The Opportunity
We are expanding our Digital Risk team and are looking for Staff with strong hands-on expertise across at least two of the following domains:
- IT Risk
- Cloud Risk
- Technology Controls Assurance
- Third Party Digital Risk
- Cyber and Operational Resilience
As Staff, you'll contribute technically to client engagements and internal projects.
You will be responsible for executing tasks with increasing autonomy, applying sound judgment within defined parameters, and contributing to team outcomes. You are expected to demonstrate initiative, resolve routine issues independently, and support junior colleagues.
You will anticipate and identify risks within engagements and share any issues with senior members of the team. In line with EY commitment to quality, youll confirm that work is of high quality and is reviewed by the next-level reviewer.
Your Key Responsibilities Client Delivery
- Participate in application security engagements, including Threat Modelling and SDL reviews
- Perform architecture and design security assessments to identify potential risks and control gaps
- Evaluate secure SDLC controls, including design reviews, code security practices, and release governance
- Work closely with asset owners, developers, and stakeholders to explain findings and remediation actions
- Document security findings and assist in preparing client reports and presentations
- Track remediation efforts and follow up with stakeholders to ensure closure
- Continuously strive to exceed client and team expectations while handling increasingly complex assignments
- Manage day-to-day client relationships,
leading client meetings, working sessions, and status reporting.
People responsibilities
- Maintain an ongoing learning plan to enhance application security and threat modelling skills
- Adherent to organizational policies and security standards
- Participate in training programs related to secure coding, cloud security, and AppSec tools
- Exhibit initiative, teamwork, and contribute to knowledge sharing within the team
- Support junior team members when required
Skills and attributes for success
- Experience in:
- Threat Modelling methodologies (STRIDE, PASTA, etc.)
- Secure SDLC practices and security controls
- OWASP Top 10 and common application vulnerabilities
- Using SAST/DAST and security testing tools
- Reviewing authentication, authorization, encryption, and API security controls
- Robust understanding of:
- Application architecture (web, APIs, Azure, Power automate)
- Azure OpenAI Service, Azure AI Foundry, Azure Machine Learning
To qualify for the role, you must have
- Bachelors degree in B.E./B.Tech (Computer Science, IT, Electronics) or M.Sc./MCA
- At least 12 years of experience in Application Security / Secure SDLC / Threat Modelling
Additionally, good to have
- Ability to work in fast-paced client environments with multiple priorities
- Analytical mindset with attention to detail in identifying security gaps
- Strong communication skills with ability to interact with asset owners and technical stakeholders.
- Proven experience in direct client facing roles, partnering with cross functional teams to deliver assessment and remediation activities.
📌 Risk Consulting - Digital Risk - Staff - Application Security (Coimbatore)
🏢 EY
📍 Coimbatore