Consultant – SOAR/XSOAR Job in Mumbai & Bengaluru | Cybersecurity Automation Role at Deloitte – May 2025
Consultant – SOAR/XSOAR Job Opportunity in Mumbai & Bengaluru | Cyber Defense & Resilience Careers – May 2025
Are you passionate about cybersecurity automation and looking for a dynamic role that blends technology, innovation, and incident response? An exciting opportunity is now open for a Consultant – SOAR/XSOAR within the Cyber Defense & Resilience (D&R) practice in Mumbai and Bengaluru. This role is ideal for professionals who want to work at the forefront of security orchestration, automation, and response (SOAR), enabling organizations to react faster, smarter, and more efficiently to ever-evolving cyber threats.
If you thrive in high-paced environments and possess strong technical knowledge of platforms like Palo Alto Networks Cortex XSOAR, this is your chance to join a world-class team committed to protecting digital ecosystems across the globe.
Position Overview
-
Job Title: Consultant – SOAR/XSOAR
-
Requisition ID: 81069
-
Location: Bengaluru (Eco Space) & Mumbai
-
Domain: Cyber Defense & Resilience
-
Employment Type: Full-time
-
Date Posted: May 14, 2025
This consultant-level position is part of the Cybersecurity team focusing on delivering advanced SOAR capabilities, especially using tools like Cortex XSOAR, to streamline incident response, reduce analyst workload, and enhance threat detection and resolution strategies.
About Cyber Defense & Resilience (D&R)
The Cyber D&R division helps clients build robust and resilient digital defenses. The team specializes in Security Operations Center (SOC) design, incident management, threat hunting, and cyber automation. By leveraging advanced platforms such as SOAR, EDR, SIEM, and threat intelligence systems, Cyber D&R ensures organizations can defend, detect, respond, and recover from cyber incidents rapidly and effectively.
Role Responsibilities
As a SOAR/XSOAR Consultant, you will work closely with cybersecurity architects, SOC analysts, and client stakeholders to deploy, customize, and optimize SOAR solutions that improve cyber incident response and automate repetitive tasks.
1. SOAR/XSOAR Development & Integration
-
Design and implement playbooks in Palo Alto Cortex XSOAR to orchestrate and automate security operations workflows.
-
Integrate XSOAR with third-party tools like SIEMs (e.g., Splunk, QRadar), EDRs (e.g., CrowdStrike, SentinelOne), firewalls, email gateways, and ticketing systems.
-
Develop custom integrations using Python, REST APIs, and scripting to enhance SOAR capabilities.
2. Incident Response Enablement
-
Collaborate with SOC teams to identify automation opportunities across use cases such as phishing triage, malware analysis, insider threat detection, and incident closure.
-
Develop use-case-specific logic to drive enrichment, correlation, and auto-remediation tasks within playbooks.
3. Use Case Development & Deployment
-
Translate business and operational requirements into technical use cases for SOAR platforms.
-
Customize dashboards, reports, and alerts to provide actionable insights for security analysts and leadership teams.
-
Implement enrichment workflows that pull threat intelligence from platforms like VirusTotal, Recorded Future, and MISP.
4. Stakeholder Engagement
-
Act as a technical liaison between clients, vendors, and internal teams to drive successful project delivery.
-
Provide training and documentation for SOC teams on new XSOAR workflows and features.
5. Performance Optimization & Troubleshooting
-
Continuously monitor and tune XSOAR performance, scalability, and reliability.
-
Troubleshoot and resolve issues related to integration failures, API limits, or playbook logic errors.
Required Skills & Experience
To succeed in this role, the candidate must bring a strong mix of cybersecurity, automation, and scripting expertise:
✅ Core Technical Skills
-
Hands-on experience with Palo Alto Cortex XSOAR (formerly Demisto) or other SOAR platforms (e.g., Splunk SOAR, IBM Resilient).
-
Experience in developing and modifying SOAR playbooks, scripts, and integrations.
