T&T I Cyber-D&R I Assistant Manager I Red Teaming Attack Surface Management | Mumbai (Mumbai, IN)
Deloitte
Deloitte
Join our dynamic Cybersecurity team as an Assistant Manager specializing in Red Teaming and Attack Surface Management. This role is pivotal in simulating sophisticated cyber-attacks to enhance client defenses, particularly within the BFSI sector. You'll be instrumental in ensuring our clients remain secure, vigilant, and resilient against evolving threats.
We are seeking a seasoned Red Team Specialist with extensive offensive security experience. Your expertise will be crucial in testing and strengthening detection and response capabilities through realistic attack simulations. This is an opportunity to make a significant impact in a leading cybersecurity practice.
Plan and execute comprehensive Red Team engagements, simulating diverse threat actor scenarios including external, internal, and physical threats. Conduct assumed breach assessments, initial access simulations, lateral movement exercises, and data exfiltration drills.
Leverage the MITRE ATT&CK framework to design realistic threat scenarios and meticulously map findings. Exploit misconfigurations and vulnerabilities across Active Directory, cloud environments, and enterprise infrastructure. Utilize and integrate CART/BAS tools to automate security posture validation.
Collaborate closely with Blue Teams to measure and improve detection, prevention, and response capabilities. Develop detailed reports featuring actionable remediation recommendations. Conduct threat emulation tailored to industry-specific APT groups relevant to the BFSI sector. Support security awareness initiatives, purple teaming exercises, and tabletop sessions.
A minimum of 5 years of hands-on experience in offensive security or red teaming roles is essential. Proficiency in Red Team TTPs, including phishing, C2 infrastructure, evasion techniques, privilege escalation, and data exfiltration, is required.
Demonstrate an in-depth understanding of Windows internals and Active Directory attacks (e.g., Kerberoasting, Pass-the-Hash/Ticket, ACL abuse). Possess a solid grasp of network protocols, cloud platforms, and endpoint security bypass techniques. Familiarity with attack simulation tools, custom scripting, and open-source frameworks like Cobalt Strike, Metasploit, Empire, and Covenant is expected.
Possession of OSCP or CRTP certifications is mandatory. Prior experience in BFSI sector engagements is highly valued, along with an understanding of regulatory requirements in financial institutions. Excellent analytical, problem-solving, and communication skills are crucial for stakeholder management and presenting findings. The ability to thrive in high-pressure environments and coordinate effectively with cross-functional teams is also key.
Deloitte
Financial Services