T&T | Cyber - CST | Deputy Manager | Delhi | Software Asset Management (Delhi, IN)
Deloitte
Deloitte
Join Deloitte Touche Tohmatsu India LLP as a Deputy Manager in our Cyber team, focusing on Software Asset Management in Delhi. This role is integral to ensuring our cybersecurity posture and protecting valuable organizational assets. We emphasize security, vigilance, and resilience, embedding cyber risk management into strategic development.
Learn more about our Cybersecurity offerings and how we empower organizations to manage information and technology risks effectively. This is an exciting opportunity to contribute to a leading firm in a critical area of cyber defense.
Your responsibilities will involve the thorough review, analysis, validation, and maintenance of Software Bills of Materials (SBOMs) from vendors and internal teams. You will be responsible for creating and generating SBOMs for in-house applications and products.
Key duties include ensuring SBOM compliance with organizational, regulatory, and industry standards. You'll identify vulnerabilities, obsolete components, or unauthorized software through detailed SBOM analysis. This role also supports software supply chain security, vulnerability management programs, and collaborates closely with Security, Procurement, Development, and Application teams to drive compliance.
Further responsibilities include supporting software supply chain security assessments, maintaining SBOM repositories, documentation, audit records, and reporting metrics. You will perform gap analyses and provide actionable recommendations for non-compliant SBOMs.
We are seeking a candidate with a Bachelor's or Master's degree and a minimum of 5 years of experience in Software Asset Management, Software Compliance, Application Security, or Software Supply Chain Security. A strong track record of hands-on experience in SBOM creation, review, validation, and governance is essential.
Candidates should possess a deep understanding of software supply chain security, open-source software compliance, and dependency management. Experience in analyzing software vulnerabilities and component risks is required, alongside robust stakeholder management and communication skills. Proficiency with SBOM and Software Composition Analysis (SCA) tools such as Black Duck, Snyk, Mend, FOSSA, Sonatype Nexus Lifecycle, or similar is necessary.
Familiarity with SBOM standards like SPDX, CycloneDX, and SWID is crucial. You should also have knowledge of Software Composition Analysis (SCA), Open-Source Governance, License Compliance, Vulnerability Management, CVE/CVSS, DevSecOps, and Secure Software Development practices. Experience integrating SBOM generation into CI/CD pipelines and understanding of NIST SSDF and relevant frameworks are highly desirable.
Deloitte
Cybersecurity