Deliver critical cyber risk insights by supporting Deloitte’s vulnerability management and perception monitoring activities. In this role, you will analyze external exposure and cyber risk-rating data, help identify drivers of rating changes, and support consistent operational delivery across global stakeholders. The role offers the opportunity to work across third-party risk, remediation tracking, reporting, and service operations in a fast-paced cyber environment.
Work you'll do
As an Analyst, Cyber Engineering on the Vulnerability Management team, you will be responsible for…
- Monitoring third-party cyber risk ratings and external exposure indicators across approved security rating and exposure monitoring platforms
- Analyzing rating changes and exposure data to identify drivers such as misconfigurations, exposed services, and security hygiene issues
- Validating findings through platform evidence, scan outputs, and publicly available data, and escalating high-risk issues when required
- Supporting third-party risk operations, including intake, triage, remediation tracking, and reporting in line with documented procedures
- Preparing standardized dashboards, reports, and operational documentation to support regional and global service delivery
The team
The Vulnerability Management team supports consistent, scalable cyber risk visibility across Deloitte’s global environment. The team helps monitor external exposure, assess changes in cyber risk indicators, and support operational processes that enable informed risk decisions. This role works closely with regional and global stakeholders to support service delivery, reporting, and remediation follow-up.
Location: Hyderabad
Shift Timings: 11 AM to 8 PM
Qualifications
Required:
- Bachelor’s degree in Computer Science, Information Security, Information Systems, or a related field
- 3+ years of experience in information security or cybersecurity
- 3+ years of experience supporting vulnerability management, third-party cyber risk, or cyber risk-rating activities
- Experience using one or more vulnerability management, exposure monitoring, or security rating platforms such as Qualys, Nessus, Rapid7, BitSight, SecurityScorecard, or RiskRecon
- Experience analyzing vulnerability, exposure, or rating data to identify misconfigurations, exposed services, or security posture issues
- Experience preparing reports, dashboards, or status updates using Microsoft Word, Excel, and PowerPoint
- Experience documenting findings, remediation status, and operational procedures in trackers, workflows, or standard operating documents
Preferred:
- Experience with Common Vulnerabilities and Exposures (CVE) and Common Vulnerability Scoring System (CVSS)
- Experience with cloud platforms such as Microsoft Azure, Amazon Web Services, or Google Cloud Platform
- Experience with data analysis, reporting, or visualization tools
- Experience with Python or PowerShell for basic scripting or automation
- Experience with OWASP Top 10 or application security risk concepts
- Experience working with global or cross-functional teams