Deloitte USI
Consultant, Cyber Engineering-Cyber Security SSDLC- Hyderabad
Skills
Job description
Seeking a Cyber Security Senior Analyst to support secure software development through application security assessments across the software development lifecycle. This role will help identify vulnerabilities, guide remediation, and work closely with engineering and DevOps teams to strengthen secure coding and DevSecOps practices. The role is well suited for a professional with hands-on experience in static application security testing, dynamic application security testing, software composition analysis, threat modeling, and modern application environments.
Work you'll do
As a Cyber Security Senior Analyst on the Member firm team, you will be responsible for strengthening application security across the software development lifecycle and helping teams address risk early and effectively.
Perform application security assessments across design, development, testing, and deployment phases of the software development lifecycle.
Use tools such as Snyk, StackHawk, and similar platforms to conduct static application security testing, dynamic application security testing, and software composition analysis.
Conduct threat modeling, participate in design and code reviews, and identify vulnerabilities in applications, dependencies, and runtime environments.
Partner with engineering, DevOps, and architecture teams to embed security into continuous integration and continuous deployment pipelines and promote DevSecOps practices.
Prepare assessment reports, communicate risk severity, track remediation progress, and provide guidance on prioritized fixes.
The team
At Deloitte, we’re all about collaboration. And nowhere is this more apparent than among our 2,000-strong internal services team. With our combined specialist skills, we provide all the essential support and advice our client-facing colleagues need, right across the firm. This enables them to focus all of their efforts on delivering the best service possible to their clients. Covering seven distinct areas; Human Resources, Clients & Industries, Finance & Legal, Practice Support Services, Quality & Risk Services, IT Services, and Workplace Services & Real Estate, together we live, breathe and deliver the Deloitte experience.
Location: Hyderabad
Shift Timings: 2 PM to 11 PM
Qualifications
Required:
Bachelor’s degree or equivalent
4-5 years of experience in application security, secure software development life cycle, or product security
Experience performing static application security testing, dynamic application security testing, and software composition analysis using tools such as Snyk, StackHawk, Burp Suite, or OWASP ZAP
Experience conducting threat modeling, vulnerability triage, and remediation tracking
Experience integrating security practices into continuous integration and continuous deployment pipelines
Experience working with containerized environments such as Docker or Kubernetes
Experience applying OWASP Top 10, Common Weakness Enumeration, and Common Vulnerability Scoring System in security assessments
Preferred:
Experience participating in secure design reviews and code reviews
Experience preparing security assessment reports for technical and leadership stakeholders
Experience working in Agile or DevOps environments
Experience providing security guidance or training to development teams
Security certification such as Certified Ethical Hacker, GIAC Web Application Penetration Tester, or Certified Secure Software Lifecycle Professional