Grant Thornton's Cybersecurity & Privacy Advisory practice provides risk management consulting and advisory services to the clients. Cybersecurity & Privacy Advisory practice offers an excellent opportunity to leverage your information security consulting knowledge and experience to broaden your business and project management skills in a rewarding and challenging environment. Cyber Risk team is responsible for delivering a full range of services to clients and all phases of project and engagement management for multiple clients. Responsibilities include engagement planning, directing, and completion of Security Framework assessment, Vulnerability Testing, Application Security Testing, GRC Management using tools like ServiceNow, RSA Archer, Third Party Risk Assessment, and Information Security architectural design, Privacy regulations such as GDPR, CCPA; developing and supervising other Grant Thornton engagement staff; assisting in assigned client management and practice development activities.
Responsibilities
Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) across web, mobile, and API applications.
Identify, validate, and document security vulnerabilities, misconfigurations, and weaknesses in applications.
Strong knowledge of Industry standard application security tools (e.g., Burp Suite, Nmap, Zap proxy)
Collaborate with development and DevOps teams to provide remediation guidance and verify fixes.
Integrate security testing into CI/CD pipelines and DevSecOps workflows to ensure secure SDLC practices.
Conduct API security testing and ensure compliance with industry standards (OWASP Top 10, ASVS, NIST).
Prepare detailed security assessment reports and communicate findings to stakeholders.
Required Technical Skills
Hands-on experience with SAST and DAST tools (e.g., Veracode, Fortify, AppScan, Burp Suite).
Strong knowledge of API security testing methodologies and tools.
Understanding of secure coding practices, SDLC, and threat modeling.
Ability to analyze source code and debug applications for security flaws.
Familiarity with DevSecOps practices and integrating security controls into CI/CD pipelines.
Knowledge of vulnerability management and common security standards (OWASP, NIST).