Consultant - Manager| Cyber Operate | Vulnerability Management Specialist | KSA

Deloitte Development LLC

Riyadh

On-site

SAR 260,000 - 420,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this recruiter — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Deloitte Development LLC in Saudi Arabia seeks a Consultant - Manager to lead Cyber Operate with a focus on Vulnerability Management. You will oversee vulnerability assessments across networks, cloud, systems and applications, administer scanning platforms (Tenable, Qualys, Rapid7), and drive risk-based remediation with asset owners.

Bring 4–8 years of hands-on experience, a degree in IT/cybersecurity, and familiarity with CSPM and industry standards.

Qualifications

  • 4–8 years of hands-on vulnerability assessment and management experience.
  • Bachelor's in IT, cybersecurity or a related field.
  • Practical experience with at least one enterprise scanner (Tenable, Qualys or Rapid7).
  • Experience assessing on-premise networks, cloud platforms, web apps and APIs.
  • Solid Windows, Linux, networks, cloud fundamentals; understands CVSS/EPSS.

Responsibilities

  • Conduct vulnerability assessments across networks, cloud, systems, and applications.
  • Operate and tune scanning platforms (Tenable, Qualys, Rapid7) and manage policies, credentials, schedules, and agents.
  • Prioritize vulnerabilities using CVSS, EPSS, CISA KEV, asset criticality and threat intel.

Skills

Vulnerability assessment
Risk analysis
Security monitoring
Python scripting

Education

Bachelor's in IT or cybersecurity

Tools

Tenable
Qualys
Rapid7
ServiceNow
Jira

Job description

Consultant - Manager| Cyber Operate | Vulnerability Management Specialist | KSA

About Deloitte : When you work for us, you commit to a career at one of the largest and most prestigious professional services firms in the world. We have received numerous awards over the last few years, including Best Employer in the Middle East, and Best Consulting Firm, and the Middle East Training & Development Excellence Award.

Our Purpose

  • Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most- for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.
  • Our shared values guide the way we behave to make a positive, enduring impact:

During your tenure as a Consultant - Manager, you will demonstrate and develop your capabilities in the following areas.

Conduct vulnerability assessments

  • Networks: plan and run authenticated and unauthenticated assessments across corporate, data-Center, DMZ, wireless, guest-facing and partner-connected networks, including internal and internet-facing perimeter assessments
  • Cloud platforms: assess Azure, AWS and GCP environments, covering workloads, configuration and identity settings against CIS benchmarks and NCA CCC, and scan container images and Kubernetes clusters
  • Systems: assess Windows and Linux servers, endpoints, databases, virtualisation platforms, and network and security devices, including configuration and hardening checks against approved baselines
  • Applications: assess web applications, APIs and mobile app back-ends with authenticated DAST scanning, working with the Application Security team on in-depth testing
  • Assess new systems before go-live and after major changes, and run targeted assessments on request
  • Produce clear assessment reports with risk-rated findings, evidence and practical remediation steps for each asset owner

Run tooling and coverage

  • Operate and tune scanning platforms (e.g. Tenable, Qualys, Rapid7), including scan policies, credentials, schedules and agents
  • Keep scan coverage aligned with the asset inventory and CMDB, and find and close blind spots, including new and unmanaged assets
  • Work with the OT team on safe, approved methods for assessing industrial and building systems
  • Prioritize what matters
  • Prioritize vulnerabilities using CVSS, EPSS, CISA KEV, asset criticality, exposure and threat intelligence, so teams fix the riskiest issues first rather than chasing volume
  • Validate critical findings and filter out false positives before they reach IT teams
  • Track emerging threats and zero-days; run rapid exposure checks and issue clear advisories

Drive remediation

  • Agree remediation plans and deadlines with IT, cloud and application owners, and follow them through to closure with persistence and good working relationships
  • Verify fixes by rescanning, and manage the exception and risk-acceptance process with proper justification and expiry dates
  • Govern patch management in line with NIST SP 800-40, working with the infrastructure teams

Set up the programme and report on it

  • Define the vulnerability management policy, procedure, scan schedules and remediation SLAs in line with NCA ECC
  • Build dashboards and KPIs (SLA compliance, ageing, coverage, risk trend), and produce monthly reports for management
  • Automate scanning, ticketing and reporting where possible (e.g. Python, APIs, ServiceNow integration)
  • Share findings with the Penetration Testing, SOC and Risk teams so the overall risk picture stays current

Leadership Capabilities:

  • Builds own understanding of our purpose and values; explores opportunities for impact.
  • Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
  • Understands expectations and demonstrates personal accountability for keeping performance on track.
  • Actively focuses on developing effective communication and relationship-building skills.
  • Understands how their daily work contributes to the priorities of the team and the business.

