T&T | Cyber - CST | Consultant | Hyderabad | Security Controls
Deloitte
Deloitte
Join Deloitte's Cyber team in Hyderabad as a Security Controls Consultant. This role is integral to safeguarding organizational data by managing and validating data security controls. You will ensure adherence to regulatory mandates and internal policies, focusing on critical areas like identity and access management, database security, and evidence-based assurance across both on-premise and cloud environments.
Deloitte empowers organizations to build robust defenses against cyber threats, ensuring security, vigilance, and resilience. We advocate for integrating cyber risk management into the foundational stages of strategic development to effectively handle information and technology risks.
Key responsibilities include assessing the effectiveness of security controls and identifying implementation gaps. You will conduct thorough access control reviews, particularly focusing on Role-Based Access Control (RBAC) and dynamic access review mechanisms. This involves validating Identity and Access Management (IAM) controls across various applications, databases, and infrastructure.
You will also evaluate and monitor database access controls, ensuring segregation of duties and proper privileged access management. Identifying and analyzing potential access bypass scenarios and control weaknesses, including unauthorized direct access patterns, is crucial. Support periodic and event-driven access reviews and ensure timely remediation of violations. You will collect and document evidence to support access controls, audit requirements, and regulatory compliance, while also analyzing control testing results and escalating access-related risks.
A Bachelor's or Master's degree in Computer Science, Information Technology, or a related discipline is required. We seek candidates with 2-3 years of experience in Data Security, IAM, access control reviews, or cybersecurity GRC roles.
Essential skills include a strong understanding of Identity and Access Management (IAM) concepts, Role-Based Access Control (RBAC), access governance models, and database security. Familiarity with security frameworks such as NIST CSF, CIS, and ISO 27001 is expected. Possess strong analytical and problem-solving abilities, coupled with excellent communication and documentation skills, and the capacity to manage multiple priorities independently.
Experience with access governance and IAM tools is advantageous. Exposure to automation or scripting for access reviews and evidence validation is a plus. Familiarity with cloud-based databases (AWS/Azure) and hybrid access models, along with experience analyzing access bypass scenarios between on-prem and cloud environments, will be highly valued. Relevant certifications like CISSP, CISA, CRISC, or IAM-specific certifications are preferred.
Deloitte
IT Consulting