Level: Consultant
As an experienced Consultant at Deloitte Consulting, you will be responsible for individually delivering high quality work products within due timelines. Need-basis you will be mentoring and/or directing junior team members/liaising with onsite/offshore teams to understand the functional requirements.
Work you'll do
As a Consultant on the Detect & Respond team, you will be responsible for vulnerability management activities that support cyber security monitoring, reporting, and remediation.
- Configure and execute vulnerability scans across internal and external networks.
- Analyze, enrich, and prioritize remediation activities, including patch deployment and configuration hardening.
- Use threat feeds, assessment tools, asset inventory tools, and reporting frameworks to match assets to identified vulnerabilities and produce reporting.
- Support cyber security situational awareness by responding to ad hoc reporting requests, research topics, and recurring production reporting requirements.
- Identify gaps in asset information, coordinate with leadership and remediation partners, and follow Deloitte operational security policies.
The team
Deloitte’s Detect & Respond (D&R) aims to combine sophisticated technologies and human intelligence to help the clients monitor, detect, investigate, and respond to known and unknown attacks. We help our clients to be secure, vigilant, and resilient in the face of an ever-increasing array of cyber threats and vulnerabilities. The Detect and Respond team delivers service to clients through following key areas:
- Threat detection and response
- Attack surface management
- Threat Intelligence
- Threat Hunting
- Data Protection
Location: Bengaluru/Hyderabad/Pune/Chennai
Shift Timings: 24x7 rotational shifts; flexibility for night, weekend, and holiday coverage is essential; on-call support required based on project assignments
Qualifications
Required:
- Bachelor’s degree in Information Security, Information Technology, Computer Science, Mathematics, or another technical field
- 3+ years of experience in vulnerability management, information security, incident response, red team operations, application security, reverse engineering, or another cyber security role
- CISSP, GIAC Certified Intrusion Analyst, GIAC Continuous Monitoring, CEH, or equivalent certification
- Experience with network probing, scanning, denial-of-service activity, or malicious code analysis
- Knowledge of network infrastructure devices, including routers and switches
- Knowledge of networking protocols, including TCP/IP, DNS, and HTTP
- Knowledge of vulnerability classification frameworks, including CVE and CVSS
Preferred:
- Experience with vulnerability analysis tools such as Qualys or Tenable
- Experience with asset provisioning and deprovisioning lifecycle processes
- Experience with patch management technologies such as Microsoft System Center Configuration Manager
- Experience using Confluence, Jira, or Configuration Management Databases such as ServiceNow
- Knowledge of operating systems, networking technologies, databases, and query design
- Knowledge of how malicious code operates and how technical vulnerabilities are exploited
#Cyber_Cyber Operate