Job Title:  T&T | Cyber: D&R | Manager | Security Architect | Delhi

T&T | Cyber: D&R | Manager | Security Architect | Delhi
Job requisition ID : 112409 
Location: Delhi
Entity: Deloitte Touche Tohmatsu India LLP 

The Team

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about   Cybersecurity

 

Key Responsibilities:

  • Build and govern the framework, entry criteria, and lifecycle processes for creating technology-specific Minimum Security Baselines.
  • Develop and tailor MSBs using NIST CSF, NIST SP 800-53/53B, MITRE ATT&CK, internal standards, and threat-led methodologies.
  • Translate threats and risks into clear, measurable, and technically testable security controls.
  • Collaborate with architects, product owners, and technology teams to review and finalize MSBs.
  • Analyze API and technical documentation to develop, test, and maintain Rego policies using Open Policy Agent.
  • Maintain traceability between threats, MSB controls, Rego policies, evidence requirements, and compliance results.
  • Validate non-compliance findings and false positives before raising remediation items in SNAB.
  • Manage MSB adoption, exceptions, remediation governance, dashboards, and project KPIs.
  • Strong knowledge of NIST CSF, NIST SP 800-53/53B, control baselines, control tailoring, and security overlays.
  • Demonstrable experience developing and governing Minimum Security Baselines.
  • Hands-on experience with Open Policy Agent, Rego development, policy testing, and Policy-as-Code.
  • Experience mapping MITRE ATT&CK techniques to security controls.
  • Ability to write measurable control requirements, validation criteria, and evidence requirements.

 

Nice to Have

    • A minimum of 8 years of experience in Minimum Security Baseline.

    • Understanding of cloud, API, infrastructure, identity, and application security controls.

  • Experience with version control, peer review, exception management, and policy lifecycle governance.
  • Strong stakeholder management, governance, dashboarding, and reporting skills.

    • Education: B.E./B.Tech. Or M.C.A. in Computer Science from a reputed University