Job Title:  T&T | Cyber : D&R | Manager | Network Security -CSPM | Bengaluru

T&T | Cyber : D&R | Manager | Network Security -CSPM | Bengaluru
Job requisition ID : 110923 
Location: Bengaluru
Entity: Deloitte Touche Tohmatsu India LLP 

 

 

The team 

 

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity 

 

Your work profile 

We are seeking a highly skilled and motivated Cloud Security Posture Management (CSPM) and Cloud Native Application Protection Platform (CNAPP) Specialist to join our growing cloud security team. As an L2/L3 resource, you will be responsible for ensuring the security, compliance, and operational excellence of cloud environments and applications through advanced CSPM and CNAPP technologies. You will play a critical role in securing our cloud infrastructure and applications, ensuring adherence to best practices and policies.

 

Key skills required

  • 5+ years of experience in cloud security with deep expertise in CSPM and CNAPP technologies.
  • CSPM Implementation & Management (L2/L3):
  • Design, configure, and maintain CSPM solutions (e.g., Primarily Wiz, or other similar solutions like Prisma Cloud, Check Point, AWS Security Hub, etc.).
  • Monitor cloud environments for misconfigurations, vulnerabilities, and security risks.
  • Perform regular security assessments of cloud infrastructure, identifying gaps, and providing remediation recommendations.
  • Lead incident response for cloud security issues and misconfiguration alerts.
  • Develop and enforce security policies for cloud resource provisioning and access management.
  • CNAPP Integration & Protection (L2/L3):
  • Implement and manage CNAPP tools for securing cloud-native applications, including containerized environments, Kubernetes, and serverless architectures.
  • Conduct continuous security posture assessments of containerized applications, identifying vulnerabilities and ensuring compliance.
  • Implement runtime protection strategies and integrate threat intelligence for proactive attack detection.
  • Collaborate with development and DevOps teams to embed security into the CI/CD pipeline and shift-left practices.
  • Cloud Security Monitoring and Incident Response (L2/L3):
  • Investigate and respond to cloud-related security incidents and alerts, leveraging CSPM and CNAPP solutions.
  • Use cloud-native logging and monitoring tools (e.g., AWS CloudTrail, Azure Security Center) to track security-related events and anomalies.
  • Provide detailed reports and post-incident analyses to management.
  • Collaboration & Documentation:
  • Collaborate with cross-functional teams (DevOps, engineering, network security, etc.) to enhance cloud security posture.
  • Create and maintain detailed documentation on cloud security policies, configurations, and best practices.
  • Provide technical guidance and mentorship to junior team members (L2/L3).
  • Ongoing Improvement & Research:
  • Stay up-to-date with the latest cloud security trends, tools, and best practices.
  • Research and evaluate new CSPM and CNAPP technologies, recommending and implementing enhancements to the security posture.
  • Hands-on experience with leading CSPM and CNAPP tools like Prisma Cloud, Check Point, Aqua Security, Sysdig, etc.
  • Strong understanding of cloud platforms (AWS, Azure, GCP) and cloud-native technologies (Kubernetes, Docker).
  • Knowledge of security best practices, compliance standards (e.g., CIS, NIST, SOC 2), and cloud security frameworks.
  • Familiarity with scripting and automation (Python, Bash, Terraform, etc.) for cloud security tasks.
  • Strong problem-solving and analytical skills.
  • Extensive hands-on experience with multiple CSPM and CNAPP tools, and cloud-native security services.
  • Proven experience in designing, implementing, and managing secure cloud environments at scale.
  • Strong expertise in incident response, vulnerability management, and cloud security monitoring.
  • Deep knowledge of advanced cloud security architectures, threat modeling, and risk assessment.
  • Experience with security automation, DevSecOps practices, and cloud security integrations.
  • Excellent communication skills and the ability to mentor junior team members.
  • Education: Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.