T&T | Cyber: ES | Deputy Manager | Security Architect | Chennai (Chennai, IN)
Deloitte
Deloitte
Join Deloitte Touche Tohmatsu India LLP as a Deputy Manager, Security Architect in Chennai. This role is integral to our Cyber ES team, focusing on building resilience against cyber threats and protecting valuable organizational assets.
We enable organizations to proactively prevent cyberattacks and safeguard their critical information. Our approach integrates cyber risk management into strategic development, ensuring effective handling of information and technology risks. Explore more about our Cybersecurity services and how we empower businesses.
Develop and implement comprehensive threat models for both on-premises and cloud systems, employing methodologies like STRIDE, DREAD, and PASTA. Conduct detailed risk assessments to pinpoint security weaknesses and propose effective mitigation strategies for IT and cloud infrastructures.
Integrate security best practices into cloud application architectures and the Software Development Lifecycle (SDLC), ensuring security is a foundational element. Regularly update security models to counter evolving threats and adapt to cloud technology advancements.
Review system designs and architectures to identify security vulnerabilities. Collaborate with development teams to embed security throughout the SDLC, especially for cloud services. Design and deploy robust security controls and provide strategic recommendations to enhance the overall security posture.
Partner with cross-functional teams to resolve security issues and implement action plans aligned with industry standards like NIST 800-53 and ISO 27002. Generate detailed reports on identified risks, mitigation strategies, cloud controls, and improvement recommendations. Act as a subject matter expert in cloud security, guiding secure adoption strategies.
We seek an experienced Information Security Architect with a minimum of 5 years in the field, specializing in security architecture, cloud security, threat modeling, and risk assessments. A Bachelor's or Master's degree in Computer Science, Information Security, Cybersecurity, or a related discipline is required.
Demonstrated expertise in threat modeling methodologies (STRIDE, DREAD, PASTA) and tools, alongside proven experience with cloud security platforms such as AWS, Azure, and GCP. Familiarity with cloud security best practices, compliance, and vulnerability management is essential.
Proficiency in understanding common security vulnerabilities (e.g., OWASP Top 10) and their mitigation. Knowledge of enterprise architecture and its security implications, along with an understanding of cloud governance models, is crucial. Proficiency in cyber resilience practices and alignment with frameworks like NIST SP 800-53 and ISO 27002 is expected.
Industry-recognized certifications such as CISSP, CCSP, ISO 27001, CISM, or CEH are highly desirable. Excellent communication, collaboration, and analytical skills are necessary to excel in this role.
Deloitte
Information Technology & Services