Deloitte
Website:
deloitte.com
Company:
https://www.linkedin.com/company/deloitte
Seniority: Not Applicable
Industries: Business Consulting and Services
Job details:
Summary
Position Summary
Deloitte Cyber understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful insights that help clients navigate the ever-changing threat landscape and technology environment as we partner with them to transform their businesses.
Work you'll do
As a Manager on the Cyber Defense & Resilience team, you will be responsible for leading offensive security engagements and helping clients identify, validate, and remediate vulnerabilities across applications, APIs, mobile platforms, thick-client environments, infrastructure, and cloud environments.
- Lead penetration testing and application security engagements from scoping through execution, reporting, remediation support, and closure.
- Oversee manual and automated security assessments across web applications, APIs, mobile applications, thick-client applications, infrastructure, and cloud environments.
- Review testing results, prioritize findings using Common Vulnerabilities and Exposures, Common Vulnerability Scoring System, Common Weakness Enumeration, Open Worldwide Application Security Project guidance, and business impact, and develop remediation recommendations.
- Present technical findings, risk summaries, and attack paths to client stakeholders, technology leaders, risk owners, and executive audiences, and coordinate remediation tracking through resolution.
- Manage engagement delivery, team oversight, quality reviews, reporting, proposal support, and practice development initiatives.
The team
Cyber Defense & Resilience teams help clients identify, prioritize, and remediate vulnerabilities across their digital ecosystem through penetration testing, application security, Attack Surface Management, adversary simulation, and related cybersecurity services. By continuously assessing client environments—including networks, applications, cloud assets, endpoints, APIs, and mobile platforms—our teams proactively identify exposure points before threat actors can exploit them. Penetration testing and application security are foundational capabilities within the Cyber Defense & Resilience portfolio, enabling clients to validate preventive and detective controls, reduce attack paths, and improve overall cyber resilience.
Location: Bengaluru/Hyderabad/Pune/Chennai
Shift Timings: General
Qualifications
Required:
- 9+ years of experience in cybersecurity, cyber risk services, application security, vulnerability assessment, penetration testing, or technical security roles.
- 7+ years of hands-on experience in application security, vulnerability assessment, penetration testing, mobile application security, thick-client security, and web application programming interface security assessments.
- Experience leading penetration testing and application security engagements, including planning, execution, quality review, reporting, and remediation support.
- Experience performing secure code reviews, threat modeling, application security architecture reviews, or secure design assessments.
- Experience using tools such as Burp Suite, Fiddler, Veracode, Sysinternals, Wireshark, dnSpy, IDA Pro, EchoMirage, Apktool, JADX-GUI, or Frida.
- Knowledge of OAuth 2.0, OpenID Connect, authentication and authorization models, session management, and application security vulnerabilities.
- One or more cybersecurity certifications such as Certified Information Systems Security Professional, Offensive Security Certified Professional, Offensive Security Web Expert, GIAC Penetration Tester, GIAC Web Application Penetration Tester, or CREST certification.
Preferred:
- Experience with cloud, container, microservices, mobile, thick-client, or application programming interface security assessments.
- Experience with red team, purple team, breach and attack simulation, or adversary emulation engagements.
- Experience testing artificial intelligence-enabled applications, large language model integrations, machine learning systems, or AI-assisted business processes.
- Experience assessing Amazon Web Services, Microsoft Azure, or Google Cloud environments, including identity and access management, Kubernetes, and hybrid infrastructure.
- Experience with Python, PowerShell, Bash, or comparable scripting languages used for security testing or automation.
- Publications, conference presentations, research, disclosed Common Vulnerabilities and Exposures, or offensive security methodology development.
Our purpose
Deloitte’s purpose is to make an impact that matters for our people, clients, and communities. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. Our purpose comes through in our work with clients that enables impact and value in their organizations, as well as through our own investments, commitments, and actions across areas that help drive positive outcomes for our communities.
Our people and culture
Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ways of thinking, ideas and perspectives, and bring more creativity and innovation to help solve our clients’ most complex challenges. This makes Deloitte one of the most rewarding places to work.
Professional development
At Deloitte, professionals have the opportunity to work with some of the best and discover what works best for them. Here, we prioritize professional growth, offering diverse learning and networking opportunities to help accelerate careers and enhance leadership skills. Our state-of-the-art DU: The Leadership Center in India, located in Hyderabad, represents a tangible symbol of our commitment to the holistic growth and development of our people. Explore DU: The Leadership Center in India .
Benefits To Help You Thrive
At Deloitte, we know that great people make a great organization. Our comprehensive rewards program helps us deliver a distinctly Deloitte experience that helps that empowers our professionals to thrive mentally, physically, and financially—and live their purpose. To support our professionals and their loved ones, we offer a broad range of benefits. Eligibility requirements may be based on role, tenure, type of employment and/ or other criteria. Learn more about what working at Deloitte can mean for you.
Recruiting tips
From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.
Requisition code: 362814
Click on Apply to know more.