T&T I Cyber-D&R I Deputy Manager I Red Teaming Attack Surface Management | Mumbai
Deloitte
Deloitte
Join our Cyber Defense and Response team as a Deputy Manager specializing in Red Teaming and Attack Surface Management. Deloitte is at the forefront of helping organizations build robust defenses against cyber threats. We focus on creating secure, vigilant, and resilient environments by integrating cyber risk management into strategic development, allowing for effective information and technology risk management and the exploration of new opportunities. Explore more about our Cybersecurity services.
This role offers a dynamic opportunity to significantly impact client security postures by simulating advanced cyber-attacks. You will play a crucial part in assessing and strengthening detection and response capabilities, with a particular focus on the BFSI sector.
Plan and execute comprehensive Red Team engagements, replicating realistic threat actor scenarios across external, internal, and physical vectors. Conduct assumed breach assessments, focusing on initial access, lateral movement, and data exfiltration techniques. Leverage the MITRE ATT&CK framework to architect threat scenarios and meticulously map findings.
Exploit vulnerabilities and misconfigurations within Active Directory, cloud platforms, and enterprise infrastructure. Utilize and integrate Continuous Attack Resistance Testing (CART) and Breach and Attack Simulation (BAS) tools, such as Cymulate or Pycus, to automate security posture validation. Collaborate closely with Blue Teams to measure and enhance detection, prevention, and response capabilities post-engagement.
Develop detailed reports outlining actionable remediation recommendations. Conduct sophisticated threat emulation exercises, tailored to specific industry-relevant Advanced Persistent Threat (APT) groups, particularly within the BFSI sector. Maintain up-to-date knowledge of emerging threats, attack methodologies, and effective countermeasures. Support various security initiatives, including awareness training, purple teaming, and tabletop exercises, for both internal teams and clients.
A minimum of 5 years of hands-on experience in offensive security or Red Team roles is essential. Proficiency in Red Team Tactics, Techniques, and Procedures (TTPs), including phishing, Command and Control (C2) infrastructure, evasion strategies, privilege escalation, and data exfiltration, is required.
Possess an in-depth understanding of Windows internals and common Active Directory attack vectors such as Kerberoasting, Pass-the-Hash/Ticket, ACL abuse, and DCShadow. Demonstrate a solid grasp of network protocols, cloud environments, and techniques for bypassing endpoint security solutions.
Familiarity with attack simulation tools, custom scripting, and open-source frameworks like Cobalt Strike, Metasploit, Empire, and Covenant is expected. Prior experience in physical security assessments, badge cloning, RFID/NFC exploitation, and social engineering is a significant advantage.
Strong knowledge of frameworks like MITRE ATT&CK and NIST is crucial. The ability to document findings, align them with risk frameworks, and present complex information to both technical and executive stakeholders is vital. Possess offensive security certifications such as OSCP, CRTP, or equivalent. Prior experience in BFSI sector engagements and an understanding of financial institution compliance requirements (e.g., RBI, SEBI, ISO 27001) are preferred.
Exceptional analytical and problem-solving abilities are a must. Strong communication skills are essential for effective stakeholder management and post-engagement debriefs. The capacity to perform under pressure and coordinate seamlessly with cross-functional teams is also a key requirement. Candidates should hold a Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field.
Deloitte
Information Technology & Services