Job Title:  Senior Analyst | Governance and Policy Development | Mumbai | Cyber Strategy & Transformation

Senior Analyst | Governance and Policy Development | Mumbai | Cyber Strategy & Transformation
Job requisition ID : 110231 
Location: Mumbai
Entity: Deloitte Touche Tohmatsu India LLP 

The Team 

 

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks.Learn moreabout Cybersecurity 

 

Your Work Profile 

 

We are looking for a motivated and detail-oriented Cloud Security & Cloud Governance Analyst to join our cybersecurity team. This role is ideal for early-career professionals who are passionate about cloud technologies, security best practices, and governance frameworks. The selected candidate will support cloud security operations, governance initiatives, compliance activities, and security monitoring across cloud environments such as AWS, Microsoft Azure, and Google Cloud Platform (GCP).

 

Key Skills Required

 

  • Assist in implementing and maintaining cloud security controls across AWS, Azure, and GCP.
  • Support cloud governance initiatives, including policy enforcement, resource tagging, and compliance monitoring.
  • Monitor cloud environments for security alerts, misconfigurations, and vulnerabilities.
  • Participate in cloud security assessments, audits, and risk evaluations.
  • Help identify and remediate cloud security posture issues using Cloud Security Posture Management (CSPM) tools.
  • Review Identity and Access Management (IAM) configurations, user permissions, and role assignments.
  • Assist in implementing security best practices such as least privilege, encryption, logging, and multi-factor authentication.
  • Support compliance activities related to standards such as ISO 27001, SOC 2, CIS Benchmarks, PCI DSS, or GDPR.
  • Collaborate with infrastructure, DevOps, and application teams to ensure secure cloud deployments.
  • Prepare documentation for cloud governance policies, standards, procedures, and audit evidence.
  • Stay updated with evolving cloud security threats, vulnerabilities, and industry best practices.
  • Basic understanding of cloud platforms (AWS, Azure, or GCP).
  • Knowledge of cloud security concepts including IAM, networking, encryption, logging, and monitoring.
  • Familiarity with cloud governance principles and security frameworks.
  • Understanding of networking fundamentals (TCP/IP, DNS, Firewalls, VPNs).
  • Basic knowledge of Linux and Windows operating systems.
  • Familiarity with scripting languages such as PowerShell, Python, or Bash is an advantage.
  • Understanding of security tools such as Microsoft Defender for Cloud, AWS Security Hub, Azure Policy, AWS Config, or similar solutions.
  • Strong analytical, problem-solving, and troubleshooting skills.
  • Good written and verbal communication skills.
  • Ability to work collaboratively in a team environment.
  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field.
  • Relevant certifications (preferred but not mandatory):
  • AWS Certified Cloud Practitioner
  • Microsoft Azure Fundamentals (AZ-900)
  • Microsoft Security, Compliance, and Identity Fundamentals (SC-900)
  • Google Associate Cloud Engineer
  • CompTIA Security+
  • ISC2 Certified in Cybersecurity (CC)
  • Cloud Security Posture Management (CSPM)
  • Cloud governance and policy management
  • Identity and Access Management (IAM)
  • Security monitoring and logging
  • Vulnerability management
  • Risk and compliance concepts
  • SIEM and cloud-native security services