Position Summary

Job Summary

 

The Business Information Security Officer (BISO) Team works with the Deloitte Function Specific Subsidiaries (FSS) & Chief Information Security Officer (CISO) organization directly supporting Advisory and Consulting FSS business. The BISO Analyst will work closely with technical and non-technical stakeholders to drive widespread cyber security program adoption.  

As a BISO Analyst you will be responsible for providing cyber security expertise and risk mitigation approaches between technical and non-technical domains. The role is responsible for supporting and applying security through industry best practices in technology design, architecture, and compliance.

This fast-paced multi-faceted environment requires a highly motivated, self-driven, strong team player who demonstrates and intrinsic desire for continuous personal and professional growth.

 

Responsibilities

  • Contribute to the ongoing development and implementation of cybersecurity initiatives
  • Participate in the security governance model, establishing policies, standards, and best practices
  • Possess a working knowledge on the fundamentals of all major cloud providers (Azure, AWS, GCP)
  • Review cloud IAM roles and prescribe recommendations based on the least privilege principle
  • Review cloud infrastructure patterns and identify security gaps
  • Contribute to addressing changes in the external threat landscape that have an impact on the use of on-premise and cloud computing technologies
  • Possess an understanding of OWASP top 10 for API security and application modernization such as Docker images security and container security
  • Support application teams in meeting cyber security compliance requirements
  • Deliver technical guidance related to enhancing the security posture of information systems solutions
  • Assist with the design and implementation of security architecture controls to meet compliance requirements
  • Support managers in delivering security domain solutions for Advisory and Consulting portfolios
  • Source and provide qualitative and quantitative metrics to help measure the performance of the organization
  • Support the delivery and adoption of new security controls and compliance through well-formed and organized communication to impacted stakeholders

Minimum Qualifications

 

Education: Bachelor’s Degree or equivalent experience in Information Security, Computer Science, or Information Systems

 

Years of Experience: 2+ years of experience in cybersecurity and/or risk management in organizations of a similar scale or client-service experience in the field

Certifications: Professional information security certifications preferred

 

Other Specific Skills or Knowledge

  • Strong understanding of cloud security concepts
  • Knowledge of network and system security principles
  • Familiarity with operations systems (Windows, Linux, Unix) and network protocols
  • Exceptional verbal and written communication skills. Must be able to interact effectively with professionals at all levels and capable of communicating recommendations
  • Strong analytical and problem-solving skills
  • Ability to work independently and as part of a team
  • Detail-oriented with a strong focus on accuracy and quality
  • Knowledge and experience across multiple information protection and security domains
  • Knowledge of IT asset management and/or configuration information database (CMDB)
  • Broad knowledge and experience across IT infrastructure with security frameworks and standards such as ISO 27001, NIST, PCI, and other relevant security-related regulations
  • Understanding of and ability to effectively apply trends and developments in security and risk management

The team

Information Technology Services (ITS) helps power Deloitte’s success.  ITS is the engine that helps to drive Deloitte, which serves many of the world’s largest organizations. We develop and deploy cutting-edge internal and go-to-market solutions that help Deloitte operate effectively and lead in the market. Our reputation is built on a tradition of delivering with excellence.

 

The ~2,200 professionals in ITS deliver services internally including:

  • Cyber security
  • Technology support
  • Technology & Infrastructure
  • Application development and management
  • Relationship management group
  • Strategy
  • Deployment
  • PMO
  • Financials
  • Communications

For more information on ITS, you can visit our dedicated recruitment page at https://usrecruiting.deloitte.com/-its-recruiting-for-experienced-hires.

  

Cyber Security

The Cyber Security team is responsible for vigilantly protecting Deloitte and client data. The team is responsible for a strategic cyber risk program that adapts to a rapidly changing threat landscape, changes in business strategies, risks, and vulnerabilities. Using situational awareness, threat intelligence, and building a security culture across the organization, the team helps to protect the Deloitte brand.

 

Areas of focus include:

  • Cyber design
  • Risk & Compliance 
  • Technology Risk Management
  • Identity & Access Management
  • Data Protection
  • Incident Response and Architecture

Recruiting tips

From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.
Benefits

At Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits. Learn more about what working at Deloitte can mean for you.
Our people and culture

Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ideas and perspectives, and bring more creativity and innovation to help solve our client most complex challenges. This makes Deloitte one of the most rewarding places to work.
Our purpose

Deloitte’s purpose is to make an impact that matters for our clients, our people, and in our communities. We are creating trust and confidence in a more equitable society. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. We are focusing our collective efforts to advance sustainability, equity, and trust that come to life through our core commitments. Learn more about Deloitte's purpose, commitments, and impact.
Professional development

From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.

Requisition code: 214645