D

๐•๐€๐๐“ ๐„๐ง๐ ๐ข๐ง๐ž๐ž๐ซ (Tenable.sc)

Deloitte ยท Mumbai, Maharashtra

2โ€“7 yrs experienceFullTimePosted 3 days ago
Apply now โ†’

Job description

**The team** Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient---not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity **Your work profile** * Perform external penetration testing which includes, Public IP ranges, Web applications and API's, VPN GW's, exposed services, Firewall and Perimeter devices focusing on Authentication bypass, SSL/TLS configuration review, Misconfiguration and exposure assessment and network reconnaissance which includes Port Scanning / Service Enumeration. * Perform Internal penetration testing which includes, Servers (Linux / Windows), Active directory, Network devices, Internal applications, Database services focusing on Privilege escalation, Lateral movement, Weak authentication protocols, Credential harvesting and network segmentation validation. **Key Skills required:** * 3years - 7 years. * Experience in configuring, installing, and integrating Tenable.sc. * Conduct testing and validation after Tenable.sc migration to ensure accurate vulnerability scanning and reporting. * Conduct Vulnerability Assessment (VA) for servers, Network devices, databases, security devices, Active directory and End points on Monthly Basis. * Conduct Vulnerability assessment for open-source components such as Redis, kafka, Kubernetes, Jenkins, etc. * Automate Vulnerability assessment processes to improve TAT. * Publish report with findings, Impact, severity, trend analysis and recommendations. * Closely work with SOC / Incident response and Threat hunting teams on vulnerability identification and remediation. * Work with patch management team to identify Information like missing patches, confirmation of certain potential vulnerabilities. * Perform Manual assessments to eliminate false positive. * Publish Dashboard having details of Vulnerability along with Severity and ageing status along with EPSS scores. * Perform rescans after patch management process. * Technical assistance to handle both internal and external audit. * Basic level of understating of logs of various devices for performing VAPT and Configuration Audit/Assessment (CA) activity * Assistance and preparation of advisory / and tracking of Critical and High vulnerabilities Threat feeds. * Education: Bachelor's degree in information security, Computer Science, or a related field. A master's in business management is preferred. * Location: Hyderabad, Mumbai