Job description
Connect to your Industry
Global Cyber Defense integrates defensive measures to detect, mitigate, and respond to identified cyber threats across the global network through the integration of cross-functional capabilities; operationalized by a well trained and experienced world class workforce; driven by centralized governance; utilizing standardized operating procedures that orchestrates and automates through global technology platforms.
Connect to your career at Deloitte
Deloitte drives progress. Using our vast range of expertise, we help our clients' become leaders wherever they choose to compete. To do this, we invest in outstanding people. We build teams of future thinkers, with diverse talents and backgrounds, and empower them all to reach for and achieve more.
What brings us all together at Deloitte? It's how we approach the thousands of decisions we make every day. How we behave, our beliefs and our attitudes. In other words: our values. Whatever we do, wherever we are in the world, we lead the way, serve with integrity, take care of each other, foster inclusion, and collaborate for measurable impact. These five shared values lead every decision we make and action we take, guiding us to deliver impact how and where it matters most.
Connect to your opportunity
As a Vulnerability Management T1 Operator, you will provide expertise to ensure the Vulnerability Management Service delivers consistently across regional areas. You will develop and maintain infrastructure and continually improve and automate the service road map to increase value to the global service teams and member firms.
* Perform information system security vulnerability scanning to discover and analyze vulnerabilities and characterize risks to networks, operating systems, applications, databases, and other information system components.
* Deliver the following day to day support activities:
o Act as a regional operator for managing and optimizing VM scanning tools (e.g., Qualys, Tenable, Rapid7).
o Serve as point of contact for the team, representing the team as subject matter expert.
o Develop ad-hoc scripts, reports, or dashboards to enhance, automate and drive service enhancement in the use of vulnerability management tools and the triage of data.
o Manage major service upgrades and changes to core platforms to ensure consistency and stability.
o Respond to time-sensitive requests from IT and patching teams.
o Provide exposure reports for vulnerabilities, assets, and software.
o Perform recurring and on-demand scanning of organization systems and cloud environments.
o Monitor vulnerability scans to assess prioritize, and report findings to provide recommended remediation actions.
o Assist in the development of best practices to mitigate against common threats assessing damage potential.
o Manage multiple projects including ongoing scanning of environment, security awareness, documentation, and technical reviews for projects.
o Prepare reports on metrics, remediation guidance, and technical risk evaluation.
o Monitor remediation methods in place and ensure timely completion.
o Maintain documentation regarding threat management, including policies and procedures.
o Gather security notifications from our vendors and perform an initial analysis and reports.
o Improve and automate existing vulnerability management systems.
o Provide technical support for vulnerability management projects.
Connect to your skills and professional experience
Who you'll work with:
The Deloitte Global Cybersecurity function is responsible for enhancing data protection, standardizing and securing critical infrastructure, and gaining cyber visibility through security operations centers. The Cybersecurity organization delivers a comprehensive set of security services to Deloitte's global network of firms around the globe.
What do we expect from you?
* Strong knowledge of vulnerability management tools and techniques (such as Qualys, Nessus, Nexpose/Rapid7).
* Experience working with large data sets.
* Experience automating processes and procedures.
* Experience in scanning for vulnerabilities and prioritizing them based on their severity.
* Experience in scripting especially in Python, Bash and PowerShell or other languages.
* Proven experience leading in a cybersecurity environment.
* In-depth knowledge of information security best practices.
* Understanding of general Secure Software Development Lifecycle standards.
* Knowledge of technical concepts such as cloud computing, automation, networking, and application development.
Education:
* Bachelor's Degree (or equivalent) in computer science, information security, or a related field.
* Security+, Network+, or vendor-specific certifications in Vulnerability & Asset Management
* Certifications such as CISSP, CISM, CEH, or GIAC are highly desirable.
Preferred:
* Proven experience in Vulnerability Management or compliance monitoring
* Proven experience working in Information Security
* Good working knowledge of Vulnerability scanning and management platforms.
* Experience with IT controls monitoring for regulatory and compliance requirements.
* Knowledge of vulnerability data management and reporting process automation
* Knowledge of security frameworks and standards, such as CVSS and CVE.
* Experience in cross-functional teaming and managing multiple stakeholders.
* Knowledge of security modern threats, Cyber-attack vectors and Indicators of Compromise.
* Strong analytical and problem-solving skills.
* Ability to work independently and manage multiple tasks.
* Have strong organizational and communication capabilities.
Connect to your business - Enabling Functions
Collaboration is central to everything we do at Deloitte. From IT to HR, marketing and more, our teams help to support the wider business in everything they do. Bringing your individual skills and specialist knowledge, you can make a far-reaching impact. Come join us.
Personal independence
Regulation and controls are standard practice in our industry and Deloitte is no exception. These controls provide important legal protection for both you and the firm. We are subject to a number of audit regulations, one of which requires that certain colleagues abide by specific personal independence constraints (e.g., in relation to any financial interests and employment relationships). This can mean that you and your "Immediate Family Members" are not permitted to hold certain financial interests (shares, funds, bonds etc.) with audit clients of the firm, and also prohibitions on certain employment relationships (e.g., you are not permitted to hold a secondary employment role with SEC audit clients of the firm whilst being employed by the firm). The recruitment team will provide further detail as you progress through the recruitment process or you can contact the Independence team upon request.
Connect with your colleagues
"Everyone at Deloitte builds relationships with their peers and puts in effort to get to know one another, making the work more enjoyable."
Our hybrid working policy
You'll be based in one of our UK locations with hybrid working.
At Deloitte we understand the importance of balancing your career alongside your home life. That's why we'll support you to work flexibly through our hybrid working policy. Depending on the requirements of your role, you'll have the opportunity to work in your local office, virtual collaboration spaces, client sites and remotely. You'll get the chance to meet face to face when needed, while you collaborate and learn from colleagues, share your experiences, and build the relationships that will fuel your career and prioritise your wellbeing. Please check with your recruiter for the specific working requirements that may apply for your role.
Our commitment to you
Making an impact is more than just what we do: it's why we're here. So we work hard to create an environment where you can experience a purpose you believe in, the freedom to be you, and the capacity to go further than ever before.
We want you. The true you. Your own strengths, perspective and personality. So we're nurturing a culture where everyone belongs, feels supported and heard, and is empowered to make a valuable, personal contribution. You can be sure we'll take your wellbeing seriously, too. Because it's only when you're comfortable and at your best that you can make the kind of impact you, and we, live for.
Your expertise is our capability, so we'll make sure it never stops growing. Whether it's from the complex work you do, or the people you collaborate with, you'll learn every day. Through world-class development, you'll gain invaluable technical and personal skills. Whatever your level, you'll learn how to lead.
Connect to your next step
A career at Deloitte is an opportunity to develop in any direction you choose. Join us and you'll experience a purpose you can believe in and an impact you can see. You'll be free to bring your true self to work every day. And you'll never stop growing, whatever your level.
Discover more reasons to connect with us, our people and purpose-driven culture at deloitte.co.uk/careers
WPFULL SLICSS LOCOFFICE