24 Aug
|
Deloitte Shared Services India
|
Bengaluru
24 Aug
Deloitte Shared Services India
Bengaluru
Application Security Controls
Experience: 6+ Years
Role: Deputy Manager- Cyber Security / Application Security
Domain: Application Security, Cybersecurity Risk, Security Controls & Compliance
Job Overview
We are looking for a Deputy Manager Application Security Controls with strong expertise in Application Security, Cybersecurity Control Assessments, Risk Assessments, and Compliance Reviews. The role will involve leading application security control reviews, assessing the effectiveness of security controls, identifying risks and gaps, and providing remediation recommendations across application and supporting technology environments.
Key Responsibilities
- Lead and perform cybersecurity control testing to assess the design and operating effectiveness of security controls.
- Conduct Application Security control assessments against organizational requirements and industry best practices.
- Perform cybersecurity risk assessments, identify risks and impacts, and recommend appropriate mitigation strategies.
- Conduct security and compliance assessments against applicable cybersecurity frameworks and standards.
- Evaluate security governance processes and identify control gaps and improvement opportunities.
- Assess controls related to access management, authentication, logging & monitoring, vulnerability management, and data protection.
- Support internal, external, audit, and regulatory assessments through security reviews and evidence validation.
- Conduct security assessments of Web Applications, APIs, Mobile Applications, Networks, and Cloud environments.
- Identify vulnerabilities aligned with OWASP Top 10 and industry-standard attack methodologies.
- Conduct threat modeling and security architecture reviews.
- Review application security controls and provide actionable remediation recommendations.
- Validate remediation through re-testing and security verification exercises.
- Assess and provide guidance on AI/LLM security vulnerabilities and risks.
- Work closely with Development, Infrastructure, Cloud, Architecture, Operations, and Compliance teams.
- Communicate technical security risks and recommendations effectively to senior technical and business stakeholders.
Required Skills & Experience
- 6+ years of experience in Application Security, Cybersecurity, Information Security, Security Risk, or a related domain.
- Strong understanding of Application Security and Secure SDLC practices.
- Hands-on experience with Web, API, and Mobile Application Security Testing.
- Strong knowledge of Network Security and infrastructure security assessments.
- Practical experience with Cloud Security across AWS, Azure, or GCP.
- Strong understanding of authentication and authorization technologies:
- OAuth 2.0
- OpenID Connect / OIDC
- SAML
- JWT
- Experience conducting security control testing and control effectiveness assessments.
- Strong understanding of cybersecurity risk assessment and risk management methodologies.
- Knowledge of cybersecurity compliance frameworks and standards.
- Strong understanding of common attack vectors, vulnerabilities, and exploitation techniques.
- Knowledge of OWASP, NIST, CIS Benchmarks, and MITRE ATT&CK.;
- Strong analytical, reporting, documentation, and stakeholder management skills.
- Ability to translate technical security risks into clear business-level recommendations.
Preferred Certifications
- CISA
- CEH
- CCSP
- OSCP
- AWS Security Specialty
- Azure Security Engineer Associate
- CompTIA Security+
Valuable to Have
- Experience in AI/LLM Security or GenAI security assessments.
- Knowledge of OWASP LLM Top 10.
- Experience with threat modeling methodologies.
- Experience in security architecture and secure design reviews.
- Exposure to security automation and continuous security monitoring.
Interested candidates can apply with their updated resume.
📌 Application Security Controls (Bengaluru)
🏢 Deloitte Shared Services India
📍 Bengaluru