T&T | Cyber: D&R | Assistant Manager | Network Security | Mumbai
Deloitte
Deloitte
Join a leading cybersecurity team focused on protecting valuable assets and preventing cyberattacks. This role is instrumental in developing robust security strategies, managing information and technology risks effectively, and enabling new opportunities through enhanced cyber resilience. We are dedicated to embedding cyber risk management into the core of strategic development for superior information and technology risk oversight. Discover more about our Cybersecurity practice.
This position involves conducting comprehensive IT audit and risk advisory initiatives. Key responsibilities include assessing, auditing, and fortifying client network security environments. You will leverage risk-based methodologies, compliance frameworks, and industry best practices to evaluate network controls, pinpoint vulnerabilities, and guide remediation efforts in collaboration with cross-functional teams.
Key duties encompass: - Evaluating network architecture and security zoning based on data flow, adhering to Zero Trust Architecture Frameworks and segmentation controls. - Assessing security controls against established frameworks like ISO 27001, NIST, CIS Controls, SOC 2, and relevant regulatory standards. - Reviewing configurations of network switches, routers, firewalls, WAF, Active Directory, proxies, VPN, IDS/IPS, antivirus, and DLP solutions. - Identifying control gaps and proposing actionable remediation steps. - Examining firewall rules, access controls, and secure configurations. - Maintaining thorough audit documentation and working papers. - Collaborating with stakeholders to understand risks and control effectiveness. - Staying abreast of emerging threats and evolving security practices.
We are seeking a Network Security professional with 2 to 5 years of dedicated experience in network security or broader cybersecurity. A solid grasp of network protocols such as TCP/IP, DNS, and HTTP is essential. Hands-on experience with major firewall solutions (Fortinet, Cisco, Palo Alto, Check Point) is required, alongside knowledge of VPNs, WAF, Proxy, SIEM, IDS/IPS, and endpoint security controls. A foundational understanding of cloud security principles in AWS or Azure is also beneficial.
Preferred certifications include at least one OEM certification like CCNA/CCNA Security, NSE 4+, PCNSA, or CCSA. Additionally, certifications such as CEH, Security+, or ISO 27001 Lead Auditor/Implementer are highly regarded. The ideal candidate will possess a Bachelor's or Master's degree in Information Security, Computer Science, or a closely related field.
Deloitte
Information Technology & Services