Grant Thornton's Cybersecurity & Privacy Advisory practice provides risk management consulting and advisory services to the clients. Cybersecurity & Privacy Advisory practice offers an excellent opportunity to leverage your information security consulting knowledge and experience to broaden your business and project management skills in a rewarding and challenging environment. Cyber Risk team is responsible for delivering a full range of services to clients and all phases of project and engagement management for multiple clients. Responsibilities include engagement planning, directing, and completion of Security Framework assessment, Vulnerability Testing, Application Security Testing, GRC Management using tools like ServiceNow, RSA Archer, Third Party Risk Assessment, and Information Security architectural design, Privacy regulations such as GDPR, CCPA; developing and supervising other Grant Thornton engagement staff; assisting in assigned client management and practice development activities.
Responsibilities
Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) across web, mobile, and API applications.
Identify, validate, and document security vulnerabilities, misconfigurations, and weaknesses in applications.
Strong knowledge of Industry standard application security tools (e.g., Burp Suite, Nmap, Zap proxy)
Collaborate with development and DevOps teams to provide remediation guidance and verify fixes.
Integrate security testing into CI/CD pipelines and DevSecOps workflows to ensure secure SDLC practices.
Conduct API security testing and ensure compliance with industry standards (OWASP Top 10, ASVS, NIST).
Prepare detailed security assessment reports and communicate findings to stakeholders.
Required Technical Skills
Hands-on experience with SAST and DAST tools (e.g., Veracode, Fortify, AppScan, Burp Suite).
Strong knowledge of API security testing methodologies and tools.
Understanding of secure coding practices, SDLC, and threat modeling.
Ability to analyze source code and debug applications for security flaws.
Familiarity with DevSecOps practices and integrating security controls into CI/CD pipelines.
Knowledge of vulnerability management and common security standards (OWASP, NIST).
Grant Thornton INDUS is the global capability center for Grant Thornton US, the U.S. member firm of Grant Thornton International Ltd., a leading global network of independent audit, tax, and advisory firms. Founded in Chicago in 1924, Grant Thornton US is one of the leading accounting and advisory firms in the U.S., bringing together $4B+ in revenue, 56 U.S. offices, and a multi-national platform spanning 20 countries with 25,000 people. It combines deep expertise, advanced technology, and a collaborative mindset to help clients solve complex challenges and grow with confidence. Since 2012, Grant Thornton INDUS has brought together 3,300+ professionals across Tax, Audit, Advisory, Client Services, Innovation, and Enabling Functions to deliver high-impact solutions for Grant Thornton US and its global network. Recognized as a Great Place To Work® for three consecutive years and among India’s Top 15 Best Workplaces™ in Professional Services 2026, INDUS offers a high-performance culture where people are trusted, supported, and empowered to grow.