About this role
A career in IBM Consulting is built on long-term client relationships and close collaboration worldwide. You’ll work with leading companies across industries, helping them shape their hybrid cloud and AI journeys. With support from our strategic partners, robust IBM technology, and Red Hat, you’ll have the tools to drive meaningful change and accelerate client impact. At IBM Consulting, curiosity fuels success. You’ll be encouraged to challenge the norm, explore new ideas, and create innovative solutions that deliver real results. Our culture of growth and empathy focuses on your long-term career development while valuing your unique skills and experiences. We are looking for an experienced Sr. Security Consultant – Cyber SOC to provide advanced cybersecurity consulting, threat detection, investigation and security assessment capabilities within a Cyber Security Operations environment. The role will work closely with SOC, Cyber Security, Infrastructure, Application, Risk, Compliance and business stakeholders to identify emerging threats, investigate complex cyber incidents, assess security controls and provide actionable recommendations to strengthen the organisation's security posture. The ideal candidate should combine hands-on cyber incident investigation and threat hunting expertise with strong consulting, analytical, presentation and stakeholder-management capabilities. Key Responsibilities 1. Threat Hunting & Detection Perform proactive and hypothesis-driven Threat Hunting across endpoint, network, identity, cloud and security telemetry. Analyse SIEM, EDR/XDR, network, authentication, DNS, proxy, firewall and other security logs to identify suspicious activity and advanced threats. Develop and refine threat-hunting use cases based on MITRE ATT&CK, emerging TTPs and organisational threat intelligence. Identify gaps in existing detection capabilities and recommend improvements to monitoring and detection rules. Support development and tuning of detection use cases, correlation rules and security analytics. 2. Cyber Incident Investigation & Response Lead or support investigation of complex and high-severity cyber security incidents. Perform detailed analysis of suspicious activities, compromised accounts, endpoints, network connections and attack paths. Establish incident timelines, identify indicators of compromise (IoCs), attack techniques and potential root causes. Conduct evidence gathering, preservation and analysis to support incident investigations. Support containment, eradication and recovery activities in coordination with SOC and technology teams. Prepare comprehensive incident investigation reports, including findings, impact, root cause and recommended remediation actions. 3. Threat Modelling & Security Assessment Conduct Threat Modelling for applications, infrastructure, networks, cloud environments and critical business services. Identify attack paths, trust boundaries, security weaknesses and potential threat scenarios. Perform cybersecurity assessments and control reviews across technology environments. Assess existing security controls against organisational requirements, security frameworks and industry good practices. Identify control gaps and provide pragmatic, risk-based recommendations. Support security posture assessments and consultative cybersecurity improvement initiatives. 4. Cybersecurity Consulting Act as a security consultant and trusted advisor to technology and business stakeholders. Translate technical security findings into business-impact-oriented risks and actionable recommendations. Provide consulting support for security architecture, SOC monitoring, detection and response capabilities. Identify opportunities to improve security processes, controls, automation and operational effectiveness. Participate in cybersecurity transformation and continuous-improvement initiatives. 5. Stakeholder & Client Management Engage with senior technology, cybersecurity, risk and business stakeholders. Present investigation findings, security assessments, threat scenarios and remediation recommendations to clients and leadership. Conduct workshops, assessment discussions, technical walkthroughs and security review meetings. Coordinate with multiple technology teams to drive remediation of identified security gaps. Demonstrate strong communication skills and the ability to explain complex cybersecurity topics to both technical and non-technical audiences. 6. Reporting & Governance Prepare executive-level and technical cybersecurity reports. Track security findings, remediation actions, risks and observations through closure. Define and report relevant cybersecurity metrics, trends and key observations. Contribute to SOC governance, security reviews, service reporting and continuous improvement. Maintain appropriate investigation and assessment documentation. Threat Hunting Cyber Incident Investigation & Response Threat Modelling Security Assessment SIEM / SOC Operations MITRE ATT&CK IoC / IoA, Security Log Analysis, Root Cause Analysis Evidence Gathering & Analysis Cybersecurity Risk Assessment Security Control Assessment Cybersecurity Consulting 8+ years of overall experience in Cyber Security, with significant experience in SOC, incident response, threat hunting or cybersecurity consulting. Strong analytical and investigative mindset. Ability to independently handle complex security investigations. Strong understanding of enterprise cybersecurity architecture and security controls. Excellent client-facing communication and presentation skills. Strong stakeholder management and collaboration skills. Ability to work effectively across SOC, infrastructure, application, cloud, network, IAM and risk teams. Ability to convert technical observations into business risks and actionable remediation plans. Comfortable working in high-priority incident and crisis situation Preferred Expertise – Digital Forensics Practical experience in Digital Forensics / Cyber Forensics will be preferred. Experience with forensic investigation of compromised endpoints, user accounts, servers and network activity. Knowledge of evidence preservation, forensic artefacts, timeline analysis and incident reconstruction. Exposure to forensic tools and techniques for endpoint, memory, disk and network analysis will be an advantage. Desired Certifications One or more of the following certifications would be advantageous: CISSP GIAC / SANS certifications CEH OSCP Security+ or equivalent cybersecurity certification Relevant cloud security certifications India Consulting Professional Mumbai, IN (0063) IBM India Private Limited