Senior Executive | Risk Management | Pune | Cyber Strategy & Transformation (Pune, IN)
Deloitte
Deloitte
Join our Cyber Strategy & Transformation team in Pune as a Senior Executive in Risk Management. Deloitte empowers organizations to proactively defend against cyber threats and safeguard critical assets. We focus on building resilience through effective cyber risk management, integrating security from the outset of strategy development to optimize information and technology risk management. Explore the world of Cybersecurity with us.
This role is crucial for enhancing our security posture by ensuring development and DevOps teams implement robust security controls and effective remediation measures. You will play a key part in identifying and addressing vulnerabilities, ensuring applications adhere to Secure SDLC standards and compliance mandates.
Your core responsibilities will involve validating security controls and remediation efforts across applications and cloud platforms. You'll verify critical security aspects like authentication, authorization (RBAC/ABAC), input validation, secure configurations, and API security.
Key duties include re-testing identified vulnerabilities to confirm effective remediation using comprehensive testing scenarios, and performing security regression testing to prevent the introduction of new risks. You will also review and validate findings from SAST, DAST, SCA, and Threat Modeling activities. Collaboration with Development, DevOps, Security, and QA teams throughout the Secure SDLC is essential, along with maintaining detailed records of security testing evidence, reports, and vulnerability tracking.
We are seeking an experienced Application Security/DevSecOps professional with a proven track record in security control verification, remediation validation, and secure application delivery. The ideal candidate will possess strong hands-on experience and the ability to collaborate effectively with engineering teams to enhance the overall security posture.
Essential skills include expertise in Secure SDLC, OWASP Top 10, Threat Modeling, Application Security Controls, DevSecOps Practices, and Vulnerability Management. You should be proficient in SAST, DAST, SCA validation, Security Control Verification, Remediation Testing & Validation, and REST API Security Testing. Familiarity with tools like SonarQube, Coverity, Burp Suite, Jira, and Azure DevOps is expected. Cloud experience, particularly Azure, is preferred, with AWS/GCP considered a plus. Scripting skills in Python, Bash, or JavaScript are also advantageous.
Deloitte
Information Technology & Services