Consultant - Manager| Cyber Operate | Vulnerability Management Specialist | KSA
Deloitte Middle East · Riyadh, Saudi Arabia · 1d ago
ManagerOn-siteTechnology & Digital Consulting
Our Purpose
- Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most—for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.
- Our shared values guide the way we behave to make a positive, enduring impact:
Conduct vulnerability assessments
- Networks: plan and run authenticated and unauthenticated assessments across corporate, data-Center, DMZ, wireless, guest-facing and partner-connected networks, including internal and internet-facing perimeter assessments
- Cloud platforms: assess Azure, AWS and GCP environments, covering workloads, configuration and identity settings against CIS benchmarks and NCA CCC, and scan container images and Kubernetes clusters
- Systems: assess Windows and Linux servers, endpoints, databases, virtualisation platforms, and network and security devices, including configuration and hardening checks against approved baselines
- Applications: assess web applications, APIs and mobile app back-ends with authenticated DAST scanning, working with the Application Security team on in-depth testing
- Assess new systems before go-live and after major changes, and run targeted assessments on request
- Produce clear assessment reports with risk-rated findings, evidence and practical remediation steps for each asset owner
- Operate and tune scanning platforms (e.g. Tenable, Qualys, Rapid7), including scan policies, credentials, schedules and agents
- Keep scan coverage aligned with the asset inventory and CMDB, and find and close blind spots, including new and unmanaged assets
- Work with the OT team on safe, approved methods for assessing industrial and building systems
- Prioritize what matters
- Prioritize vulnerabilities using CVSS, EPSS, CISA KEV, asset criticality, exposure and threat intelligence, so teams fix the riskiest issues first rather than chasing volume
- Validate critical findings and filter out false positives before they reach IT teams
- Track emerging threats and zero-days; run rapid exposure checks and issue clear advisories
- Agree remediation plans and deadlines with IT, cloud and application owners, and follow them through to closure with persistence and good working relationships
- Verify fixes by rescanning, and manage the exception and risk-acceptance process with proper justification and expiry dates
- Govern patch management in line with NIST SP 800-40, working with the infrastructure teams
- Define the vulnerability management policy, procedure, scan schedules and remediation SLAs in line with NCA ECC
- Build dashboards and KPIs (SLA compliance, ageing, coverage, risk trend), and produce monthly reports for management
- Automate scanning, ticketing and reporting where possible (e.g. Python, APIs, ServiceNow integration)
- Share findings with the Penetration Testing, SOC and Risk teams so the overall risk picture stays current
- Builds own understanding of our purpose and values; explores opportunities for impact.
- Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
- Understands expectations and demonstrates personal accountability for keeping performance on track.
- Actively focuses on developing effective communication and relationship-building skills.
- Understands how their daily work contributes to the priorities of the team and the business.
- Years of experience: 4-8 years in total with hands-on vulnerability assessment and management experience
- Bachelor's in IT, cybersecurity or a related field
- Practical experience with at least one enterprise scanner (Tenable, Qualys or Rapid7)
- Has assessed at least two of: on-premise networks and systems, cloud platforms, web applications and APIs
- Solid Windows, Linux, network and cloud fundamentals; understands CVSS and EPSS scoring
- Knowledge of NCA ECC vulnerability management requirements
- Scripting in Python or PowerShell for automation and reporting is preferred.
- Experience with ITSM tools (ServiceNow, Jira) for remediation workflows is preferred.
- Experience with cloud security posture (CSPM) or container scanning tools (e.g. Wiz, Prisma Cloud, Defender for Cloud) is preferred.
- Arabic Language is preferred.
- At least one preferred: CompTIA Security+, CySA+, CEH. Also valued: GIAC (GSEC, GCIH), and Tenable or Qualys vendor certifications.
- Frameworks and Standards: NCA ECC-2:2024 · NCA CCC · NIST SP 800-40 Rev 4 · NIST SP 800-115 · NIST CSF 2.0 · ISO/IEC 27001:2022 (A.8.8) · CIS Controls v8 · CIS Benchmark