Responsibilities
As a key member of the IT Security team, you will play a pivotal role in driving and overseeing security-related projects, initiatives and security reviews for the team. Your responsibilities will span across the lifecycle of security controls, from assessment and implementation to ongoing review and enhancement, ensuring that the organization’s IT environment remains secure, compliant, and resilient.
Key Responsibilities
Project & Initiative Leadership
Security Control Reviews
- Lead periodic and ad hoc reviews of critical security controls, such as network access, authentication, and exception management processes.
- Review of the firewall configurations and inactive/risky rules.
- Coordinate and execute comprehensive reviews of existing security configurations and policies to ensure ongoing compliance with internal standards and regulatory requirements.
- Identify gaps or areas for improvement in current security controls and recommend actionable enhancements.
- Lead internal initiatives and global Audit engagements for Cyber.
- Identify opportunities to automate repetitive or manual security processes, increasing efficiency and reducing risk.
- Collaborate with cross-functional teams to assess, design, and implement security controls for new/existing technologies, products, and platforms.
- Conduct security impact assessments for new solutions, tools, and services being introduced into the environment.
- Oversee the evaluation and approval process for security exceptions, ensuring that risks are properly documented, mitigated, and tracked.
- Facilitate risk assessments for changes in IT infrastructure, applications, or access policies.
- Provide guidance and recommendations for risk remediation and exception handling.
Skills:
· Comprehensive knowledge of IT security principles and frameworks, including risk management, security controls, and regulatory compliance.
· Experience with security reviews and assessments for IT infrastructure, applications, and new technology deployments.
· Proficiency in automation tools and streamline security processes and reporting.
· Familiarity with workflow automation platforms (e.g., ServiceNow, Ansible, or similar) for process optimization.
· Strong understanding of security technologies, such as firewalls, endpoint protection, identity and access management (IAM), and vulnerability management solutions.
· Hands-on experience with security incident management, including detection, analysis, response, and remediation in both cloud and on-premise environments.
· Ability to evaluate and integrate security requirements into new projects, products, and IT initiatives.
· Experience with exception management processes, including risk assessment, documentation, and remediation planning.
· Excellent analytical and problem-solving skills, with the ability to identify gaps and recommend improvements in security controls.
· Effective communication and stakeholder management skills, with the ability to translate technical security requirements for non-technical audiences.
· Demonstrated ability to lead and collaborate within cross-functional teams, fostering a culture of continuous improvement.
· Experience with DevSecOps practices and integrating security into CI/CD pipelines is an advantage.
· Strong organizational skills to manage multiple projects, reviews, and automation initiatives simultaneously.
Education: Bachelor’s Degree or equivalent
Experience: 5-6 years of relevant experience.
Work Location: Hyderabad
Shift Timings: 11 AM to 2 PM IST or 2 PM to 11 PM IST.
The Team
At Deloitte, we’re all about collaboration. And nowhere is this more apparent than among our 2,000-strong internal services team. With our combined specialist skills, we provide all the essential support and advice our client-facing colleagues need, right across the firm. This enables them to focus all of their efforts on delivering the best service possible to their clients. Covering seven distinct areas; Human Resources, Clients & Industries, Finance & Legal, Practice Support Services, Quality & Risk Services, IT Services, and Workplace Services & Real Estate, together we live, breathe and deliver the Deloitte experience.