Deloitte Cyber understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful insights that help clients navigate the ever-changing threat landscape and technology environment as we partner with them to transform their businesses.
Work you'll do
As a Senior Consultant on the Cyber Defense & Resilience team, you will be responsible for leading offensive security engagements and helping clients identify, validate, and remediate vulnerabilities across their digital ecosystem.
- Lead penetration testing workstreams across web, API, mobile, thick-client, network, cloud, and infrastructure environments.
- Design and execute manual and automated security assessments, validate findings, and develop remediation recommendations.
- Perform secure code reviews, application security architecture reviews, and threat modeling to identify design and implementation risks.
- Prepare client-ready reports, executive summaries, technical findings, and presentation materials, and support remediation and retesting discussions with stakeholders.
- Contribute to engagement planning, proposal support, delivery optimization, methodology development, and mentoring of junior team members.
The team
Deloitte Cyber Defense & Resilience teams assist clients in identifying, prioritizing, and remediating vulnerabilities across their digital ecosystems. Through penetration testing, application security assessments, attack surface management, red teaming, and purple teaming, our professionals help clients understand how threat actors may exploit weaknesses across applications, networks, cloud environments, endpoints, and enterprise systems. The team combines offensive security expertise with practical defensive recommendations. Our work helps clients improve detection, response, remediation, and overall cyber resilience while aligning technical findings to business priorities and risk objectives.
Location: Bengaluru/Hyderabad/Pune/Chennai
Shift Timings: General
Qualifications
Required:
- 6+ years of experience in cybersecurity, application security, vulnerability assessment, penetration testing, or cyber risk services.
- Experience conducting penetration tests across web applications, APIs, mobile applications, thick-client applications, networks, cloud environments, or enterprise infrastructure.
- Experience performing manual assessment and exploitation of vulnerabilities including SQL injection, cross-site scripting, XML external entity attacks, server-side request forgery, insecure deserialization, HTTP request smuggling, authentication weaknesses, authorization weaknesses, and business logic vulnerabilities.
- Experience performing secure code reviews and threat modeling.
- Experience using tools such as Burp Suite, Fiddler, Wireshark, Nmap, Metasploit, Nessus, Qualys, Tenable, Veracode, Frida, Apktool, JADX, dnSpy, or IDA Pro.
- One or more cybersecurity certifications such as Offensive Security Certified Professional, Offensive Security Web Expert, GIAC Penetration Tester, GIAC Web Application Penetration Tester, Certified Information Systems Security Professional, or CREST certification.
- Bachelor’s degree in Computer Science or equivalent experience.
Preferred:
- Experience with red team, purple team, breach and attack simulation, or adversary emulation engagements.
- Experience assessing Amazon Web Services, Microsoft Azure, or Google Cloud environments, including identity and access management, storage, compute, networking, containers, or Kubernetes.
- Experience testing artificial intelligence-enabled applications, large language model integrations, APIs, or agent-based systems.
- Experience developing security testing automation using Python, PowerShell, Bash, or similar scripting languages.
- Experience supporting executive briefings and presenting technical findings to technical and nontechnical audiences.
- Publications, blogs, open-source tools, conference presentations, research, or Common Vulnerabilities and Exposures submissions related to cybersecurity.