23 Sep
|
Deloitte
|
India
The team Financial Crime Compliance team provides proactive guidance to mitigate risks such as corruption, financial crime, fraud, and cybercrime. Leveraging global expertise, we help organizations swiftly respond to crises and protect their brand reputation through actionable advice and effective risk management strategies. Learn more about our Risk Regulatory & Forensic Practice. Your work profile Seeking a Manager/ Deputy Manager with solid experience in application security, SDLC governance, and application-level control analysis to work on engagements involving review of application design, workflows, and system-driven controls. The role focuses on evaluating how applications are built, configured, and used, through a combination of technical testing, control reviews, and transaction/log analysis. Application & SDLC Control Reviews Evaluate application architecture and design from a controls perspective Assess SDLC processes, including: Requirement definition and control embedding Workflow configurations, approvals, and validations Change management and release governance Review application controls such as access management, maker-checker, and system validations Application Analysis & Testing Perform application testing (functional, logic, and security-focused) using manual and automated approaches Identify gaps in business logic, workflows, and control configurations Review APIs, integrations, and data flows for consistency and control weaknesses Data, Logs & Transaction Analysis Analyze application logs, audit trails, and transaction datasets Trace end-to-end transaction flows across systems Identify patterns, anomalies, and control bypass scenarios through data-driven analysis Client Advisory & Reporting Document findings and provide practical,
implementation-focused recommendations Present insights to business, operations, and technology stakeholders Support development of control enhancements and design improvements within applications Engagement Delivery & Leadership Manage engagement delivery (timelines, quality, stakeholder expectations) Lead and mentor junior team members Contribute to solutioning and practice development initiatives Technical Expertise Hands-on Experience Application testing (manual and automated), including validation of workflows and controls Application logging and monitoring architectures, including audit trails and traceability Secure coding concepts (Java, .NET, Python, or similar) to assess control implementation Strong understanding of: OWASP Top 10 vulnerabilities (from a control/design validation lens) Authentication, authorization, and session management mechanisms API security and microservices architecture, particularly in relation to data integrity and control enforcement Ability to analyze how application behavior aligns with business processes and system controls Tools & Platforms Exposure to tools such as: Burp Suite / AppScan / Fortify / Checkmarx (for identifying gaps in implementation and validation logic) SIEM / log analysis tools (e.g., Splunk, QRadar) for application log and transaction analysis Key skills required: B.E/ B,Tech or higher qualification in computer science/ IT or any other technology domain with 5 to 8 years of experience . Applications security SDLC governance including forensic review of codes, applications and system logs BRDs, functional specification documents, UATs specific to applications fraud scenarios in FinTech space Exposure to high transaction environments (BFSI, fintech, e-commerce, etc.) Certifications such as CEH, CISSP, CFE (good to have) Willingness to travel as required in a typical Big4 client delivery model
📌 Application Security Manager (India)
🏢 Deloitte
📍 India