T&T | Cyber - CST | Deputy Manager | Delhi | Software Asset Management
Deloitte
Deloitte
Join Deloitte Touche Tohmatsu India LLP as a Deputy Manager in Cyber - CST, focusing on Software Asset Management in Delhi. You'll be integral to our mission of safeguarding valuable assets and ensuring robust cyber resilience. Our cybersecurity team empowers organizations to prevent attacks, protect assets, and manage cyber risk effectively, enabling new opportunities while embedding security from the outset of strategy development. This role offers a chance to make a significant impact in a dynamic and evolving field.
Your responsibilities will encompass a comprehensive review, analysis, and maintenance of Software Bills of Materials (SBOMs) from various sources. You will be instrumental in creating and generating SBOMs for internal applications and products, ensuring strict adherence to organizational, regulatory, and industry standards. A key aspect involves identifying vulnerable, obsolete, or unauthorized software components through detailed SBOM analysis to bolster our software supply chain security and vulnerability management programs. Collaboration with Security, Procurement, Development, and Application teams will be crucial for driving SBOM compliance. You will also support software supply chain security assessments, risk reporting, and maintain essential SBOM repositories, documentation, and audit records, performing gap analyses and providing actionable recommendations for non-compliance.
We are seeking candidates with a minimum of 5 years of experience in SBOM, Software Compliance, Application Security, or Software Supply Chain Security. Essential qualifications include hands-on experience with SBOM creation, review, validation, and governance, alongside a strong grasp of software supply chain security, open-source software compliance, and dependency management. Proficiency in analyzing software vulnerabilities and component risks is vital. Excellent stakeholder management and communication skills are expected. Experience with leading SBOM and SCA tools such as Black Duck, Snyk, or Mend is highly advantageous. Familiarity with SBOM standards like SPDX, CycloneDX, and SWID, as well as concepts in Vulnerability Management, CVE/CVSS, DevSecOps, and Secure Software Development practices, is required. Experience integrating SBOM processes within CI/CD pipelines and knowledge of NIST SSDF are also key. A Bachelor's or Master's degree is a prerequisite for this role.
Deloitte
Information Technology & Services