Job Title:  T&T | Cyber: D&R I Assistant Manager | Threat Modeling | Mumbai

T&T | Cyber: D&R I Assistant Manager | Threat Modeling | Mumbai
Job requisition ID : 108821 
Location: Hyderabad
Entity: Deloitte Touche Tohmatsu India LLP 

 

The team 

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at    how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks.  Learn more about Cybersecurity  

 

Your work profile 

Need to be a Threat Modelling Specialist and should have a profound experience in understanding and assessing the security risks in application, network, security solutions, business logic.

 

Key Skills required:  

  • 4years - 7 years.

·      Conduct threat modelling for applications, networks, security solutions, APIs, business workflows, and processes.

·      Perform security architecture reviews and identify design flaws, control gaps, and security loopholes.

·      Analyze architecture diagrams, data flows, trust boundaries, and integration points.

·      Identify threats, abuse cases, attack paths, and business logic weaknesses.

·      Recommend practical security controls and mitigation actions.

Must have skills:

·      Good knowledge on at least 2 threat modelling methodologies i.e STRIDE, PASTA, DREAD, MITRE ATT&CK based Threat Modelling.

·      Familiar in security frameworks such as NIST Cybersecurity Framework, ISO 27001, ISO 42001, CIS Controls/Benchmark

·      Experience with risk assessment and risk rating methodologies.

·      Experience with tools used for diagramming, architecture review, or threat modelling.

·      Ability to create reusable threat modelling templates, checklists, and review playbooks.

·      Knowledge of threat intelligence and adversary tactics, techniques, and procedures to understand the plausibility of the threats.

·      Good understanding of AI ecosystem like: Agentic AI, AI agents, A2A protocols, MCP, RAG etc

Key Deliverables:

·      Threat modelling reports

·      Security architecture review reports

·      Risk and control gap assessments

·      Attack path and abuse case documentation

·      Data flow and trust boundary analysis

·      Security recommendations and mitigation plans

·      Project-specific threat libraries and checklists

·      Executive-level summaries for risk stakeholders

Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.