About the Role
Leverage your passion for cybersecurity and people to help clients address key cyber risks and design cybersecurity solutions to protect critical information assets through offensive security services. Engage at all levels of an organisation in relation to the cyber risk agenda. Coordinate a diverse and driven team to assist organisations with a wide range of offensive security services, sometimes in collaboration with the broader Cyber team. Lead teams to deliver offensive security projects and contribute to the culture of learning and impact within our cyber risk practice.
Responsibilities
- Design cybersecurity solutions to protect critical information assets through offensive security services.
- Engage at all levels of an organisation in relation to the cyber risk agenda.
- Coordinate a diverse and driven team to assist organisations with a wide range of offensive security services.
- Collaborate with the broader Cyber team on services such as cyber security strategy, threat and risk assessment, security design and implementation of solutions.
- Lead teams to deliver offensive security projects.
- Contribute to the culture of learning and impact within our cyber risk practice.
- Improve security posture of clients from people, process, and technology perspective.
- Understand a client’s cyber posture, perform gap analysis, understand the regulatory & legal frameworks, prioritise offensive security services and know when to bring others into the conversation.
- Think like a threat actor, understand threat actors TTPs and mobilise a team to simulate the threat actor in a client’s environment.
- Think like a business executive, manage security team members and communicate effectively with key stakeholders.
- Develop relationships with key cyber focussed executives within client or potential client organisations as well as the local cyber community.
- Understand the client’s offensive security requirements, accurately scope the testing, price the testing appropriately, pull together an engagement team with the right skills, oversee delivery of the engagement, perform QA of the deliverable, close out the engagement internally and with the client.
- Utilise emerging technologies and tooling to deliver best of breed offensive security services to maximise value to our clients.
- Consult to build security best practices.
- Implement security measures to meet business goals, customer needs and regulatory requirements.
- Assist with business development through your relationships with clients and the ability to provide compelling business proposals.
- Identify risks associated with business processes, operations, technology projects and information security programs.
- Develop project timelines that prioritise changes that provide greatest impact.
- Drive appropriate security policies and procedure development.
- Lead and mentor a team and coach them to upscale their skills.
- Engage with stakeholders effectively at all levels of the organisation.
Requirements
- 10-15 years of experience in penetration testing, red teaming, cyber incident detection and response, leading cyber transformation initiatives, managing cyber security functions or cyber risk consulting.
- Proven ability to improve security posture of clients from people, process, and technology perspective.
- The ability to understand a client’s cyber posture, perform gap analysis, understand the regulatory & legal frameworks, prioritise offensive security services and know when to bring others into the conversation.
- The ability to think like a threat actor, understand threat actors TTPs and mobilise a team to simulate the threat actor in a client’s environment.
- The ability to think like a business executive, manage security team members and communicate effectively with key stakeholders.
- Develop relationships with key cyber focussed executives within client or potential client organisations as well as the local cyber community.
- The experience and technical expertise to understand the client’s offensive security requirements, accurately scope the testing, price the testing appropriately, pull together an engagement team with the right skills, oversee delivery of the engagement, perform QA of the deliverable, close out the engagement internally and with the client.
- Utilise emerging technologies and tooling to deliver best of breed offensive security services to maximise value to our clients.
- Consulting to build security best practices; implementation of security measures to meet business goals, customer needs and regulatory requirements.
- Assist with business development through your relationships with clients and the ability to provide compelling business proposals.
- Demonstrated ability to identify risks associated with business processes, operations, technology projects and information security programs.
- Ability to develop project timelines that prioritise changes that provide greatest impact.
- Skills to drive appropriate security policies and procedure development.
- Experience or knowledge of industry frameworks such as PCI DSS, ISO27001, NIST and APRA Standards.
- Experience in leading / mentoring a team and coaching them to upscale their skills.
- Proven ability to engage with stakeholders effectively at all levels of the organisation.
- Big 4 consulting experience looked upon favourably.
Skills
- Cybersecurity
- Offensive security services
- Strategic thinking
- Communication
- Interpersonal skills
- Penetration testing
- Red teaming
- Cyber incident detection and response
- Cyber transformation
- Cyber risk consulting
- Threat and risk assessment
- Security design
- Implementation of solutions
- Threat actor TTPs simulation
- Stakeholder management
- Business development
- Risk identification
- Project timeline development
- Security policy development
- Security procedure development
- PCI DSS
- ISO27001
- NIST
- APRA Standards
- Team leadership
- Mentoring
- Coaching
- Emerging technologies
- Tooling
Work Type
- Hybrid
Experience Level
- 10-15 years of experience
Education Level
- CISSP
- CISM
- OSCP
- OSEP
- SANS or similar certifications
Benefits
- MyBenefits platform for retail, tech, and travel discounts
- Reimbursements for professional development
- Subsidised qualifications
- Retail discounts
- Wellbeing leave
- Paid volunteering days
- Twelve flexible working options
- Market-leading parental leave
- Return to work support package
About the Company
- Positioned first globally in Security Consulting Services for the 7th year in a row.
- The cyberspace is constantly evolving and so are the threats that it brings.
- We predict risks and safeguard our clients through end-to-end solutions.
- We help clients unlock new opportunities through safer and more secure systems and policies.
- We focus our energy on interesting and impactful work.
- We’re always learning, innovating and setting the standard; making a positive difference to our clients and our society.
- We put coaching at the heart of what we do, helping our people grow their careers in any direction.
- We embrace diversity, equity and inclusion.
- We have a diverse collection of people from different backgrounds, with different experiences, gender identities, abilities and thinking styles.
- We value everyone’s perspective and cultivate inclusion.
- We value in-person connection with our clients and our colleagues.
- We offer several ways for you to work flexibly so that you can serve your clients, stay connected with your team, and manage your personal priorities.
- We help you live and work well.
Equal Opportunity
- By applying for this job, you’ll be assessed against the Deloitte Talent Standards.
- The preferred candidate will be subject to background screening by Deloitte or by their external third-party provider.
