T&T | Cyber - CST | Consultant | Application Security Control

Deloitte

2–9 yrs Bengaluru Full Time Work from office
Deloitte logo
Posted : today
Actively hiring

Job description

Join a dynamic cybersecurity team focused on helping organizations proactively prevent cyberattacks and safeguard critical assets. We champion a secure, vigilant, and resilient approach, integrating cyber risk management into strategic development to effectively manage information and technology risks.

This role offers the opportunity to specialize in Application Security, assessing and enhancing security controls across various applications and their supporting infrastructure. You will leverage your expertise to perform hands-on reviews and governance-focused assessments, ensuring robust cybersecurity posture.

Responsibilities

Perform rigorous security control testing to evaluate the design and operational effectiveness of cybersecurity measures. Conduct in-depth application security control reviews, ensuring alignment with organizational security requirements and industry best practices. Execute cybersecurity risk assessments, documenting identified risks, their impacts, and actionable mitigation strategies. Evaluate security governance processes to pinpoint control gaps and recommend improvements.

Review key security areas such as access management, logging, monitoring, vulnerability management, and data protection controls. Support audit and regulatory assessment activities by providing essential security expertise and evidence reviews. Conduct comprehensive security reviews of web applications, APIs, networks, and cloud systems, with a focus on identifying vulnerabilities aligned with OWASP Top 10. Analyze AI and LLM security vulnerabilities, perform threat modeling, and conduct security architecture reviews.

Qualifications

A strong foundation in Application Security and Secure Software Development Lifecycle (SDLC) practices is essential. Candidates should possess hands-on experience with Web, API, and Mobile Application Testing, coupled with robust knowledge of Network Security concepts and infrastructure security assessments. Practical experience with Cloud Security across AWS, Azure, or GCP is required.

Familiarity with authentication and authorization frameworks like OAuth2, OpenID Connect, SAML, and JWT is crucial. Experience in conducting security control testing and control effectiveness reviews, along with a solid understanding of risk assessment methodologies and management principles, is necessary. A working knowledge of cybersecurity compliance frameworks and standards, including OWASP, NIST, CIS Benchmarks, and MITRE ATT&CK, is expected. Strong analytical, reporting, and stakeholder management skills are vital, as is the ability to articulate technical risks to both business and management audiences.

Essential Skills

Application SecuritySecure SDLCWeb Application TestingAPI TestingMobile Application TestingNetwork SecurityCloud SecurityAWSAzureGCPOAuth2OpenID ConnectSAMLJWTSecurity Control TestingRisk AssessmentCompliance FrameworksNISTCIS BenchmarksMITRE ATT&CKThreat ModelingSecurity Architecture ReviewsOWASP Top 10Vulnerability ManagementData ProtectionAccess ManagementLoggingMonitoringStakeholder ManagementAI SecurityLLM Security

Good to Have

CISACEHCCSPAWS Security SpecialtyAzure Security Engineer AssociateOSCP

Highlights

  • Actively hiring

More Details

RoleT&T | Cyber - CST | Consultant | Application Security Control
IndustryTechnology
DepartmentInformation Technology, Security
Employment TypeFull Time, Work from office

About the Company

Deloitte logo

Deloitte

Technology

T&T | Cyber - CST | Consultant | Application Security Control at Deloitte | SkillMX | SkillMX