…

T&T Cyber D&R Manager Vulnerability Assessment & Penetration Testing (VAPT) Bengaluru

Deloitte India (South Asia) · Consulting & Professional Services

  • Bengaluru, India
  • On-site
  • Posted yesterday
  • Apply by 30 Oct
  • Cybersecurity

About the job

T&T | Cyber: D&R | Manager | Vulnerability Assessment & Penetration Testing (VAPT) | Bengaluru

Job requisition ID : 114204
Location : Bengaluru
Entity : Deloitte Touche Tohmatsu India LLP

The team

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about  Cybersecurity

Your work profile

Evaluates, counsels, mentors and provides feedback on performance of others
Assist in retention of people and lead training efforts
Manages day-to-day client relationships at appropriate senior management levels
Contributes to sales process by participating and/or leading proposal development efforts to sell "add-on" work to client and participate in the client presentation/orals
Identifies additional opportunities for the existing clients and opportunities for cross selling across service lines
Play substantive/lead role in engagement planning, economics, and billing
Demonstrates a general knowledge of market trends, competitor activities, firm products and service lines
Experience in leading multiple client engagements in multiple Cyber Security Management domains
Experience in leading and executing multiple Cyber Security Strategy engagements and building Cyber Threat and Vulnerability management programs for organizations
Cyber Threat, Vulnerability and Risk Assessment - Ability to identify business implications and identifying tactical and strategic recommendations to mitigate the risk.
Experience in managing multiple Cyber Threat Management projects including technical and strategy projects.
Substantial experience in architecting technology solutions in the Cyber Security Management space
Ability to define the business & technical scope of a project. Should be able to independently lead delivery teams to deliver projects according to client specifications after such scope is defined
Experience in managing multiple projects covering the full life cycle of project management starting from proposal, orals presentation, project planning and management, deliverables review, final client presentation and project closure.
Extensive experience in leveraging industry standards and frameworks such as OWASP, CIS, NIST, ISO/IEC 17799, ISO/IEC 27001, etc.
Experience in operationalizing the solutions implemented (e.g. ArcSight Implementation experience and operationalizing Security Monitoring and Security Operations post Implementation)
People and practice management skills
Experience with Vulnerability Management and Penetration testing tools: Burp suite, Kali Linux, Acunetix, AppScan, Nexpose, Qualys Guard, Nessus, Nmap, Metasploit, Fortify etc.
Experience in basic scripting such as: Shell, Python, PERL, etc.
Basic knowledge of Technoilogies such as: IPSEC, SSL, SSH, VPN, Ethernet Token Ring, WAP, SMTP, FTP, Frame Relay, WAN, ATM, FDDI, DSL, ISDN, HP Openview, Sun NetManage, Cisco Works, Radius, Big Brother, F5.

Key Responsibilities:

Total 9-15 years of experience in Cyber security domain
Manages Cyber Security Assessment projects, guides the team on a day-to-day basis and ensures that assigned tasks and responsibilities are fulfilled in a timely fashion
Demonstrates understanding of complex business and information technology management processes
Plays a lead role in client retention, relationship building, and communication. Act as the lead for multiple client accounts in Cyber Risk Management space.
Interacts with clients, managers and partners to build and nurture strong relationships
Tailors firm tools and methodologies as per client requirements
Evaluates, counsels, mentors and provides feedback on performance of others
Manages day-to-day client relationships at appropriate management levels
Participates in proposal development efforts to sell "add-on" work to clients
Experience in working on multiple Cyber Security Strategy including strategy and program/process development, maturity assessment, roadmap, training and awareness programs.
Demonstrates understanding of complex business and information technology management processes.
Interacts with clients, managers and partners to build and nurture strong relationships.
Tailors firm tools and methodologies as per client requirements.
Strong experience on  presales, client management and conflict management .
Experience  of Web Application Security Testing, Infrastructure VAPT, API testing, Mobile Testing (iOS & Android).
Experience on  Cloud (AWS & Azure) Configuration Review and Pentest .
Experience in  conducting Firewall and Network Devices Configuration Review and configuration reviews of Windows, Linux, UNIX, Solaris, Databases, etc.
Good Experience in  Red Teaming, Thick Client and Source Code Review .
Experience as an  Security Architect, DevSecOPs.
Experience on  End Point Security and Product Security.
Experience with Vulnerability Management tools: Burp, Kali Linux, Acunetix, AppScan, Nexpose, Qualys Guard, Nessus, Nmap, Metasploit, Fortify etc.
Experience in basic scripting such as:  Shell, Python, PERL , etc.
Extensive experience in leveraging industry standards and frameworks such as  OWASP , CIS, NIST, ISO/IEC 17799, ISO/IEC 27001 , etc.
Good knowledge of TCP/ IP and Networks including Firewall, IDS/IPS, Routers, Switches, and network architecture.
Strong knowledge on Threat Profiling, Container, Dockers.
Demonstrates knowledge of one or more industry or functional area
Demonstrates ability to develop and review technical reports and develop and deliver presentations
Strong project management skills
Demonstrates a general knowledge of market trends, competitor activities, firm products and service lines
Membership and visibility in professional & civic organizations
Candidates must possess security certification of OSCP, CRTP, eJPT, CRTA, CISM
Good to have security certification for GPEN, CREST, CISSP.
Bachelor’s or Master's degree in Cybersecurity, Information Technology, or related field.