Senior Manager - Asm Vulnerability Management

This role is for a Senior Manager in Vulnerability Management within Deloitte's Cyber Defense & Resilience team. The focus is on leading teams to identify, assess, and reduce cyber risk and attack surface for clients through exposure-based remediation and patching programs. Responsibilities include overseeing vulnerability and patch management operations, prioritizing remediation using threat intelligence, and guiding clients through exception management and process improvements. The role requires experience in IT security, leading vulnerability management programs, remediating vulnerabilities across various systems, and automating workflows using scripting languages. Experience with ITSM platforms like ServiceNow is also required.

What you'd actually do

  1. Leading teams delivering exposure-based remediation and patching programs aligned to CTEM priorities
  2. Overseeing end-to-end vulnerability and patch management operations, including deployment, maintenance, and reporting across technologies and lifecycle phases
  3. Prioritizing and coordinating remediation using threat intelligence, exploitability, attack paths, asset criticality, and exposure data
  4. Guiding clients through exception management, emergency response, and process improvements that reduce risk and enhance threat visibility
  5. Developing client deliverables, supporting proposals and points of view, and mentoring junior practitioners while driving quality delivery

Skills

Required

  • Information technology
  • Information security
  • Vulnerability management
  • Patch management
  • Continuous Threat Exposure Management (CTEM)
  • Remediation programs
  • Linux
  • Windows
  • Middleware
  • Applications
  • BigFix
  • Microsoft Endpoint Configuration Manager (MECM)
  • Red Hat Satellite
  • Windows Server Update Services (WSUS)
  • Tenable
  • Rapid7
  • Qualys
  • PowerShell
  • Bash
  • Python
  • JSON
  • Ansible
  • Terraform
  • Information Technology Service Management (ITSM)
  • Configuration management database (CMDB)
  • ServiceNow

Nice to have

  • Consulting environment
  • Big 4 firm
  • ServiceNow workflows, automation, or orchestration
  • National Institute of Standards and Technology Cybersecurity Framework (NIST CSF)
  • Center for Internet Security (CIS)
  • International Organization for Standardization 27001 (ISO 27001)
  • Cloud Security Alliance Cloud Controls Matrix (CSA CCM)
  • Proposals
  • Statements of work
  • Work orders

What the JD emphasized

  • 10+ years of experience in information technology, information security, or both
  • Experience leading vulnerability management, patch management, or continuous threat exposure management (CTEM) remediation programs from strategy through execution
  • Experience remediating vulnerabilities across Linux, Windows, middleware, and applications using tools such as BigFix, Microsoft Endpoint Configuration Manager (MECM), Red Hat Satellite, Windows Server Update Services (WSUS), Tenable, Rapid7, or Qualys
  • Experience automating remediation workflows using PowerShell, Bash, Python, JSON, Ansible, Terraform, or a combination of these
  • Experience using Information Technology Service Management (ITSM) or configuration management database (CMDB) platforms such as ServiceNow to coordinate remediation and report exposure reduction
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.