Job Title: T&T | Cyber - CST | Consultant | Application Security Control

T&T | Cyber - CST | Consultant | Application Security Control
• Job requisition ID : 108853
• Location: Bengaluru
• Entity: Deloitte Touche Tohmatsu India LLP
The team
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Lear more about Cybersecurity
Your work profile
- We are seeking a Cyber Security Consultant with strong expertise in Application Security and experience in security control assessments, risk assessments, and compliance reviews. The role will involve a combination of hands-on application security review and governance-focused security assessments to evaluate the effectiveness of security controls across applications and supporting environments.
- Perform security control testing to assess the design and operating effectiveness of cybersecurity controls.
- Conduct application security control reviews against organizational security requirements and industry best practices.
- Perform cybersecurity risk assessments and document risks, impacts, and mitigation recommendations.
- Conduct compliance assessments against regulatory and industry frameworks.
- Evaluate security governance processes and identify control gaps.
- Review access management, logging, monitoring, vulnerability management, and data protection controls.
- Support audit and regulatory assessment activities by providing security expertise and evidence reviews.
- Conduct security reviews of web application, API, Network and Cloud systems.
- Knowledge on AI&LLM security vulnerabilities.
- Identify vulnerabilities aligned with OWASP Top 10.
- Conduct threat modeling and security architecture reviews.
- Review application security controls and provide remediation recommendations.
- Validate remediation activities through re-testing and security verification exercises
Key skills required:
- Strong understanding of Application Security and Secure SDLC practices.
- Hands-on experience with Web, API, and Mobile Application Testing.
- Exp must be 2 to 9 Years in Cyber Security
- Strong knowledge of Network Security concepts and infrastructure security assessments.
- Practical experience with Cloud Security across AWS, Azure, or GCP.
- Knowledge of authentication and authorization frameworks including OAuth2, OpenID Connect, SAML, and JWT.
- Experience conducting security control testing and control effectiveness reviews.
- Knowledge of risk assessment methodologies and risk management principles.
- Familiarity with cybersecurity compliance frameworks and standards.
- Strong analytical, reporting, and stakeholder management skills. Strong understanding of common attack vectors and exploitation techniques.
- Familiarity with security standards including OWASP, NIST, CIS Benchmarks, and MITRE ATT&CK.
- Ability to communicate technical risks to business and management stakeholders.
- Pref Certifications: CISA, CEH, CCSP, AWS Security Specialty, Azure Security Engineer Associate, OSCP
- B.E./B.Tech (Tier 1/2) or Master’s degree in Information Security, Computer Science, or a related field
