Job Title:  T&T | Cyber - CST | Consultant | Hyderbad | Security Controls

T&T | Cyber - CST | Consultant | Hyderbad | Security Controls
Job requisition ID : 109084 
Location: Hyderabad
Entity: Deloitte Touche Tohmatsu India LLP 

The Team

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity 

 

Your work profile

This role is responsible for managing and validating data security controls across the organization, ensuring compliance with regulatory and internal requirements. You will focus on identity and access management controls, access control validation, database security controls, and evidence-based assurance across on-prem and cloud data environments.

 

Key Skills Required

·      Work closely with technology, security, and data teams to manage and support data security control implementation.

·      Assess control effectiveness and identify gaps in implementation

·      Perform access control reviews with a focus on RBAC models and dynamic access review mechanisms.

·      Validate identity and access management (IAM) controls across applications, databases, and infrastructure.

·      Assess and monitor database access controls, including privileged access and segregation of duties.

·      Identify and evaluate database access-bypass scenarios and control gaps, including direct or unauthorized access patterns.

·      Support periodic and event-driven access reviews, ensuring timely remediation of access violations.

·      Collect, validate, and document evidence to support access controls, audit requirements, and regulatory compliance.

·      Analyze control testing results and escalate access-related risks or violations to senior management.

·      Support and manage regulatory and audit activities related to data security and access controls.

·      Recommend and implement improvements to access control validation, monitoring, and reporting mechanisms.

 

Qualifications:

·      Bachelor’s degree in computer science, Information Technology, or a related field.

·      4+ years of experience in Data Security, IAM, access control reviews, or cybersecurity GRC roles.

·      Strong understanding of:

o  Identity and Access Management (IAM) concepts

o  Role-Based Access Control (RBAC) and access governance models

o  Database security and access controls

·      Experience with security frameworks (NIST CSF, CIS, ISO 27001).

·      Strong analytical and problem-solving skills.

·      Excellent communication and documentation skills.

·      Ability to manage multiple priorities and work independently.

 

Good to Have:

·      Experience with access governance and IAM tools.

·      Exposure to automation or scripting for access reviews and evidence validation.

·      Familiarity with cloud-based databases (AWS / Azure) and hybrid access models.

·      Experience in detecting and analyzing access bypass scenarios between on-prem and cloud environments.

·      Relevant certifications (CISSP, CISA, CRISC, or IAM-related certifications).