CBS Security Consultant

EY

Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

45 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

EY is seeking an Information Security Consultant to guide cloud security, risk assessments, and secure SDLC practices. You will work with Architects, IAM engineers and project teams to deliver secure, scalable solutions across hybrid cloud environments.

Ideal candidates have 7+ years in IT and 5+ years in information security, with strong knowledge of security standards, and hands-on experience in cloud and application security.

Qualifications

  • A BSc or MSc degree in Computer Science, Information Technology or a related discipline, or equivalent work experience, with preference towards advanced degrees.
  • Seven or more years of experience in Information Technology disciplines. Five or more years of experience in Information Security subject matter area with demonstrated experience in the following:
  • Experience providing and validating security requirements related to applications and information system design and implementation
  • Experience providing and validating security requirements related to cloud services and underlying networking and architectures
  • Experience conducting risk assessments, vulnerability assessments, vendor and third party risk assessments and recommending risk remediation strategies
  • Experience in the use of tools and methods to identify security exposures and business risks
  • Knowledge of common information security standards, such as: ISO, NIST, COBIT
  • Familiarity with information system attack methods and vulnerabilities and threat modelling
  • Working experience with web technologies and programming languages
  • Working experience with more than one of these technologies and products - Java, .NET, NodeJS, Angular, Power Apps, Kubernetes

Responsibilities

  • Direct information security assurance efforts with 3rd parties and vendors, including reviews and controls verification.
  • Perform risk assessments of cloud services and hosting infrastructure.
  • Assess security posture impact of change requests and guide DevOps teams.
  • Design and implement security controls to satisfy approved requirements.
  • Supervise security attestation activities (scans, pentests, audits).
  • Translate security findings into business risk language for management.
  • Collaborate with Architects, Developers, IAM engineers and Project Managers.

Skills

Security architecture
Cloud security
IAM
Security standards
DevOps / Agile
Strong communication

Education

BSc or MSc in CS/IT or related

Tools

Java
.NET
NodeJS
Angular
Power Apps
Kubernetes

Job description

At EY, we’re all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

Security Consultant
Job Summary

As an Information Security Consultant, the individual will be responsible for providing security guidance to projects and operations teams responsible for delivering, respectively maintaining, IT cloud-based solutions. The Consultant will support the entire system development lifecycle (SDLC) of business IT solutions with information security expertise and guidance. This includes performing a risk assessment of the solution and the underpinning cloud infrastructure in order to derive adequate risk treatment options, driving the security assurance activities with cloud vendors, specifying and prioritizing security requirements, directing the design of security controls, supervising the security attestation activities and effectively articulating all related findings, issues, recommendations to team members and management, assessing the security impact of change requests and providing the operations teams with related recommendations and decisions.

The successful candidate should have solid background in web services architecture and design, networking principles supporting hybrid cloud models, experience in applications development processes and methodologies (experience in agile application development and DevOps operations mode is strongly preferred), as well as oversight knowledge of infrastructure and hosting technologies leveraging virtualization and containerization. The successful candidate should have broad consulting or security assurance experience across all Information Security knowledge areas relevant to modern cloud-based architectures.

EY Technology

Technology has always been at the heart of what we do and deliver at EY. We need technology to keep an organization the size of ours working efficiently. We have 250,000 people in more than 140 countries, all of whom rely on secure technology to be able to do their job every single day. Everything from the laptops we use, to the ability to work remotely on our mobile devices and connecting our people and our clients, to enabling hundreds of internal tools and external solutions delivered to our clients. Technology solutions are integrated in the client services we deliver and is key to us being more innovative as an organization.

