Cyber
Deloitte Cyber understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful insights to help our clients navigate the ever-changing threat design and technology as we partner with clients to transform finance.
Position Summary
Level: Solution Delivery Lead
Work you’ll do:
- Conduct vulnerability assessments and manual penetration testing for web, API, thick client, and mobile applications.
- Perform secure code reviews and analyze false positives from industry-standard tools.
- Respond to ad-hoc reporting and research requests.
- Develop and implement application security policies and procedures.
- Identify and prioritize security vulnerabilities.
- Coordinate with development and operations teams on remediation plans.
- Quickly understand and deliver on company and client requirements.
- Participate in regular reporting for clients, partners, and internal teams.
- Adhere to internal operational security and Deloitte policies.
The team:
Cyber Operate teams manage and operate clients’ critical cyber assets through fully managed services or collaborative models, delivering skilled talent, advanced technology, and robust processes. They oversee the identity lifecycle, security operations, threat intelligence, application security, business transformation, and continuous compliance, with services including Cyber-as-a-Service, Managed Application Security, and Managed Extended Detect & Respond (MXDR). DevSecOps complements these operations by automating security testing within CI/CD pipelines and integrating security throughout the development lifecycle, enabling agile, risk-based delivery. Deloitte’s DevSecOps framework streamlines operations, supports continuous integration and delivery, and embeds secure-by-design principles across cloud and application environments for timely vulnerability identification and remediation.
Qualifications:
Must Have Skills/Project Experience/Certifications:
- 5–7 years of hands-on experience in:
- Application security
- Vulnerability assessment
- Penetration testing
- Mobile application security
- Thick client and Web API security assessments
- Strong understanding of OWASP Top 10 and related vulnerabilities.
- Experience in manual assessment and exploitation (e.g., Blind SQLi, XXE, SSRF, Insecure Deserialization, HTTP Request Smuggling).
- Understanding of OAUTHv2/OpenID standards and business logic vulnerabilities.
- Experience with secure code review (OWASP Secure Coding Practices).
- Proficiency with tools: Burp Suite, Fiddler, Sysinternals, Veracode, DnSpy, OllyDbg, IDA Pro, EchoMirage, Wireshark, Apktool, Jadx-gui, Frida, etc.
- Ability to perform manual penetration testing and use automated tools.
- Excellent technical report writing skills.
- Knowledge of web application components (frontend, backend, databases, application servers).
- Understanding of web development technologies (HTML, CSS, JavaScript, PHP, Java, .NET, backend databases).
- Experience with application security architecture review and threat modeling.
- Basic concepts of reverse engineering and memory analysis.
- Understanding of networking protocols (TCP/IP, DNS, HTTP/S).
- Familiarity with vulnerability classification (CVE/CVSS).
- Certifications: CISSP, OSCP, OSWE, BSCP, GWAPT.
Good to Have Skills/Project Experience/Certifications:
- Proficiency in web and mobile application security assessments, penetration testing, and secure code review.
- Relevant publications (blogs, tools, conference presentations, CVEs).
- Preferred certifications: OSWE, BSCP.
- Experience with automation and scripting (Python).
- Outstanding English written and oral communication skills.
- Strong understanding of web, mobile, and microservices vulnerabilities.
- Knowledge of malicious code operation and exploitation.
- Strong analytical and problem-solving skills.
- Self-motivated and eager to learn new attack vectors.
- Desire to deeply understand the what, why, and how of security vulnerabilities.
Education:
- Bachelor’s degree or higher in Computer Science, or equivalent experience.
Location:
- Bangalore, Hyderabad, Pune, Chennai, Kolkata
Shift Timings:
- Flexibility for night, weekend, and holiday coverage is essential.
- Must be willing to work 24*7 rotational shifts
- On call support required based on project assignments