21 Sep
|
Deloitte
|
Delhi
The team
Financial Crime Compliance team provides proactive guidance to mitigate risks such as corruption, financial crime, fraud, and cybercrime. Leveraging global expertise, we help organizations swiftly respond to crises and protect their brand reputation through actionable advice and effective risk management strategies. Learn more about our Risk Regulatory & Forensic Practice.
Your work profile
Seeking a Manager/ Deputy Manager with solid experience in application security, SDLC governance, and application-level control analysis to work on engagements involving review of application design, workflows, and system-driven controls. The role focuses on evaluating how applications are built, configured, and used, through a combination of technical testing, control reviews, and transaction/log analysis.
Application & SDLC Control Reviews
- Evaluate application architecture and design from a controls perspective
- Assess SDLC processes, including:
- Requirement definition and control embedding
- Workflow configurations, approvals, and validations
- Change management and release governance
- Review application controls such as access management, maker-checker, and system validations
Application Analysis & Testing
- Perform application testing (functional, logic, and security-focused) using manual and automated approaches
- Identify gaps in business logic, workflows, and control configurations
- Review APIs, integrations, and data flows for consistency and control weaknesses
Data, Logs & Transaction Analysis
- Analyze application logs, audit trails, and transaction datasets
- Trace end-to-end transaction flows across systems
- Identify patterns, anomalies, and control bypass scenarios through data-driven analysis
Client Advisory & Reporting
- Document findings and provide practical, implementation-focused recommendations
- Present insights to business, operations, and technology stakeholders
- Support development of control enhancements and design improvements within applications
Engagement Delivery & Leadership
- Manage engagement delivery (timelines, quality, stakeholder expectations)
- Lead and mentor junior team members
- Contribute to solutioning and practice development initiatives
Technical ExpertiseHands-on Experience
- Application testing (manual and automated), including validation of workflows and controls
- Application logging and monitoring architectures, including audit trails and traceability
- Secure coding concepts (Java, .NET, Python, or similar) to assess control implementation
Strong understanding of:
- OWASP Top 10 vulnerabilities (from a control/design validation lens)
- Authentication, authorization, and session management mechanisms
- API security and microservices architecture, particularly in relation to data integrity and control enforcement
- Ability to analyze how application behavior aligns with business processes and system controls
Tools & Platforms Exposure to tools such as:
- Burp Suite / AppScan / Fortify / Checkmarx (for identifying gaps in implementation and validation logic)
SIEM / log analysis tools (e.g., Splunk, QRadar) for application log and transaction analysis
Key skills required:
- B.E/ B,Tech or higher qualification in computer science/ IT or any other technology domain with 5 to 8 years of experience .
- Applications security
- SDLC governance including forensic review of codes, applications and system logs
- BRDs, functional specification documents, UATs specific to applications fraud scenarios in FinTech space
- Exposure to high transaction environments (BFSI, fintech, e-commerce, etc.)
- Certifications such as CEH, CISSP, CFE (good to have)
- Willingness to travel as required in a typical Big4 client delivery model
📌 Application Security Manager (Delhi)
🏢 Deloitte
📍 Delhi