Job Title:  T&T | Cyber : D&R | Manager | Security Platform Engineer| Delhi

T&T | Cyber : D&R | Manager | Security Platform Engineer| Delhi
Job requisition ID : 111092 
Location: Delhi
Entity: Deloitte Touche Tohmatsu India LLP 

The Team

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about   Cybersecurity

 

 Your Work Profile

  • Assess current secrets management and IAM practices across Azure, AWS, on-premises, Kubernetes, CI/CD, applications, databases, APIs, and service accounts.
  • Define target-state architecture for secrets management, IAM integration, workload identity, privileged access, credential rotation, audit, and governance.
  • Create enterprise standards for secrets storage, access, rotation, ownership, naming, tagging, expiry, exception handling, and decommissioning.
  • Define when to use centralized secrets platforms versus cloud-native tools such as Azure Key Vault and AWS Secrets Manager.
  • Design IAM access models using Azure Entra ID, AWS IAM, roles, policies, groups, service principals, managed identities, OIDC federation, and least-privilege access.
  • Support onboarding and migration of application teams from insecure or inconsistent secrets and IAM practices.
  • Integrate secrets management with IAM, PAM, CI/CD pipelines, Kubernetes, databases, APIs, legacy applications, logging, monitoring, and SIEM.
  • Help establish operating model components such as ownership, support processes, governance, exception management, control monitoring, and reporting.
  • Produce practical documentation, reference architectures, onboarding playbooks, and implementation patterns for engineering teams.

  

Your skills and experience

  • B.E./B.Tech. Or M.C.A. in Computer Science from a reputed University with 10-15 years of hands-on experience on below mentioned skills.
  • Proven experience delivering at least one enterprise transformation in secrets management, IAM, PAM, DevSecOps, cloud security, or machine identity.
  • Strong understanding of IAM concepts, including authentication, authorization, RBAC, ABAC, least privilege, federation, workload identity, privileged access, service accounts, access reviews, and audit controls.
  • Hands-on experience with Azure and AWS IAM services, including Entra ID, Azure Managed Identity, service principals, AWS IAM roles, policies, STS, and OIDC.
  • Experience with at least two secrets management technologies, such as Azure Key Vault, AWS Secrets Manager, HashiCorp Vault, CyberArk Conjur, Akeyless, Thales CipherTrust, External Secrets Operator, or Secrets Store CSI Driver.
  • Experience working in hybrid environments with cloud and on-premises workloads.
  • Experience integrating secrets and IAM controls with CI/CD tools such as Azure DevOps, GitHub Actions, Jenkins, GitLab, or similar.
  • Ability to define enterprise standards, target-state architecture, migration plans, governance models, and practical engineering patterns.
  • Strong stakeholder management skills across security, cloud, platform, infrastructure, application, risk, and audit teams.
  • Experience in regulated enterprise environments such as financial services, banking, insurance, healthcare, or similar.
  • Experience with CyberArk PAM, HashiCorp Vault Enterprise, machine identity, certificate lifecycle, or dynamic secrets.
  • Experience with policy-as-code, Terraform, Azure Policy, AWS Organizations/SCPs, OPA, Sentinel, Checkov, Prisma Cloud, Wiz, or similar tools.
  • Experience with secret scanning and remediation using tools such as GitHub Advanced Security, GitGuardian, Gitleaks, TruffleHog, or similar.
  • Experience defining dashboards or metrics for secrets compliance, IAM access hygiene, rotation status, onboarding progress, exceptions, and risk reduction.
  • Proven enterprise secrets management, Strong IAM knowledge across Azure Entra ID, AWS IAM, workload identity, federation, RBAC/ABAC, least privilege, service principals and managed identities/cyberark
  • Multi-cloud IAM knowledge across Azure Entra ID, AWS IAM, workload identity, federation, RBAC/ABAC, least privilege, service principals and managed identities CI/CD and strong DevSecOps practices