T&T | Cyber - CST | Consultant | Application Security Control (Bengaluru, IN)
Deloitte
Deloitte
Join our dynamic cybersecurity team as a Consultant specializing in Application Security Controls. This role is pivotal in helping organizations fortify their defenses against cyber threats. You will be instrumental in assessing and enhancing the security posture of applications and their supporting environments, ensuring resilience and enabling new opportunities through robust cyber risk management. This position offers a challenging yet rewarding career path within a leading cybersecurity practice.
Our cybersecurity services empower clients to prevent attacks, protect critical assets, and remain vigilant. We integrate cyber risk management early in strategy development, focusing on the effective handling of information and technology risks. Discover more about our Cybersecurity offerings.
Your primary focus will be on conducting in-depth security control assessments for applications and their infrastructure. This includes rigorous testing of cybersecurity controls to evaluate their design and operational effectiveness against organizational standards and industry best practices.
You will perform comprehensive application security control reviews, identify and document cybersecurity risks with clear mitigation strategies, and conduct compliance assessments against relevant frameworks. The role also involves evaluating security governance, access management, logging, vulnerability management, and data protection controls. You will also conduct security reviews for web applications, APIs, networks, and cloud systems, and contribute to understanding AI/LLM security vulnerabilities.
We are seeking a Cyber Security Consultant with 2 to 9 years of experience, possessing a strong foundation in Application Security and Secure SDLC. Hands-on experience in testing web, API, and mobile applications is essential.
Key qualifications include a solid understanding of network security concepts, infrastructure security assessments, and practical experience with cloud security across major platforms like AWS, Azure, or GCP. Familiarity with authentication and authorization frameworks such as OAuth2, OpenID Connect, SAML, and JWT is also required.
Candidates should demonstrate experience in security control testing, risk assessment methodologies, and risk management principles. A good grasp of cybersecurity compliance frameworks and standards, along with familiarity with OWASP, NIST, CIS Benchmarks, and MITRE ATT&CK, is expected. Excellent analytical, reporting, and stakeholder management skills are crucial for communicating technical risks effectively to diverse audiences.
Deloitte
Information Technology & Services