Senior Executive | Risk Management | Pune | Cyber Strategy & Transformation
Deloitte
Deloitte
Join our dynamic Cyber Strategy & Transformation team in Pune as a Senior Executive in Risk Management. We empower organizations to proactively prevent cyberattacks and safeguard critical assets. Our approach emphasizes security, vigilance, and resilience, integrating cyber risk management into strategic development for effective information and technology risk mitigation. Explore how we help unleash new opportunities through robust cybersecurity.
This role focuses on the critical task of validating security controls and remediation efforts implemented by Development and DevOps teams. You'll ensure that vulnerabilities are effectively addressed, and applications consistently meet Secure SDLC and compliance standards.
Key responsibilities include validating security controls and vulnerability remediations across diverse applications and cloud environments.
You will verify essential security mechanisms such as authentication, authorization (RBAC/ABAC), input validation, secure configurations, and API security.
Re-testing identified vulnerabilities and confirming the effectiveness of remediation using comprehensive testing scenarios is crucial. Additionally, perform security regression testing to guarantee that implemented fixes do not introduce new risks.
Review and validate findings from SAST, DAST, SCA, and Threat Modeling activities. Collaborate closely with Development, DevOps, Security, and QA teams throughout the Secure SDLC lifecycle.
Maintain meticulous records of security testing evidence, detailed reports, and accurate vulnerability tracking.
We seek a hands-on Application Security/DevSecOps professional with proven experience in security control verification, remediation validation, and secure application delivery. The ideal candidate will be adept at partnering with engineering teams to significantly strengthen the overall security posture of our systems.
Core skills encompass Secure SDLC, understanding OWASP Top 10, Threat Modeling, Application Security Controls, DevSecOps Practices, and Vulnerability Management.
Expertise in Security Testing is essential, including SAST, DAST, SCA Validation, Security Control Verification, Remediation Testing & Validation, and REST API Security Testing.
Familiarity with tools and technologies such as SonarQube, Coverity, Black Duck, IriusRisk for SAST/SCA, Burp Suite, OWASP ZAP, Nmap, Postman, Swagger for testing, and Jira, Azure DevOps for tracking/DevOps is expected.
While Azure Cloud Security is preferred, experience with AWS/GCP is a valuable asset. Strong knowledge of IAM, Data Protection, Cryptography, Cloud Security Controls, and CIS Benchmarks is also required.
Preferred certifications include CEH, CISSP, CISM, or Microsoft Azure Security Engineer Associate, or equivalent.
Deloitte
Technology