Qualifications:

  • Years of experience: 4-8 years in total with hands-on vulnerability assessment and management experience
  • Bachelor's in IT, cybersecurity or a related field
  • Practical experience with at least one enterprise scanner (Tenable, Qualys or Rapid7)
  • Has assessed at least two of: on-premise networks and systems, cloud platforms, web applications and APIs
  • Solid Windows, Linux, network and cloud fundamentals; understands CVSS and EPSS scoring
  • Knowledge of NCA ECC vulnerability management requirements
  • Scripting in Python or PowerShell for automation and reporting is preferred.
  • Experience with ITSM tools (ServiceNow, Jira) for remediation workflows is preferred.
  • Experience with cloud security posture (CSPM) or container scanning tools (e.g. Wiz, Prisma Cloud, Defender for Cloud) is preferred.
  • Arabic Language is preferred.
  • At least one preferred: CompTIA Security+, CySA+, CEH. Also valued: GIAC (GSEC, GCIH), and Tenable or Qualys vendor certifications.
  • Frameworks and Standards: NCA ECC-2:2024 · NCA CCC · NIST SP 800-40 Rev 4 · NIST SP 800-115 · NIST CSF 2.0 · ISO/IEC 27001:2022 (A.8.8) · CIS Controls v8 · CIS Benchmark
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Consultant – Manager| Cyber Operate | Application Security Specialist | KSA
Senior Consultant – Manager| Cyber Operate | Application Security Specialist | KSA

Deloitte Development LLC • Riyadh

On-site
SAR 260,000 - 420,000
Consultant – Manager| Cyber Operate | Cybersecurity Risk Specialist | KSA
Consultant – Manager| Cyber Operate | Cybersecurity Risk Specialist | KSA

Deloitte Development LLC • Riyadh

On-site
SAR 300,000 - 520,000
Senior Consultant – Senior Manager| Cyber Operate | Security Architecture | KSA
Senior Consultant – Senior Manager| Cyber Operate | Security Architecture | KSA

Deloitte Development LLC • Riyadh

On-site
SAR 350,000 - 600,000
Senior Consultant/ Manager| Cyber Operate | Governance & PMO Specialist |KSA
Senior Consultant/ Manager| Cyber Operate | Governance & PMO Specialist |KSA

Deloitte Development LLC • Riyadh

On-site
SAR 300,000 - 520,000
Senior Cyber Vulnerability Manager: Cloud, Apps & Networks
Senior Cyber Vulnerability Manager: Cloud, Apps & Networks

Deloitte Development LLC • Riyadh

On-site
SAR 260,000 - 420,000
Senior Consultant – Senior Manager| Cyber Operate | OT Security Specialist| KSA
Senior Consultant – Senior Manager| Cyber Operate | OT Security Specialist| KSA

Deloitte Development LLC • Riyadh

On-site
SAR 300,000 - 460,000
Cyber Security Defense Senior Specialist
Cyber Security Defense Senior Specialist

Alfalak Electronic Equipment & Supplies Co. • Saudi Arabia

On-site
SAR 300,000 - 520,000
Cybersecurity Manager - Metro
Cybersecurity Manager - Metro

Egis • Riyadh

On-site
SAR 300,000 - 550,000
Cybersecurity Assurance Specialist
Cybersecurity Assurance Specialist

Cloud Consultancy - CCDS • Riyadh

On-site
SAR 180,000 - 300,000
Security Managed Services Specialist
Security Managed Services Specialist

Accenture Middle East • Riyadh

On-site
SAR 180,000 - 300,000