06 Aug
|
Deloitte Shared Services India
|
Mumbai
06 Aug
Deloitte Shared Services India
Mumbai
Role & responsibilities
- 3 years - 7 years.
- Should have hand on experience on Tenable.sc.
- Experience in configuring, installing, and integrating Tenable.sc.
- Conduct testing and validation after Tenable.sc migration to ensure accurate vulnerability scanning and reporting.
- Conduct Vulnerability Assessment (VA) for servers, Network devices, databases, security devices, Active directory and End points on Monthly Basis.
- Conduct Vulnerability assessment for open-source components such as Redis, kafka, Kubernetes, Jenkins, etc.
- Automate Vulnerability assessment processes to improve TAT.
- Publish report with findings, Impact, severity, trend analysis and recommendations.
- Closely work with SOC / Incident response and Threat hunting teams on vulnerability identification and remediation.
- Work with patch management team to identify Information like missing patches, confirmation of certain potential vulnerabilities.
- Perform Manual assessments to eliminate false positive.
- Publish Dashboard having details of Vulnerability along with Severity and ageing status along with EPSS scores.
- Perform rescans after patch management process.
- Technical assistance to handle both internal and external audit.
- Basic level of understating of logs of various devices for performing VAPT and Configuration Audit/Assessment (CA) activity
- Assistance and preparation of advisory / and tracking of Critical and High vulnerabilities Threat feeds.
- Education: Bachelors degree in information security, Computer Science, or a related field. A masters in business management is preferred.
- Location: Hyderabad, Mumbai
Preferred candidate profile
- Perform external penetration testing which includes, Public IP ranges, Web applications and API's, VPN GW's, exposed services, Firewall and Perimeter devices focusing on Authentication bypass, SSL/TLS configuration review, Misconfiguration and exposure assessment and network reconnaissance which includes Port Scanning / Service Enumeration.
- Perform Internal penetration testing which includes, Servers (Linux / Windows), Active directory, Network devices, Internal applications, Database services focusing on Privilege escalation, Lateral movement, Weak authentication protocols, Credential harvesting and network segmentation validation.
📌 VAPT - Tenable.Sc | Consultant / AM (Mumbai)
🏢 Deloitte Shared Services India
📍 Mumbai