Join Deloitte Cyber to help clients identify, assess, and reduce exposure across their digital environment. As a Manager, you will lead vulnerability management and attack surface management efforts by driving program execution, improving visibility into asset risk, and helping stakeholders prioritize remediation actions. You will work with global teams, enterprise security tools, and reporting frameworks to strengthen cyber situational awareness and support resilient operations.
Work you'll do: - Lead the design, implementation, and day-to-day management of vulnerability management activities across client environments - Develop and maintain policies, standards, procedures, and reporting processes for vulnerability assessment, prioritization, and remediation - Oversee scanning, testing, and analysis activities using enterprise tools to identify vulnerabilities, rogue assets, and exposure trends - Communicate risk posture, remediation progress, and key metrics to technical teams, business stakeholders, and leadership - Drive continuous improvement by identifying asset data gaps, supporting program reporting, and advancing the vulnerability management roadmap
The team: Cyber Defense & Resilience teams assist clients in identifying, prioritizing, and remediating vulnerabilities across their digital ecosystem through robust Attack Surface Management (ASM). By continuously monitoring client environments—networks, applications, cloud assets, and endpoints—they proactively uncover potential exposure points before threat actors can exploit them. ASM is a foundational capability within the Cyber Defense & Resilience portfolio.
Location: Bengaluru/Hyderabad/Pune/Chennai Shift Timings: General
Required Qualifications
9+ years experience in vulnerability management or cybersecurity
CISSP, GCIA, or GMON certification
Designing or managing vulnerability management programs
Vulnerability analysis using Qualys, Tenable, or Rapid7
Networking protocols: TCP/IP, DNS, HTTP
Using CVE and CVSS frameworks
Preferred Qualifications
Metrics, dashboards, or executive reporting on vulnerability status
Asset provisioning or deprovisioning lifecycle
Patch management tools like Microsoft Intune or Red Hat Satellite
Malicious code analysis, DDoS, or network scanning analysis
Confluence, Jira, or ServiceNow (CMDBs)
Databases, query design, or data analysis
Skills Required
Vulnerability managementAttack surface managementQualysTenableRapid7TCP/IPDNSHTTPCVECVSSCISSPGCIAGMONPatch managementMicrosoft IntuneRed Hat SatelliteServiceNowJiraConfluenceData analysis