T&T | Cyber: ES | Consultant | Application Security | Pune
Deloitte
Deloitte
Join a leading cybersecurity team focused on helping organizations proactively prevent cyberattacks and safeguard critical assets. We champion a secure, vigilant, and resilient approach to cyber risk management, enabling businesses to embrace new opportunities.
This role is crucial for embedding cyber risk considerations at the initial stages of strategy development, leading to more effective management of information and technology risks. Explore the dynamic world of Cybersecurity with us.
Manage complex Cyber Security Assessment projects, providing day-to-day guidance to the team and ensuring timely completion of tasks. Engage with clients, managers, and partners to cultivate strong professional relationships and tailor firm tools and methodologies to meet specific client needs.
Lead and execute offensive security initiatives, including Vulnerability Assessment and Penetration Testing (VAPT), Red Teaming, Cloud Security Assessments, and Security Architecture Reviews. Conduct AI Security Assessments and Exposure Management engagements to identify emerging risks within modern enterprise environments.
We are seeking an experienced professional with 3–5 years in Cyber Security, specifically in VAPT encompassing Application Security Testing, Mobile Application Security, API Security, Infrastructure Security, Red Teaming, and DevSecOps.
Demonstrated experience in Web Application Security Testing, Infrastructure VAPT, API Testing, and Mobile Application Security Testing for both iOS and Android platforms is essential. Expertise in AI Offensive Security and AI Security Assessments, covering areas like LLM Security Testing, Generative AI Security, Agentic AI Security, Prompt Injection Testing, and OWASP Top 10 for LLM Applications, is highly valued.
Proficiency in DevSecOps and Secure SDLC implementations, including CI/CD Pipeline Security, SAST, DAST, SCA, Container and Kubernetes Security, Infrastructure as Code (IaC) Security, Secrets Management, Security Automation, Secure Code Review, and Threat Modeling, is required. Experience with DevSecOps Toolchain Integration (Jenkins, GitLab CI/CD, GitHub Actions, Azure DevOps, etc.) and Shift-Left Security Practices is also key.
Additional experience in conducting Firewall and Network Device Configuration Reviews, along with configuration reviews of Windows, Linux, UNIX, Solaris, Databases, Containers, and Cloud Platforms, is beneficial. Strong capabilities in Red Teaming, Thick Client Security Testing, and Source Code Review are sought after. Experience as a Security Architect with a track record of conducting Security Architecture Reviews, along with Endpoint Security and Product Security Assessments, is expected.
A solid understanding of industry frameworks and standards such as OWASP Top 10, OWASP API Security Top 10, OWASP Mobile Top 10, OWASP Top 10 for LLM Applications, NIST, and MITRE ATT&CK is fundamental. A Bachelor’s degree in information security, Computer Science, or a related field is required. A master’s degree in Cybersecurity or Business Management is preferred.
Deloitte
Cybersecurity