Consultant - AI Soc

This role focuses on implementing and configuring security operations solutions, including AI-enabled workflows, within client environments. Responsibilities include developing log ingestion, normalization, and enrichment pipelines, building automation playbooks and integrations, and applying AI/ML/LLM workflows to security use cases. The primary focus is on enhancing security monitoring, detection, response, and automation capabilities.

What you'd actually do

  1. Supporting the implementation and configuration of security information and event management, security orchestration automation and response, telemetry, and case management solutions across client environments
  2. Developing and maintaining log ingestion, normalization, enrichment, and routing workflows using application programming interfaces, connectors, and data pipelines
  3. Assisting with the development, testing, and tuning of detection content aligned to adversary behaviors and enterprise security requirements
  4. Building automation playbooks, integrations, and workflow enhancements that improve analyst efficiency and response execution
  5. Working directly with client stakeholders and Deloitte team members to document requirements, validate solutions, and support deployment activities

Skills

Required

  • 3+ years of experience in security operations, detection engineering, security engineering, or enterprise cyber defense
  • Experience supporting security information and event management, security orchestration automation and response, detection, telemetry, or incident response workflows in enterprise or cloud environments
  • Experience developing automations, integrations, or engineering workflows using Python or a similar scripting language
  • Experience with log parsing, normalization, data transformation, application programming interface integrations, or workflow orchestration
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field, or equivalent work experience

Nice to have

  • Experience with one or more security platforms across security information and event management, security orchestration automation and response, extended detection and response, endpoint detection and response, threat intelligence, or case management tools
  • Experience with Amazon Web Services, Microsoft Azure, or Google Cloud security telemetry and cloud-native security services
  • Experience with threat hunting, cyber threat intelligence, or purple team collaboration
  • Experience with data pipeline or observability technologies used for ingestion, routing, or transformation
  • Experience applying artificial intelligence, machine learning, or large language model workflows to security operations use cases
  • Relevant industry certifications such as Security+, Global Information Assurance Certification Security Essentials, Global Information Assurance Certification Certified Intrusion Analyst, Global Information Assurance Certification Certified Incident Handler, Splunk, or cloud security certifications

What the JD emphasized

  • AI-enabled workflows
  • automation playbooks
  • integrations
  • workflow enhancements
  • security operations
  • detection engineering
  • security engineering
  • enterprise cyber defense
  • security information and event management
  • security orchestration automation and response
  • detection
  • telemetry
  • incident response workflows
  • log parsing
  • normalization
  • data transformation
  • application programming interface integrations
  • workflow orchestration
  • applying artificial intelligence
  • machine learning
  • large language model workflows
  • security operations use cases

Other signals

  • AI-enabled workflows
  • automation playbooks
  • integrations
  • workflow enhancements