T&T | Cyber: ES | Deputy Manager | Security Architect | Chennai
Deloitte
Deloitte
Join Deloitte's dynamic security team as an Information Security Architect in Chennai. This role focuses on safeguarding valuable assets by preventing cyberattacks and building resilience. You will embed cyber risk management into strategy development, focusing on effective information and technology risk management to unlock new opportunities. Explore the world of Cybersecurity with us.
Develop and implement threat models using STRIDE, DREAD, and PASTA methodologies for on-premises and cloud systems. Conduct risk assessments to identify security weaknesses and propose mitigation strategies for both IT and cloud infrastructure. Integrate security best practices into cloud application architectures and regularly update security models to counter evolving threats.
Review system designs and architectures to pinpoint security vulnerabilities. Collaborate with development teams to embed security throughout the Software Development Lifecycle (SDLC), especially for cloud services. Design and deploy security controls, and recommend enhancements to the overall security posture by evaluating existing measures and proposing new countermeasures.
Partner with cross-functional teams to resolve security issues, implement action plans, and ensure adherence to standards like NIST 800-53 and ISO 27002. Generate detailed reports on identified risks, mitigation plans, cloud controls, and improvement recommendations. Act as a cloud security subject matter expert, guiding the organization's cloud adoption strategy for secure design and implementation.
A Bachelor’s or Master’s degree in Computer Science, Information Security, Cybersecurity, or a related field is required. A minimum of 5 years of experience in information security, with a strong emphasis on security architecture, cloud security, threat modeling, and risk assessments is essential.
Demonstrated experience with threat modeling methodologies like STRIDE, DREAD, and PASTA, and tools such as OWASP Threat Dragon and Microsoft Threat Modeling Tool. Proficiency in cloud security platforms (AWS, Azure, GCP) and best practices, including compliance and vulnerability management, is also crucial.
Familiarity with security tools and technologies, enterprise architecture security implications, and cyber resilience practices aligned with frameworks like NIST SP 800-53 and ISO 27002 is expected. Excellent communication, collaboration, analytical skills, and attention to detail are vital for this role. Industry-recognized certifications are highly desirable.
Deloitte
Cybersecurity