Join Deloitte Cyber to help organizations strengthen visibility across their attack surface and address vulnerabilities before they can be exploited. As a Consultant, you will support attack surface management and vulnerability management activities by identifying exposures, analyzing findings, and helping drive remediation. You will work with global teams, threat intelligence, and security tools to deliver actionable reporting and improve cyber situational awareness.
Work you'll do
As a Consultant on the Cyber Defense & Resilience team, you will be responsible for:
- Configure and execute internal and external vulnerability scans to identify vulnerabilities and rogue assets
- Analyze, enrich, and prioritize findings and support remediation activities, including patching and configuration hardening
- Correlate threat feeds, assessment results, asset inventory data, and reporting frameworks to produce actionable vulnerability reports
- Support cyber situational awareness through recurring production reporting and ad hoc research requests for clients, partners, and internal stakeholders
- Identify asset data gaps, escalate issues affecting service-level agreements, and coordinate with leadership and remediation partners to improve service delivery
- Adhere to internal operational security requirements and Deloitte policies
The team
Cyber Defense & Resilience teams assist clients in identifying, prioritizing, and remediating vulnerabilities across their digital ecosystem through robust Attack Surface Management (ASM). By continuously monitoring client environments—networks, applications, cloud assets, and endpoints—they proactively uncover potential exposure points before threat actors can exploit them. Attack Surface Management (ASM) is a foundational capability within the Cyber Defense & Resilience portfolio, enabling proactive identification and mitigation of security vulnerabilities across an organization’s digital landscape.
Location: Bengaluru/Hyderabad/Pune/Chennai/Kolkata
Shift Timings: General
Qualifications
Required:
- 3-6 years of experience in vulnerability management, information security, or technical cybersecurity roles
- Bachelor’s degree in Computer Science or equivalent experience
- Certified Information Systems Security Professional (CISSP) certification
- Experience conducting vulnerability scans across internal and external networks
- Experience with network infrastructure devices, including routers and switches
- Experience with networking protocols, including Transmission Control Protocol/Internet Protocol (TCP/IP), Domain Name System (DNS), and Hypertext Transfer Protocol (HTTP)
- Experience using National Vulnerability Database, Common Vulnerabilities and Exposures (CVE), and Common Vulnerability Scoring System (CVSS) nomenclature
Preferred:
- Experience with vulnerability management tools such as Qualys, Tenable, or Rapid7
- Experience translating technical findings into remediation recommendations
- Experience with patch management tools such as Microsoft Intune, BigFix, Red Hat Satellite, or Microsoft System Center Configuration Manager (SCCM)
- Experience with asset inventory, provisioning, or deprovisioning lifecycle processes
- Experience with Confluence, Jira, or Configuration Management Databases (CMDBs) such as ServiceNow
- Experience with threat analysis, malicious code analysis, or enterprise mitigation strategies
#Cyber_Defense & Resilience