T&T | Cyber: D&R | Manager | Security Architect | Delhi
Deloitte
Deloitte
Join Deloitte's Cyber team as a Security Architect Manager in Delhi. We empower organizations to proactively defend against cyber threats and safeguard critical assets. Our approach emphasizes security, vigilance, and resilience, integrating cyber risk management into strategic development for effective information and technology risk mitigation. Discover more about our Cybersecurity offerings.
This role is pivotal in building and maintaining robust security frameworks to prevent and respond to cyberattacks, ensuring our clients can seize new opportunities securely.
Develop and manage frameworks for creating technology-specific Minimum Security Baselines (MSBs), including entry criteria and lifecycle processes. Tailor these baselines using industry standards like NIST CSF, NIST SP 800-53/53B, and MITRE ATT&CK, along with threat-led methodologies. Translate complex threats and risks into clear, measurable, and technically testable security controls.
Collaborate with cross-functional teams, including architects and product owners, to finalize MSBs. Analyze technical documentation to develop and maintain Rego policies using Open Policy Agent. Ensure traceability between threats, controls, policies, evidence, and compliance results. Validate non-compliance findings and manage MSB adoption, exceptions, and remediation governance.
A minimum of 8 years of experience is required, with a strong foundation in developing and governing Minimum Security Baselines. Proficiency in NIST CSF, NIST SP 800-53/53B, control baselines, tailoring, and security overlays is essential. Demonstrable hands-on experience with Open Policy Agent, Rego development, policy testing, and Policy-as-Code is a must.
Candidates should possess experience mapping MITRE ATT&CK techniques to security controls and be capable of writing measurable control requirements and validation criteria. An understanding of cloud, API, infrastructure, identity, and application security controls, along with experience in version control, peer review, and policy lifecycle governance, are highly desirable. Strong stakeholder management, governance, dashboarding, and reporting skills are also important.
Deloitte
Cybersecurity