Continuous Threat Exposure Management (ctem) Manager

This role is for a Continuous Threat Exposure Management (CTEM) Manager at Deloitte. The primary focus is on cybersecurity, specifically managing and reducing an organization's attack surface and cyber risk through vulnerability and patch management. While the role mentions foundational knowledge of AI and LLM concepts, AI/ML is not the core craft or a primary deliverable.

What you'd actually do

  1. Execute exposure-based patching and automation aligned to CTEM priorities
  2. Lead teams and build trusted client relationships through high-quality delivery
  3. Oversee end-to-end patching operations, including deployment and maintenance of vulnerability and patch management tools across technologies and lifecycle phases
  4. Provide technical guidance across vulnerability management, patching, exception management, and reporting
  5. Identify opportunities to improve efficiency, reduce risk, and enhance threat visibility

Skills

Required

  • information technology
  • information security
  • service delivery teams
  • vulnerability management
  • patch management
  • CTEM remediation lifecycle
  • remediating vulnerabilities
  • patch management tools (BigFix, SCCM/MECM, Red Hat Satellite, WSUS)
  • vulnerability management tools (Tenable, Rapid7, Qualys)
  • PowerShell
  • Bash
  • Python
  • JSON
  • Ansible
  • Terraform
  • orchestration tools
  • remediation validation
  • remediation blockers
  • patch windows
  • patch procedures
  • runbooks
  • exception processes
  • KPI reporting
  • CVSS
  • exploitability
  • exposure context
  • defense-in-depth
  • least privilege
  • security architecture
  • threat modeling
  • Linux patching
  • Windows patching
  • ITSM platforms (ServiceNow)
  • CMDB platforms (ServiceNow)

Nice to have

  • AI and LLM concepts

What the JD emphasized

  • 10+ years of experience in information technology and/or information security
  • Demonstrated ability to plan, design, deploy, operationalize, and lead secure, scalable vulnerability and patch management programs from strategy through execution
  • Experience owning the end-to-end CTEM remediation lifecycle, including exposure identification, prioritization, patch execution, validation, and reporting
  • Hands-on experience remediating vulnerabilities across operating systems, middleware, and applications, including critical exposures such as zero-days, KEVs, and externally exposed assets
  • Experience leading continuous patching operations aligned to real-time threat conditions, including emergency response for active threats and exploitation campaigns