HamburgerMenu
hirist

Deloitte - Assistant Manager/Deputy Manager - Vulnerability Management

Deloitte
3 - 8 Years
Multiple Locations

Posted on: 07/07/2026

Job Description

Job Description :

Role & Responsibilities :

Vulnerability Management (VulnOps) :

- Analyze, prioritize, and track security vulnerabilities identified across applications, APIs, cloud environments, operating systems, databases, and infrastructure components.

- Correlate vulnerability findings with active threats, attack patterns, threat intelligence, and security monitoring data.

- Assess vulnerability exploitability, business impact, and remediation priorities.

- Validate remediation efforts through retesting and verification activities.

- Perform root cause analysis (RCA) for recurring vulnerabilities and security issues.

- Maintain end-to-end vulnerability lifecycle management, including :

1. Discovery

2. Assessment

3. Triage

4. Prioritization

5. Remediation

6. Validation

7. Closure tracking

- Generate vulnerability reports, dashboards, metrics, and risk summaries for stakeholders.

- Collaborate with application development, infrastructure, DevOps, and cloud teams to drive timely remediation and secure configurations.

WAF Monitoring & Threat Investigation :

- Monitor and investigate Web Application Firewall (WAF) alerts and events for real-time threat detection and response.

- Analyze HTTP requests and responses, headers, parameters, payloads, session information, and user behavior patterns.

- Investigate and respond to web-based attacks including :

1. SQL Injection (SQLi)

2. Cross-Site Scripting (XSS)

3. Command Injection

4. Local/Remote File Inclusion

5. API Abuse

6. Credential Stuffing

7. Bot Attacks

8. Directory Traversal

9. Web Scanning Activities

10. OWASP Top 10 attack patterns

- Correlate WAF alerts with the below by collaborating with different teams :

1. SIEM events

2. Application logs

3. Infrastructure logs

4. Threat intelligence feeds

5. Endpoint security alerts

- Identify false positives and false negatives and recommend rule optimization.

- Support incident response activities involving web application security events.

- Recommend and implement WAF rule tuning, custom signatures, and policy enhancements.

Preferred Candidate Profile :

- Strong understanding of Web Application Security concepts and OWASP Top 10.

- Experience working with WAF technologies such as :

1. F5 ASM/AWAF

2. Imperva

3. Akamai Kona

- Knowledge of HTTP/HTTPS protocols, REST APIs, web application architecture, and authentication mechanisms.

- Understanding of common web application attack techniques and threat actor methodologies.

- Familiarity with CVSS scoring, vulnerability prioritization, and risk assessment methodologies.

- Ability to perform log analysis, attack investigation, and threat correlation.

- Experience working with development and DevOps teams in remediation activities.

Preferred Skills :

- Hands-on experience with Burp Suite, OWASP ZAP, Postman, or similar tools.

- Knowledge of WAF and cloud security (AWS, Azure, GCP).

- Familiarity with threat intelligence platforms and ATT&CK framework.

- Understanding of CI/CD security practices and secure SDLC.

Qualifications :

- Bachelor's degree in Computer Science, Information Security, Cybersecurity, Engineering, or related field.

- 3 - 8 years of experience in Application Security, Vulnerability Management, Threat Detection, or WAF Operations.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...