Job Title:  Associate Partner | Vulnerability Assessment & Penetration Testing (VAPT) | Chennai | Cyber Defense

Overview

Deloitte India’s Cyber Defense and Resilience practice is seeking a senior professional to serve as Executive Director for Attack Surface Management with 20+ years of experience across Offensive Security, Vulnerability Management, Secure Application Development, DevSecOps, Application Security, Exposure Management, Threat Modelling, etc., with a proven record of building offerings, scaling teams, and leading C-suite relationships.

This senior level role focuses on market growth, opportunity creation, and strengthening client relationships, while also supporting delivery teams with practical guidance and helping shape the future direction of Attack Surface Management in a rapidly evolving technology landscape.

Key Responsibilities

1.      Market Leadership & Growth

·      Drive market-making for Attack Surface Management by identifying client pain points & challenges and converting them into structured multi-year opportunities.

·      Identify, structure, and sell complex engagements that unify discovery, prioritization, validation, and remediation, thereby positioning ASM as an outcome‑oriented investment.

·      Build and expand senior executive relationships with CISOs, CTOs, CIOs, digital/engineering leaders, chief product officers, and risk committees, positioning Deloitte as the partner of choice for exposure reduction.

·      Drive pipeline growth through thought leadership, targeted campaigns, solution showcases, and alliance‑based market plays.

2.      Client Leadership and Advisory

·      Advise Boards and senior technology stakeholders on evolving exposure management operating models and moving from periodic testing to continuous, intelligence‑driven reduction.

·      Shape client strategies for integrating ASM with SOC, Incident Response, Threat Intelligence, Cloud Security, and Product Security.

·      Design client‑specific roadmaps that unify discovery, prioritization, validation, and remediation governance into measurable outcomes.

3.      Delivery Excellence and Program Outcomes

·      Provide senior oversight for large ASM programs that span vulnerability assessments, application testing, threat modelling, red/purple teaming, DevSecOps, etc.

·      Maintain strong delivery governance, ensuring execution excellence, predictable outcomes, and scaled repeatability.

·      Drive continuous improvement in ASM methodologies and delivery approaches based on market feedback and client patterns.

4.      Solution & Capability Development

·      Contribute foresight & Drive innovation on how ASM is evolving with automation, AI‑enabled testing, secure development practices, modern attack paths, and exposure intelligence.

·      Institutionalize accelerators for asset discovery, attack path analysis, exploitability scoring, and remediation workflows, incorporating automation and GenAI where appropriate.

·      Codify industry-specific playbooks and exposure heatmaps for internet-facing assets, cloud services, APIs, and third-party externalities.

5.      People, Culture, and Capability Building

·      Build and mentor a high-performing Directors, Senior Managers, and professionals across the practice.

·      Foster a performance culture grounded in inclusion, accountability, coaching, and continuous learning.

Required Experience

·      15 to 20+ years in cybersecurity with substantial depth in Offensive Security, Vulnerability Management, AppSec, Secure Development, DevSecOps, Exposure Management, etc.

·      Demonstrated success owning P&L or a multimillion-dollar portfolio, scaling teams, and closing complex pursuits in India or global markets.

·      Proven experience advising and influencing CISOs, CTOs, CIOs, and business leaders on exposure reduction and resilience.

·      Experience leading large cross-functional cyber teams in complex delivery environments.

·      Strong market presence, thought leadership, and ability to represent Deloitte at industry forums.

Desired Attributes

·      Commercially oriented market leader with strong opportunity shaping instincts and growth mindset.

·      Strategic thinker adept at designing future‑state ASM operating models and translating complex technical insights into executive‑level narratives.

·      Demonstrated ability to influence decision-making at the highest levels and drive consensus across IT, security, and business stakeholders

·      Ability to build and scale high-performance teams that specialize in offensive security, threat-led validation, and exposure reduction.

·      Passion for innovation, automation and continuous monitoring to drive measurable improvements in client resilience.