T&T | Cyber - CST | Deputy Manager | Delhi | Software Asset Management

Deloitte

5+ yrs New Delhi Full Time Work from office
Deloitte logo
Posted : yesterday
Actively hiring

Job description

Join Deloitte Touche Tohmatsu India LLP as a Deputy Manager in Cyber - CST, focusing on Software Asset Management in Delhi. You'll be integral to our mission of safeguarding valuable assets and ensuring robust cyber resilience. Our cybersecurity team empowers organizations to prevent attacks, protect assets, and manage cyber risk effectively, enabling new opportunities while embedding security from the outset of strategy development. This role offers a chance to make a significant impact in a dynamic and evolving field.

Responsibilities

Your responsibilities will encompass a comprehensive review, analysis, and maintenance of Software Bills of Materials (SBOMs) from various sources. You will be instrumental in creating and generating SBOMs for internal applications and products, ensuring strict adherence to organizational, regulatory, and industry standards. A key aspect involves identifying vulnerable, obsolete, or unauthorized software components through detailed SBOM analysis to bolster our software supply chain security and vulnerability management programs. Collaboration with Security, Procurement, Development, and Application teams will be crucial for driving SBOM compliance. You will also support software supply chain security assessments, risk reporting, and maintain essential SBOM repositories, documentation, and audit records, performing gap analyses and providing actionable recommendations for non-compliance.

Qualifications

We are seeking candidates with a minimum of 5 years of experience in SBOM, Software Compliance, Application Security, or Software Supply Chain Security. Essential qualifications include hands-on experience with SBOM creation, review, validation, and governance, alongside a strong grasp of software supply chain security, open-source software compliance, and dependency management. Proficiency in analyzing software vulnerabilities and component risks is vital. Excellent stakeholder management and communication skills are expected. Experience with leading SBOM and SCA tools such as Black Duck, Snyk, or Mend is highly advantageous. Familiarity with SBOM standards like SPDX, CycloneDX, and SWID, as well as concepts in Vulnerability Management, CVE/CVSS, DevSecOps, and Secure Software Development practices, is required. Experience integrating SBOM processes within CI/CD pipelines and knowledge of NIST SSDF are also key. A Bachelor's or Master's degree is a prerequisite for this role.

Essential Skills

Software Asset ManagementSBOMSoftware ComplianceApplication SecuritySoftware Supply Chain SecurityVulnerability ManagementOpen-Source Software ComplianceDependency ManagementStakeholder ManagementCommunicationSPDXCycloneDXSWIDSoftware Composition Analysis (SCA)NIST SSDFDevSecOpsSecure Software DevelopmentCI/CD

Good to Have

Black DuckSnykMend (WhiteSource)FOSSASonatype Nexus Lifecycle

Highlights

  • Actively hiring

More Details

RoleT&T | Cyber - CST | Deputy Manager | Delhi | Software Asset Management
IndustryInformation Technology & Services, Management Consulting
DepartmentSoftware Development
Employment TypeFull Time, Work from office

About the Company

Deloitte logo

Deloitte

Information Technology & Services

T&T | Cyber - CST | Deputy Manager | Delhi | Software Asset Management at Deloitte | SkillMX | SkillMX