Job Title:  T&T | Cyber: ES | Consultant | Application Security | Pune

Job requisition ID ::  109337
Date:  Jul 23, 2026
Location:  Pune
Designation:  Consultant
Entity:  Deloitte Touche Tohmatsu India LLP

T&T | Cyber: ES | Consultant | Application Security | Pune
Job requisition ID : 109337 
Location: Pune
Entity: Deloitte Touche Tohmatsu India LLP 

The team

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Lear more about Cybersecurity

 

Your work profile:

• Manages Cyber Security Assessment projects, guides the team on a day-to-day basis and ensures that assigned tasks and responsibilities are fulfilled in a timely fashion.

 

• Demonstrates understanding of complex business and information technology management processes.

 

• Interacts with clients, managers and partners to build and nurture strong relationships.

 

• Tailors firm tools and methodologies as per client requirements.

 

• Manages day-to-day client relationships at appropriate management levels.

 

• Participates in proposal development efforts to sell "add-on" work to clients.

 

• Leads and executes offensive security engagements including Vulnerability Assessment and Penetration Testing (VAPT), Red Teaming, Cloud Security Assessments, and Security Architecture Reviews.

 

• Conducts AI Security Assessments and Exposure Management engagements to identify emerging risks across modern enterprise environments.

 

---

 

**Key Skills required**

 

• 3–5 years of experience in Cyber Security.

 

• Experience in VAPT – Application Security Testing, Mobile Application Security, API Security, Infrastructure Security, Red Teaming, and DevSecOps.

 

• Experience in Web Application Security Testing, Infrastructure VAPT, API Testing, Mobile Application Security Testing (iOS & Android).

 

• Experience in AI Offensive Security and AI Security Assessments, including:

 

* LLM Security Testing

* Generative AI Security

* Agentic AI Security

* Prompt Injection Testing

* OWASP Top 10 for LLM Applications

 

• Experience in DevSecOps and Secure SDLC implementations, including:

 

* CI/CD Pipeline Security

* Static Application Security Testing (SAST)

* Dynamic Application Security Testing (DAST)

* Software Composition Analysis (SCA)

* Container and Kubernetes Security

* Infrastructure as Code (IaC) Security

* Secrets Management and Security Automation

* Secure Code Review and Threat Modeling

* DevSecOps Toolchain Integration (Jenkins, GitLab CI/CD, GitHub Actions, Azure DevOps, etc.)

* Shift-Left Security Practices and Secure SDLC Frameworks

 

• Experience in conducting Firewall and Network Device Configuration Reviews and configuration reviews of Windows, Linux, UNIX, Solaris, Databases, Containers, and Cloud Platforms.

 

• Good experience in Red Teaming, Thick Client Security Testing, and Source Code Review.

 

• Experience as a Security Architect and conducting Security Architecture Reviews.

 

• Experience in Endpoint Security and Product Security Assessments.

 

• Strong understanding of industry frameworks and standards such as OWASP Top 10, OWASP API Security Top 10, OWASP Mobile Top 10, OWASP Top 10 for LLM Applications, NIST, and MITRE ATT&CK.

 

---

 

**Education**

 

• Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field.

 

• Master's degree in Information Security, Cyber Security, or Business Management preferred.

 

---

 

**Preferred Certifications**

 

• OSCP, OSEP,OSWE, CRTO, CRTP, CEH

 

---

 

**Hiring Requirement**

 

Candidates with hands-on experience in **AI Offensive Security, LLM Security Testing, Agentic AI Security, Exposure Management (CTEM/EASM), and Advanced Red Teaming** will be preferred in addition to traditional VAPT and DevSecOps experience.