T&T | Cyber - CST | Consultant | Hyderabad | Security Controls (Hyderabad, IN)
Deloitte
Deloitte
Join a leading cybersecurity team dedicated to protecting organizations from cyber threats and safeguarding valuable assets. This role focuses on enhancing security by managing and validating data security controls across the enterprise. You'll ensure compliance with regulatory standards and internal policies, with a strong emphasis on identity and access management, access control validation, and database security.
The position involves evidence-based assurance for both on-premises and cloud data environments. This is an excellent opportunity to embed cyber risk management early in strategy development for effective information and technology risk management. Learn more about our Cybersecurity practice.
This role is pivotal in assessing and validating data security controls, ensuring adherence to compliance mandates. Key responsibilities include performing in-depth access control reviews, particularly focusing on RBAC models and dynamic access review mechanisms. You will validate identity and access management (IAM) controls across diverse applications, databases, and infrastructure.
Further duties involve assessing and monitoring database access controls, including privileged access and segregation of duties principles. Identifying and evaluating potential access bypass scenarios and control gaps is crucial, alongside supporting periodic and event-driven access reviews with timely remediation of violations. You will also collect and document evidence to support audits and compliance, analyze control testing outcomes, and escalate identified risks.
We seek candidates with 2-3 years of experience in Data Security, IAM, access control reviews, or cybersecurity GRC. A strong foundation in Identity and Access Management concepts, Role-Based Access Control (RBAC), and database security is essential.
Familiarity with security frameworks like NIST CSF, CIS, or ISO 27001 is required. Candidates should possess excellent analytical, problem-solving, communication, and documentation skills, with the ability to manage multiple priorities and work independently. Experience with access governance and IAM tools is beneficial.
Exposure to automation or scripting for access reviews, along with familiarity with cloud databases (AWS/Azure) and hybrid access models, is advantageous. Experience in detecting access bypass scenarios between on-prem and cloud environments is a plus. Relevant certifications such as CISSP, CISA, or CRISC are highly regarded.
Deloitte
Information Technology & Services