-
Proficiency in Python scripting, JSON, and RESTful APIs for automation tasks.
✅ Cybersecurity & SOC Knowledge
-
Understanding of SOC operations, MITRE ATT&CK framework, threat intelligence workflows, and incident lifecycle management.
-
Familiarity with cybersecurity tools like SIEM (Splunk, QRadar), EDR (CrowdStrike, Microsoft Defender), and firewalls (Palo Alto, Fortinet).
✅ Analytical & Problem-Solving
-
Strong debugging skills and the ability to dissect complex automation logic.
-
Capacity to identify root causes, optimize playbook efficiency, and enhance response speed.
✅ Soft Skills & Collaboration
-
Excellent verbal and written communication to document processes, deliver presentations, and train teams.
-
Collaborative mindset to work across security, infrastructure, and DevOps teams in a hybrid environment.
Preferred Qualifications
-
Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related field.
-
Certifications such as:
-
Palo Alto Networks Certified Security Automation Engineer (PCSAE)
-
Certified SOC Analyst (CSA)
-
GIAC Security Automation (GSA)
-
CompTIA CySA+
-
-
Experience with DevSecOps and CI/CD pipelines for security tool integration is a plus.
-
Prior experience in a consulting or client-facing role is advantageous.
Tools & Technologies
Candidates should demonstrate proficiency with a range of technologies relevant to SOAR deployments:
-
SOAR Platforms: Cortex XSOAR, Splunk SOAR, IBM Resilient
-
SIEM Tools: Splunk, QRadar, ArcSight
-
EDR Solutions: CrowdStrike, Microsoft Defender ATP, SentinelOne
-
Threat Intelligence: VirusTotal, MISP, Anomali, Recorded Future
-
Ticketing & Collaboration: ServiceNow, Jira, Slack, MS Teams
-
Automation Languages: Python, Bash, PowerShell
Why Join This Role?
Joining Deloitte’s Cyber Defense & Resilience team as a SOAR Consultant means becoming part of a high-impact, future-forward team focused on intelligent security automation. Here’s why this role is a career-defining move:
-
Work on high-profile cybersecurity transformation projects for global clients.
-
Lead automation strategy in modern SOC environments.
-
Gain exposure to cutting-edge tools and methodologies in incident response and cyber orchestration.
-
Collaborate with a diverse and talented team of engineers, analysts, and leaders across geographies.
-
Benefit from continuous learning, industry certifications, and structured career development.
Growth Opportunities
This role opens doors to various career paths in cybersecurity and automation, such as:
-
Lead Consultant – SOAR & Automation
-
Security Automation Architect
-
SOC Manager – Threat Detection & Response
-
Cybersecurity Solutions Architect
-
Principal Consultant – Cyber Engineering
Deloitte’s Work Culture
At Deloitte, inclusivity, collaboration, and innovation are more than buzzwords—they are deeply embedded in our culture. As a Consultant, you’ll be encouraged to:
-
Innovate fearlessly with support from leadership
-
Collaborate across global teams to solve complex security challenges
-
Own your growth through mentorship, certifications, and learning platforms
-
Bring your whole self to work, embracing authenticity and diversity
Location & Work Mode
-
Base Locations: Mumbai and Bengaluru Eco Space
-
Work Mode: Hybrid – combination of remote and in-office work, based on project needs
-
Travel: Minimal and project-based
How to Apply
Interested candidates can apply using Requisition ID: 81069 on the official Deloitte careers portal. Make sure to include updated details of your automation projects, certifications, and SOAR-specific experience.
Final Thoughts
As cyber threats become more sophisticated, the need for automated, proactive defense mechanisms is paramount. This Consultant – SOAR/XSOAR position offers a front-row seat to the evolution of cybersecurity operations—combining speed, scale, and intelligence.
If you’re a cybersecurity professional passionate about automation, orchestration, and innovation, this is your opportunity to create impact, solve global cyber challenges, and advance your career with Deloitte’s world-class Cyber Defense & Resilience team