  • Client Technology (CT) - focuses on developing new technology services for our clients. It enables EY to identify new technology-based opportunities faster, and pursue those opportunities more rapidly.
  • Enterprise Workplace Technology (EWT –) EWT supports our Core Business Services functions and will deliver fit-for-purpose technology infrastructure at the cheapest possible cost for quality services. EWT will also support our internal technology needs by focusing on a better user experience.
  • Information Security (Info Sec) - Info Sec prevents, detects, responds and mitigates cyber-risk, protecting EY and client data, and our information management systems.
The opportunity

The Security Consultant reports to Deputy CISO of Enterprise Workplace Technology in a hands-on role, focused on the secure design, architecture and development for applications, which processes sensitive data and constitutes core as well as critical business services. The Security Consultant works directly with Architects, Developers, IAM engineers, Project Managers and other resources; through collaboration and mentoring, they help teams to deliver secure business solutions.

Your key responsibilities
  • Directing and managing solution-specific information security assurance efforts with 3rd parties and vendors, like backend reviews, controls verification and validation, etc., oriented on standards and frameworks like ISO, COBIT, NIST, TSC, etc.
  • Risk assessments (threats, vulnerabilities) of cloud services and applications
  • Risk assessments of cloud hosting infrastructure underpinning the services and applications
  • Security assessment of architecture and networking supporting the services and applications
  • Derivation of risk treatment options from risk assessments and effectively facilitating the implementation of the optimal security-usability trade-off in interactions with project teams and management
  • Identifying, specifying and prioritizing security requirements in new applications and services deployment, as well as specifying and facilitating security changes in DevOps operations mode of existent applications
  • Directing the design of security controls to satisfy the approved security requirements
  • Supervising and managing various types of security attestation activities (scans, pentests, audits), including the definition of scope, pass criteria, contribution to test scenarios, articulating and formalizing findings and decisions
  • Assessing the security posture impact of change requests and providing the operations teams with related recommendations and decisions
  • Effectively communicating the findings, recommendations and decisions from all above activities, by adapting the form and depth of statements adequately to audiences and stakeholders
  • Translating technical security terms and concepts into business risk terminology to facilitate making objective and security-aware risk decisions by management
  • Providing knowledge sharing and technical assistance to other team members
  • Acting as an agile team member according to established agile development best practices and guidelines
Skills and attributes for success

The position requires knowledge of various IT system architectures and technologies like cloud, virtualization, containerization, mobile, as well as expertise and experience in security subject matter areas such as IAM, network and perimeter security, web applications security, user account management, privileged access, auditing & logging, and others as outlined in ISO 27001, OWASP, NIST and related guidelines and standards. The consultant filling the position should also have experience in conduction of 3rd party security assessments, in particular within the scope of SOC1, SOC2 reports, and in vendor risk management.

  • Agile & DevOps Methodologies – Experience as a contributing member of a balanced team within an Agile development or DevOps environment.
  • Application Security - Experience with the design of security controls for multi-tier business solutions including the design of application-level access and entitlement management, data tenancy and isolation, encryption, and logging. Working familiarity with REST API and micro services architecture.
  • Cloud Security –Technical understanding of virtualization, cloud infrastructure, and public cloud offerings and experience designing security configuration and controls within cloud based solutions in Microsoft Azure and Azure PAAS services
  • Infrastructure Security – Experience with the integration of common infrastructure security technologies and solutions into business solution architectures including the integration of identity & access management, intrusion detection and prevention, security monitoring, and data encryption solutions.
  • Identity and Access Management - Active Directory based Identity and Access Management and Authorization design experience and integration with IDaaS and Federation technologies.
To qualify for the role you must have

A BSc or MSc degree in Computer Science, Information Technology or a related discipline, or equivalent work experience, with preference towards advanced degrees.

