Analyst - Penetration Tester (Security Testing) - Deloitte Support Services India Pvt. Ltd.
Are you energized by helping organizations protect their data and build client trust? Do you want to work in one of the world’s largest holistic internal cybersecurity organizations? If you’re interested in proactively preventing, detecting, and responding to cyber-attacks across a complex global footprint, then Deloitte Global could be the perfect place for you. We’re looking for an analytical thinker passionate about cybersecurity to join our team.
Work you’ll do
As part of the Global Cybersecurity team, responsibilities will be to work with customers to deliver technical assessments against a broad range of services, illustrative duties will include:
This role is responsible for providing manual penetration testing services as part of the shared services organization for member firms. Illustrative responsibilities.
- Assisting in technical scoping of security testing activities
- Executing security testing.
- Web Application Penetration Testing
- Web Services / Application Programming Interface (API) Penetration Testing
- Network Penetration Testing
- Mobile Application Penetration Testing
- Thick Client Penetration Testing
- Conducting focused research when not deployed on an active project
- Provide consultative guidance to customers on findings identified in a clear and actionable fashion both in writing and verbally.
- Enhancing and updating testing methodologies, processes and standards documentation
- Maintaining proficiency of knowledge through ongoing training paths
- Proficient at analyzing and understanding complex architecture designs.
- Ability to effectively communicate what services and capabilities our group can facilitate to our clients.
The team
The Deloitte Global Cybersecurity function is responsible for enhancing data protection, standardizing and securing critical infrastructure, and gaining cyber visibility through security operations centers. The Cybersecurity organization delivers a comprehensive set of security services to Deloitte’s global network of firms around the globe.
Qualifications
· Education (degree): Bachelor’s Degree or equivalent experience
Skills/abilities:
- · Ability to communicate strategic information security topics, policies, and standards as well as risk-related concepts to technical and nontechnical audiences
· Threat modeling experience
· Scripting experience (Power shell, Python)
· Sound knowledge of common infrastructure and web application vulnerabilities and
common vulnerability categorizations such as OWASP, CVSS Secure DevOps experience
Knowledge of ticketing and tracking tools such as Service Now - Security Operation
Preferred:
- Offensive Certified Security Professional (OSCP)
- Any GIAC Certification (GSEC, GWAB, GPEN, GMOB, GCPN)
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM) or Certified Information Systems Auditor (CISA
- OWASP Application Security Top 10
- OWASP API Security Top 10
- OWASP Thick Client Top 10
- MITRE ATT&CK Framework
- Cloud Service testing
- Reverse Engineering