T&T | Cyber: ES | Consultant | Application Security | Pune

Deloitte

3–5 yrs Pune Full Time Work from office
Deloitte logo
Posted : 1 week ago
Actively hiring

Job description

Join a leading cybersecurity team focused on helping organizations proactively prevent cyberattacks and safeguard critical assets. We champion a secure, vigilant, and resilient approach to cyber risk management, enabling businesses to embrace new opportunities.

This role is crucial for embedding cyber risk considerations at the initial stages of strategy development, leading to more effective management of information and technology risks. Explore the dynamic world of Cybersecurity with us.

Responsibilities

Manage complex Cyber Security Assessment projects, providing day-to-day guidance to the team and ensuring timely completion of tasks. Engage with clients, managers, and partners to cultivate strong professional relationships and tailor firm tools and methodologies to meet specific client needs.

Lead and execute offensive security initiatives, including Vulnerability Assessment and Penetration Testing (VAPT), Red Teaming, Cloud Security Assessments, and Security Architecture Reviews. Conduct AI Security Assessments and Exposure Management engagements to identify emerging risks within modern enterprise environments.

Qualifications

We are seeking an experienced professional with 3–5 years in Cyber Security, specifically in VAPT encompassing Application Security Testing, Mobile Application Security, API Security, Infrastructure Security, Red Teaming, and DevSecOps.

Demonstrated experience in Web Application Security Testing, Infrastructure VAPT, API Testing, and Mobile Application Security Testing for both iOS and Android platforms is essential. Expertise in AI Offensive Security and AI Security Assessments, covering areas like LLM Security Testing, Generative AI Security, Agentic AI Security, Prompt Injection Testing, and OWASP Top 10 for LLM Applications, is highly valued.

Proficiency in DevSecOps and Secure SDLC implementations, including CI/CD Pipeline Security, SAST, DAST, SCA, Container and Kubernetes Security, Infrastructure as Code (IaC) Security, Secrets Management, Security Automation, Secure Code Review, and Threat Modeling, is required. Experience with DevSecOps Toolchain Integration (Jenkins, GitLab CI/CD, GitHub Actions, Azure DevOps, etc.) and Shift-Left Security Practices is also key.

Additional experience in conducting Firewall and Network Device Configuration Reviews, along with configuration reviews of Windows, Linux, UNIX, Solaris, Databases, Containers, and Cloud Platforms, is beneficial. Strong capabilities in Red Teaming, Thick Client Security Testing, and Source Code Review are sought after. Experience as a Security Architect with a track record of conducting Security Architecture Reviews, along with Endpoint Security and Product Security Assessments, is expected.

A solid understanding of industry frameworks and standards such as OWASP Top 10, OWASP API Security Top 10, OWASP Mobile Top 10, OWASP Top 10 for LLM Applications, NIST, and MITRE ATT&CK is fundamental. A Bachelor’s degree in information security, Computer Science, or a related field is required. A master’s degree in Cybersecurity or Business Management is preferred.

Essential Skills

Vulnerability AssessmentPenetration TestingRed TeamingCloud Security AssessmentsSecurity Architecture ReviewsAI Security AssessmentsExposure ManagementLLM Security TestingGenerative AI SecurityAgentic AI SecurityPrompt Injection TestingOWASP Top 10 for LLM ApplicationsDevSecOpsSecure SDLCCI/CD Pipeline SecuritySASTDASTSCAContainer SecurityKubernetes SecurityInfrastructure as Code SecuritySecrets ManagementSecurity AutomationSecure Code ReviewThreat ModelingDevSecOps Toolchain IntegrationShift-Left SecurityFirewall Configuration ReviewsNetwork Device Configuration ReviewsWindows SecurityLinux SecurityUNIX SecurityDatabase SecurityCloud Platform SecurityThick Client Security TestingSource Code ReviewSecurity ArchitectEndpoint SecurityProduct Security AssessmentsOWASP Top 10OWASP API Security Top 10OWASP Mobile Top 10NISTMITRE ATT&CK

Highlights

  • Actively hiring

More Details

RoleT&T | Cyber: ES | Consultant | Application Security | Pune
IndustryCybersecurity
DepartmentConsulting
Employment TypeFull Time, Work from office

About the Company

Deloitte logo

Deloitte

Cybersecurity

T&T | Cyber: ES | Consultant | Application Security | Pune at Deloitte | SkillMX | SkillMX