Seven or more years of experience in Information Technology disciplines. Five or more years of experience in Information Security subject matter area with demonstrated experience in the following:

  • Experience providing and validating security requirements related to applications and information system design and implementation
  • Experience providing and validating security requirements related to cloud services and underlying networking and architectures
  • Experience conducting risk assessments, vulnerability assessments, vendor and third party risk assessments and recommending risk remediation strategies
  • Experience in the use of tools and methods to identify security exposures and business risks
  • Knowledge of common information security standards, such as: ISO, NIST, COBIT
  • Familiarity with information system attack methods and vulnerabilities and threat modelling
  • Working experience with web technologies and programming languages
  • Working experience with more than one of these technologies and products - Java, .NET, NodeJS, Angular, Power Apps, Kubernetes
Ideally you'll also have
  • A vendor-neutral security certification of DoD IAT Level II-III or DoD IAM Level II-III is strongly preferred (SSCP, Security+, CEH, CISSP, CISM)
  • A vendor-specific cloud security certification would be an additional asset (Microsoft AZ-500, AWS Security Specialty, …)
  • Proven experience as a standing member of an agile development team (in any agile role) or as DevOps operations mode contributor would be an additional asset,
  • Proven experience with either of the Adobe cloud products would be an additional assets.
What we look for
  • Ability to team well with others to facilitate and enhance the understanding & compliance to security policies
  • Ability to work effectively with customers, management, staff members, vendors, and consultants and articulate findings and recommendations
  • Strong English communication and writing skills are required
  • Strong judgment and analytical ability
  • Excellent interpersonal, communication, organizational, and project management skills
  • Flexibility to adjust to multiple demands, shifting priorities, ambiguity, and rapid change
What working at EY offers
  • Support, coaching and feedback from some of the most engaging colleagues around
  • Opportunities to develop new skills and progress your career
  • The freedom and flexibility to handle your role in a way that’s right for you
EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

TC-CS-Cyber Architecture- OT and Engineering-infrastructure Security-Manager
TC-CS-Cyber Architecture- OT and Engineering-infrastructure Security-Manager

EY • Thiruvananthapuram

On-site
INR 1,400,000 - 2,100,000
Health insurance
Flexible work environment
Learning opportunities
FS-RISK CONSULTING-TPRM-SENIOR
FS-RISK CONSULTING-TPRM-SENIOR

EY • Hyderabad

On-site
INR 1,000,000 - 1,600,000
Flexible working
Career development
Senior Infrastructure Security Consultant
Senior Infrastructure Security Consultant

Ernst & Young LLP ( EY India ) • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Coaching and feedback
Career development
Flexible work options
TC-CS-SRCR-Risk and Compliance-SeniorManager
TC-CS-SRCR-Risk and Compliance-SeniorManager

EY • Bengaluru

On-site
INR 4,200,000 - 6,400,000
TC-CS-Cyber Architecture-OT And Engineering- Netskope SASE-Senior
TC-CS-Cyber Architecture-OT And Engineering- Netskope SASE-Senior

EY • Hyderabad

On-site
INR 1,500,000 - 2,200,000
Support & coaching
Career development
Flexible working style
TC-CS-Cyber Architecture-OT And Engineering- Netskope SASE-Senior
TC-CS-Cyber Architecture-OT And Engineering- Netskope SASE-Senior

EY • Mumbai

On-site
INR 2,500,000 - 4,000,000
Coaching and feedback
Career development opportunities
Flexible work arrangements
TC-CS-SRCR- Cyber Risk And Compliance- Senior
TC-CS-SRCR- Cyber Risk And Compliance- Senior

EY • Chennai District

On-site
INR 1,800,000 - 3,000,000
TC-CS-Cyber Architecture-OT And Engineering- Netskope SASE-Senior
TC-CS-Cyber Architecture-OT And Engineering- Netskope SASE-Senior

EY • Gurugram District

On-site
INR 1,500,000 - 2,100,000
TC-CS-Cyber Architecture-OT and Engineering- Netskope SASE-Senior
TC-CS-Cyber Architecture-OT and Engineering- Netskope SASE-Senior

EY • Kolkata District

On-site
INR 1,800,000 - 2,500,000
Support and coaching from engaging colleagues
Opportunities for skill development
Flexible working options
Senior Cyber Security Architect - Network & Cloud Security
Senior Cyber Security Architect - Network & Cloud Security

Ernst & Young LLP ( EY India ) • Bengaluru

On-site
INR 3,500,000 - 7,000,000