Job Description
โ Summary
Join Deloitte India as a Deputy Manager โ Red Teaming & Vulnerability Assessment & Penetration Testing (VAPT) in Mumbai and become a key player in offensive security operations. In this role, youโll simulate sophisticated cyberattacks, emulate advanced persistent threats (APTs), and uncover system vulnerabilities across client environmentsโespecially in the BFSI sector.
This position is perfect for cybersecurity professionals with deep expertise in Red Team operations, threat emulation, penetration testing, and advanced attack techniques using industry frameworks like MITRE ATT&CK. If you’re passionate about hands-on offensive security and ready to challenge detection and response strategies in enterprise environments, this is the opportunity for you.
๐ Job Details at a Glance
| Job Title | Deputy Manager โ Red Teaming & VAPT |
|---|---|
| Location | Mumbai, India |
| Department | Cyber Risk |
| Experience Required | 5 โ 8 years in Red Teaming / Offensive Security |
| Industry Focus | BFSI (Banking, Financial Services, Insurance) |
| Work Type | Full-Time |
| Primary Tools/Platforms | Cymulate, Pycus, Cobalt Strike, Metasploit, etc. |
| Certifications (Preferred) | OSCP, CRTP, or equivalent |
| Entity | Deloitte Touche Tohmatsu India LLP |
๐ About the Role
As a Deputy Manager โ Cybersecurity, you will lead Red Team engagements, simulate real-world cyberattack scenarios, and assess clients’ cyber resilience. You will work closely with Blue Teams to identify detection gaps, collaborate on Purple Teaming, and provide remediation strategies aligned with security frameworks such as MITRE ATT&CK, NIST, and ISO 27001.
๐ผ Key Responsibilities
- Plan and execute Red Team simulations involving external, internal, and physical attack vectors.
- Conduct assumed breach assessments, lateral movement, and data exfiltration exercises.
- Utilize tools such as Cymulate, Pycus, or equivalent CART/BAS platforms.
- Exploit misconfigurations in Active Directory, cloud infrastructure, and endpoints.
- Leverage MITRE ATT&CK framework to design and document threat scenarios.
- Create detailed reports with technical findings, risk mapping, and remediation steps.
- Perform APT simulations tailored to the BFSI sector.
- Collaborate with Blue Teams and participate in Purple Team and tabletop exercises.
- Stay current with emerging threats, vulnerabilities, and exploitation tactics.
๐ ๏ธ Required Skills & Experience
- 5โ8 years of Red Teaming / Penetration Testing experience in enterprise environments.
- Proficiency in:
- TTPs: phishing, C2 infrastructure, evasion, privilege escalation
- Active Directory attack techniques (Pass-the-Hash, Kerberoasting, DCShadow, etc.)
- Cloud and endpoint security bypass methods
- Familiarity with open-source and commercial frameworks like:
- Cobalt Strike, Metasploit, Empire, Covenant
- Solid knowledge of:
- MITRE ATT&CK, NIST, ISO 27001
- Network protocols, Windows internals, RFID/NFC exploitation (preferred)
๐ Preferred Qualifications
- Bachelorโs degree (B.E/B.Tech) in Computer Science, Information Technology, or related field (Tier 1/2 institute preferred)
- Offensive security certifications such as:
- OSCP, CRTP, CRTO
- BFSI industry experience or familiarity with RBI/SEBI compliance standards
โญ What Makes You a Strong Fit
- Excellent analytical and problem-solving abilities
- Strong written and verbal communication skills
- Ability to document technical findings and present to diverse stakeholders
- Comfortable working in high-pressure environments
- Team-oriented with cross-functional coordination experience
๐ Why Join Deloitte India?
- Be part of a globally recognized cybersecurity practice
- Access to cutting-edge tools and enterprise clients
- Collaborate on large-scale Red Teaming and Cyber Defense projects
- Grow your skills with ongoing training, mentorship, and career mobility
- Inclusive, impact-driven, and people-first work culture
๐ฅ Apply Now
Are you ready to elevate your cybersecurity career?
๐ Click here to apply directly on Deloitte Careers
Donโt miss the chance to work on elite offensive security engagements with Deloitteโs Cyber team.