T&T I Cyber-D&R I Assistant Manager VAPT -Tenable.Sc | Hyderabad, Mumbai
Deloitte
Deloitte
Join a leading cybersecurity team focused on safeguarding valuable assets and preventing cyberattacks. This role is integral to developing robust strategies for managing information and technology risks, enabling organizations to operate securely and resiliently. You'll contribute to embedding cyber risk management from the initial stages of strategic planning.
Our team is dedicated to creating secure, vigilant, and resilient environments. We go beyond preventing and responding to attacks, focusing on holistic cyber risk management that unlocks new opportunities for our clients. Learn more about the exciting world of Cybersecurity and how you can make an impact.
Execute comprehensive external penetration tests, including public IP ranges, web applications, APIs, VPN gateways, and exposed services. Conduct network reconnaissance and assess perimeter devices, focusing on authentication bypass, SSL/TLS configuration, and misconfigurations.
Perform in-depth internal penetration testing targeting servers (Linux/Windows), Active Directory, network devices, and internal applications. Focus on privilege escalation, lateral movement, credential harvesting, and network segmentation validation to identify and address internal vulnerabilities.
Seeking professionals with 4-6 years of hands-on experience in Vulnerability Assessment and Penetration Testing (VAPT), with a strong proficiency in Tenable.sc. This includes experience in its configuration, installation, integration, and validation post-migration.
Key responsibilities involve conducting monthly VA for servers, network devices, databases, security devices, Active Directory, and endpoints, alongside assessing open-source components like Redis, Kafka, Kubernetes, and Jenkins. You will automate VA processes to enhance turnaround time, publish detailed reports with findings and recommendations, and collaborate with SOC, Incident Response, and Threat Hunting teams.
Additional duties include assisting the patch management team, performing manual assessments to minimize false positives, publishing vulnerability dashboards with severity and ageing status, conducting rescans post-patching, and providing technical assistance for audits. A foundational understanding of device logs for VAPT and Configuration Audit activities is essential, along with assisting in advisory preparation and tracking critical vulnerabilities.
An educational background with a Bachelor's or Master's degree in Computer Science, Information Security, or a related field is required. This role is based in Hyderabad or Mumbai.
Deloitte
Information Technology & Services