As a Senior Consultant at Deloitte Consulting, you will support end-to-end vulnerability management engagements, assisting in the identification, assessment, prioritization, and remediation tracking of security vulnerabilities across client environments. You will work alongside senior practitioners and cross-functional teams to deliver high-quality outcomes, leveraging both traditional VM tooling and emerging Anthropic / Agentic AI capabilities to accelerate threat detection and response.
Work you'll do
As a Senior Consultant on the Cyber Operate team, you will be responsible for leading vulnerability management engagements across client environments.
- Lead vulnerability assessment engagements across on-premises, cloud, and hybrid environments, and manage the vulnerability management lifecycle from policy design through remediation verification.
- Serve as a primary client contact, align vulnerability management strategies to business risk priorities and regulatory requirements, and produce risk-based dashboards and reporting for leadership.
- Design and implement Anthropic Claude-powered automation workflows for vulnerability ingestion, triage, prioritization, and remediation guidance.
- Integrate vulnerability management platforms with security orchestration, security information and event management, and information technology service management systems to automate workflows and reduce manual effort.
- Define and improve operating procedures, service level agreements, and quality metrics; mentor junior team members; and coordinate remediation tracking across stakeholder groups.
The team
Cyber Operate teams manage clients' critical cyber assets either as a fully managed service or in partnership with clients. They deliver skilled talent, cutting-edge technologies, and robust processes to operate client cyber capabilities. This includes managing the identity lifecycle, security operations, threat intelligence, application security, business transformation, and ensuring continuous compliance. Services include Cyber-as-a-Service, Managed Application Security, and Managed Extended Detect & Respond (MXDR).
Location: Bengaluru / Hyderabad / Pune / Chennai
Shift Timings: 2:00 PM to 11:00 PM IST, with flexibility required based on client expectations, engagement demands, time zone coverage, on-call support, and after-hours operational needs
Qualifications
Required:
- 5-10 years of experience in cybersecurity, including 4+ years of vulnerability management experience in enterprise or managed service environments
- Experience with vulnerability management platforms such as RiskSense, ServiceNow Vulnerability Response, Armis VIPR, Tenable.sc, Tenable.io, Qualys VMDR, Rapid7 InsightVM, Microsoft Defender Vulnerability Management, or Prisma Cloud
- Experience integrating Anthropic Claude application programming interfaces into security workflows, including prompt engineering, function calling, and tool use for triage, summarization, and remediation guidance
- Experience with vulnerability risk scoring frameworks, including Common Vulnerability Scoring System version 3 or version 4, Exploit Prediction Scoring System, CISA Known Exploited Vulnerabilities, and business-risk contextualization
- Experience scripting application programming interface integrations, data pipelines, and automation of vulnerability management reporting workflows
- Experience with security information and event management platforms, cloud security posture management, container or Kubernetes vulnerability scanning, and security orchestration, automation, and response platforms
- Bachelor’s degree in Computer Science, Cyber Security, Information Security, Engineering, Information Technology, or equivalent
Preferred:
- Experience building retrieval-augmented generation pipelines using Claude or similar large language models against vulnerability knowledge bases
- Experience with artificial intelligence or machine learning-based anomaly detection integrated with vulnerability management tooling for predictive risk scoring
- CISSP, CISM, Tenable Certified Security Professional, Qualys Certified Specialist, AWS Security Specialty, or Azure Security Specialty certification
- Experience with attack surface management platforms such as Mandiant ASM, CrowdStrike Falcon Surface, or Cortex XPANSE