Deloitte Cyber understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful insights that help clients navigate the ever-changing threat landscape and technology environment as we partner with them to transform their businesses.
Work you'll do
As a Senior Consultant on the Cyber Defense & Resilience team, you will be responsible for leading offensive security engagements and helping clients identify, validate, and remediate vulnerabilities across their digital ecosystem.
- Lead penetration testing workstreams across web, API, mobile, thick-client, network, cloud, and infrastructure environments.
- Design and execute manual and automated security assessments, validate findings, and develop remediation recommendations.
- Perform secure code reviews, application security architecture reviews, and threat modeling to identify design and implementation risks.
- Prepare client-ready reports, executive summaries, technical findings, and presentation materials, and support remediation and retesting discussions with stakeholders.
- Contribute to engagement planning, proposal support, delivery optimization, methodology development, and mentoring of junior team members.
The team
Deloitte Cyber Defense & Resilience teams assist clients in identifying, prioritizing, and remediating vulnerabilities across their digital ecosystems. Through penetration testing, application security assessments, attack surface management, red teaming, and purple teaming, our professionals help clients understand how threat actors may exploit weaknesses across applications, networks, cloud environments, endpoints, and enterprise systems. The team combines offensive security expertise with practical defensive recommendations. Our work helps clients improve detection, response, remediation, and overall cyber resilience while aligning technical findings to business priorities and risk objectives.
Location: Bengaluru/Hyderabad/Pune/Chennai
Shift Timings: General
Qualifications
Required:
- 6+ years of experience in cybersecurity, application security, vulnerability assessment, penetration testing, or cyber risk services.
- Experience conducting penetration tests across web applications, APIs, mobile applications, thick-client applications, networks, cloud environments, or enterprise infrastructure.
- Experience performing manual assessment and exploitation of vulnerabilities including SQL injection, cross-site scripting, XML external entity attacks, server-side request forgery, insecure deserialization, HTTP request smuggling, authentication weaknesses, authorization weaknesses, and business logic vulnerabilities.
- Experience performing secure code reviews and threat modeling.
- Experience using tools such as Burp Suite, Fiddler, Wireshark, Nmap, Metasploit, Nessus, Qualys, Tenable, Veracode, Frida, Apktool, JADX, dnSpy, or IDA Pro.
- One or more cybersecurity certifications such as Offensive Security Certified Professional, Offensive Security Web Expert, GIAC Penetration Tester, GIAC Web Application Penetration Tester, Certified Information Systems Security Professional, or CREST certification.
- Bachelor’s degree in Computer Science or equivalent experience.
Preferred:
- Experience with red team, purple team, breach and attack simulation, or adversary emulation engagements.
- Experience assessing Amazon Web Services, Microsoft Azure, or Google Cloud environments, including identity and access management, storage, compute, networking, containers, or Kubernetes.
- Experience testing artificial intelligence-enabled applications, large language model integrations, APIs, or agent-based systems.
- Experience developing security testing automation using Python, PowerShell, Bash, or similar scripting languages.
- Experience supporting executive briefings and presenting technical findings to technical and nontechnical audiences.
- Publications, blogs, open-source tools, conference presentations, research, or Common Vulnerabilities and Exposures submissions related to cybersecurity.
Our purpose
Deloitte’s purpose is to make an impact that matters for our people, clients, and communities. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. Our purpose comes through in our work with clients that enables impact and value in their organizations, as well as through our own investments, commitments, and actions across areas that help drive positive outcomes for our communities.
Professional development
At Deloitte, professionals have the opportunity to work with some of the best and discover what works best for them. Here, we prioritize professional growth, offering diverse learning and networking opportunities to help accelerate careers and enhance leadership skills. Our state-of-the-art DU: The Leadership Center in India, located in Hyderabad, represents a tangible symbol of our commitment to the holistic growth and development of our people. Explore DU: The Leadership Center in India.
Benefits to help you thrive
At Deloitte, we know that great people make a great organization. Our comprehensive rewards program helps us deliver a distinctly Deloitte experience that helps that empowers our professionals to thrive mentally, physically, and financially—and live their purpose. To support our professionals and their loved ones, we offer a broad range of benefits. Eligibility requirements may be based on role, tenure, type of employment and/ or other criteria. Learn more about what working at Deloitte can mean for you.
Recruiting tips
From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.