Job Title:  T&T | Cyber: D&R | Manager | Vulnerability Assessment & Penetration Testing (VAPT) | Bengaluru

T&T | Cyber: D&R | Manager | Vulnerability Assessment & Penetration Testing (VAPT) | Bengaluru
• Job requisition ID : 114203 
• Location: Bengaluru
• Entity: Deloitte Touche Tohmatsu India LLP 

 

The team  

 

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity  

 

Your work profile

  • Evaluates, counsels, mentors and provides feedback on performance of others
  • Assist in retention of people and lead training efforts
  • Manages day-to-day client relationships at appropriate senior management levels
  • Contributes to sales process by participating and/or leading proposal development efforts to sell "add-on" work to client and participate in the client presentation/orals
  • Identifies additional opportunities for the existing clients and opportunities for cross selling across service lines
  • Play substantive/lead role in engagement planning, economics, and billing
  • Demonstrates a general knowledge of market trends, competitor activities, firm products and service lines
  • Experience in leading multiple client engagements in multiple Cyber Security Management domains
  • Experience in leading and executing multiple Cyber Security Strategy engagements and building Cyber Threat and Vulnerability management programs for organizations
  • Cyber Threat, Vulnerability and Risk Assessment - Ability to identify business implications and identifying tactical and strategic recommendations to mitigate the risk. 
  • Experience in managing multiple Cyber Threat Management projects including technical and strategy projects.
  • Substantial experience in architecting technology solutions in the Cyber Security Management space
  • Ability to define the business & technical scope of a project. Should be able to independently lead delivery teams to deliver projects according to client specifications after such scope is defined
  • Experience in managing multiple projects covering the full life cycle of project management starting from proposal, orals presentation, project planning and management, deliverables review, final client presentation and project closure.
  • Extensive experience in leveraging industry standards and frameworks such as OWASP, CIS, NIST, ISO/IEC 17799, ISO/IEC 27001, etc. 
  • Experience in operationalizing the solutions implemented (e.g. ArcSight Implementation experience and operationalizing Security Monitoring and Security Operations post Implementation)
  • People and practice management skills
  • Experience with Vulnerability Management and Penetration testing tools: Burp suite, Kali Linux, Acunetix, AppScan, Nexpose, Qualys Guard, Nessus, Nmap, Metasploit, Fortify etc.
  • Experience in basic scripting such as: Shell, Python, PERL, etc.
  • Basic knowledge of Technoilogies such as: IPSEC, SSL, SSH, VPN, Ethernet Token Ring, WAP, SMTP, FTP, Frame Relay, WAN, ATM, FDDI, DSL, ISDN, HP Openview, Sun NetManage, Cisco Works, Radius, Big Brother, F5.

 

Key Responsibilities:

  • Total 9-15 years of experience in Cyber security domain
  • Manages Cyber Security Assessment projects, guides the team on a day-to-day basis and ensures that assigned tasks and responsibilities are fulfilled in a timely fashion
  • Demonstrates understanding of complex business and information technology management processes
  • Plays a lead role in client retention, relationship building, and communication. Act as the lead for multiple client accounts in Cyber Risk Management space.
  • Interacts with clients, managers and partners to build and nurture strong relationships
  • Tailors firm tools and methodologies as per client requirements
  • Evaluates, counsels, mentors and provides feedback on performance of others
  • Manages day-to-day client relationships at appropriate management levels
  • Participates in proposal development efforts to sell "add-on" work to clients
  • Experience in working on multiple Cyber Security Strategy including strategy and program/process development, maturity assessment, roadmap, training and awareness programs.
  • Demonstrates understanding of complex business and information technology management processes.
  • Interacts with clients, managers and partners to build and nurture strong relationships.
  • Tailors firm tools and methodologies as per client requirements.
  • Strong experience on presales, client management and conflict management.
  • Experience of Web Application Security Testing, Infrastructure VAPT, API testing, Mobile Testing (iOS & Android). 
  • Experience on Cloud (AWS & Azure) Configuration Review and Pentest.
  • Experience in conducting Firewall and Network Devices Configuration Review and configuration reviews of Windows, Linux, UNIX, Solaris, Databases, etc.
  • Good Experience in Red Teaming, Thick Client and Source Code Review.
  • Experience as an Security Architect, DevSecOPs.
  • Experience on End Point Security and Product Security.
  • Experience with Vulnerability Management tools: Burp, Kali Linux, Acunetix, AppScan, Nexpose, Qualys Guard, Nessus, Nmap, Metasploit, Fortify etc.
  • Experience in basic scripting such as: Shell, Python, PERL, etc.
  • Extensive experience in leveraging industry standards and frameworks such as OWASP, CIS, NIST, ISO/IEC 17799, ISO/IEC 27001, etc.
  • Good knowledge of TCP/ IP and Networks including Firewall, IDS/IPS, Routers, Switches, and network architecture.
  • Strong knowledge on Threat Profiling, Container, Dockers.
  • Demonstrates knowledge of one or more industry or functional area
  • Demonstrates ability to develop and review technical reports and develop and deliver presentations
  • Strong project management skills
  • Demonstrates a general knowledge of market trends, competitor activities, firm products and service lines
  • Membership and visibility in professional & civic organizations
  • Candidates must possess security certification of OSCP, CRTP, eJPT, CRTA, CISM
  • Good to have security certification for GPEN, CREST, CISSP.
  • Bachelor’s or Master's degree in Cybersecurity, Information Technology, or related field.