Active Top-Secret Clearance.
- 2+ years of experience in cyber exploitation analysis, threat intelligence, or incident response.
- Experience with advanced persistent threats (APTs), malware, exploitation techniques, and reverse engineering tools such as IDA Pro or Ghidra.
- Experience performing vulnerability assessments, penetration testing, or red team activities.
- Experience with network traffic analysis, log analysis, digital forensics, and operating systems including Windows, Linux, and macOS.
- Experience with common network protocols; scripting languages such as Python, PowerShell, or Bash; and security monitoring tools including SIEM, IDS, IPS, or EDR.
- Ability to travel up to 20% on average based on work, clients, and industries/sectors served.
- Willingness to work at client onsite or Deloitte office for up to 5 days a week.
- Industry certifications such as GIAC, CISSP, or CompTIA Security+ are required.
- Must be legally authorized to work in the United States without employer sponsorship, now or in the future.
Tools & Technologies
- IDA Pro, Ghidra, MITRE ATT&CK (and the MITRE ATT&CK framework)
- Python, PowerShell, Bash
- SIEM, IDS, IPS, EDR
- Windows, Linux, macOS
Additional Team Context
Deloitte’s Cyber Defense & Resilience offering is built to help clients manage and protect dynamic attack surfaces, strengthen monitoring and threat intelligence, and provide rapid crisis and cyber incident response to support continuity during disruptive events.
Preferred
- Experience supporting incident response in government, defense, intelligence, or large enterprise environments.
- Experience analyzing packet captures, memory dumps, and host-based forensic artifacts.
- Experience mapping threat activity to the MITRE ATT&CK framework.
- Experience developing or tuning detections for SIEM or EDR platforms.
- Industry certifications such as GIAC, CISSP, or CompTIA Security+.