Manager – Red Team Specialist | Offensive Security | Cybersecurity Manager | Mumbai | Deloitte India

Job Description

Summary

Are you an experienced Red Team Specialist or Offensive Security Manager with a passion for cybersecurity and hands-on expertise in conducting advanced Red Team engagements? Deloitte India is hiring a Cybersecurity Manager in Mumbai to lead simulated cyber-attacks, testing client defenses and enhancing security posture, particularly within the BFSI (Banking, Financial Services, and Insurance) sector. This role involves offensive security operations including penetration testing, threat emulation, vulnerability exploitation, and collaboration with Blue Teams to boost detection and response. If you have strong skills in Red Team operations, MITRE ATT&CK framework, Active Directory attacks, and CART/BAS platforms like Cymulate or Pycus, this is your chance to drive impactful cyber risk management at a global leader.


Job Details at a Glance

Job TitleManager – Red Team Specialist / Offensive Security Manager
LocationMumbai, Maharashtra, India
Employment TypeFull-time, Work From Office
Experience Required8-12 years in Offensive Security, Red Teaming
IndustryBFSI (Banking, Financial Services, Insurance)
Key SkillsRed Teaming, Offensive Security, Penetration Testing, MITRE ATT&CK, Active Directory Attacks, CART/BAS Tools (Cymulate, Pycus), Vulnerability Assessment, Phishing, Social Engineering, Threat Emulation
Certifications PreferredOSCP, CRTP, or Equivalent Offensive Security Certifications
Tools ExposureCymulate, Pycus, Cobalt Strike, Metasploit, Empire, Covenant
ShiftDay Shift

Key Responsibilities

  • Lead and execute Red Team engagements simulating advanced threat actor scenarios including external, internal, and physical attacks.
  • Conduct assumed breach assessments, initial access simulations, lateral movement, and data exfiltration exercises.
  • Design threat scenarios using the MITRE ATT&CK framework and map findings to improve client security postures.
  • Exploit vulnerabilities in Active Directory, cloud environments, and enterprise infrastructure.
  • Utilize and integrate CART/BAS platforms (e.g., Cymulate, Pycus) to automate attack simulations and validate security controls.
  • Collaborate with Blue Teams to assess and enhance detection, prevention, and incident response capabilities.
  • Prepare detailed, actionable Red Team reports with remediation guidance for technical and executive audiences.
  • Perform threat emulation based on industry-specific APT (Advanced Persistent Threat) groups, especially targeting BFSI clients.
  • Stay updated on emerging cyber threats, attack techniques, and defense strategies.
  • Support security awareness programs, purple teaming exercises, and client tabletop simulations.

Required Skills & Experience

  • Minimum 8-12 years of experience in offensive security, Red Team operations, or penetration testing roles.
  • Expertise in Red Team TTPs: phishing, command & control (C2) infrastructure, evasion tactics, privilege escalation, and data exfiltration.
  • Deep understanding of Windows internals and Active Directory attack vectors (Kerberoasting, Pass-the-Hash, ACL abuse, DCShadow).
  • Proficient in network protocols, cloud security, endpoint bypass techniques, and social engineering tactics.
  • Experience with security simulation tools such as Cobalt Strike, Metasploit, Empire, Covenant, and scripting for custom exploits.
  • Knowledge of physical security testing, including badge cloning, RFID/NFC exploitation (preferred).
  • Strong familiarity with MITRE ATT&CK, NIST frameworks, and cybersecurity best practices.
  • Ability to produce clear, concise documentation and communicate complex findings effectively to technical teams and leadership.

Preferred Qualifications

  • Offensive security certifications such as OSCP, CRTP, or equivalent.
  • Prior experience working with clients in the BFSI sector.
  • Knowledge of regulatory compliance frameworks applicable to financial institutions (RBI, SEBI, ISO 27001).

Education

  • Bachelor’s or Master’s degree in Computer Science, Information Technology, Cybersecurity, or related fields from Tier 1/2 institutes.

Why Work at Deloitte?

  • Join a globally recognized leader committed to cybersecurity innovation and risk management.
  • Collaborate with diverse teams solving complex cyber threats for high-profile BFSI clients.
  • Experience continuous growth with access to advanced training, certifications, and leadership development.
  • Thrive in a dynamic, supportive work environment that values inclusion, integrity, and purpose-driven impact.
  • Enjoy a full-time, office-based role in Mumbai with opportunities for cross-business mobility.

Apply Now

Ready to take the next big step in your cybersecurity career? Join Deloitte as a Manager in Red Teaming and Offensive Security and contribute to protecting critical assets from emerging cyber threats.

👉 Apply now on Deloitte’s Official Careers Page