Join Deloitte Cyber and help organizations address evolving cyber threats through offensive security, threat simulation, and resilience services. As part of the Cyber Defense & Resilience practice, you will support client engagements focused on adversary emulation, vulnerability assessment, and security operations improvement. This role offers the opportunity to contribute to large-scale cybersecurity projects while building experience across attack simulation, threat management, and security transformation.
Work you'll do
As a Consultant on the Cyber team, you will be responsible for supporting project delivery across offensive security and cybersecurity transformation engagements.
- Support project delivery under defined guidelines, standard operating procedures, and service level agreements.
- Perform development and customization activities for security and data protection technology implementation projects.
- Execute assigned tasks under general supervision and contribute to timely, accurate delivery of client work products.
- Apply knowledge of business processes, information technology management processes, and Deloitte methodologies, frameworks, and tools.
- Support practice development initiatives, documentation, and engagement-related coordination activities.
The team
Cyber Defense & Resilience teams assist clients in defending against advanced threats by transforming security operations, and by monitoring technology, data analytics, and threat intelligence. They help manage and protect dynamic attack surfaces and provide rapid crisis and cyber incident response, thereby ensuring that clients can be ready for, respond to, and recover from business disruptions. Examples of work include Operational Resilience, Crisis & Incident Response, and Security Operations Center Transformation.
Location: Bengaluru, Hyderabad, Pune, Chennai
Shift Timings: General
Qualifications
Required:
- 3-6 years of experience in cybersecurity, including hands-on experience in at least two of the following: penetration testing, red teaming, phishing, threat management, or adversary simulation
- Experience using offensive security tools such as Nmap, Metasploit, or Cobalt Strike
- Experience with networking protocols, including Transmission Control Protocol/Internet Protocol (TCP/IP), Domain Name System (DNS), and Hypertext Transfer Protocol (HTTP)
- Experience with cybersecurity frameworks and standards such as Open Worldwide Application Security Project (OWASP), Center for Internet Security (CIS), National Institute of Standards and Technology (NIST), or ISO/IEC 17799
- Experience with vulnerability discovery, threat analysis, remediation tracking, and security reporting
- Experience with scripting in Python, PowerShell, or Bash for automation or custom tooling
- Certified Ethical Hacker (CEH), CompTIA Security+, and at least one advanced certification such as Offensive Security Certified Professional (OSCP) or Offensive Security Wireless Professional (OSWP)
Preferred:
- Experience in additional adversarial domains such as mobile testing, DevSecOps vulnerability management, or advanced red teaming
- Experience with command-and-control or lateral movement tools such as Cobalt Strike or Havoc
- Experience using reverse engineering tools such as IDA Pro or Ghidra
- Experience producing post-engagement reports and detection or response recommendations
- Experience integrating threat feeds, asset inventories, and control frameworks into security assessments
- Experience mentoring junior practitioners or supporting purple team exercises