T&T | Cyber: D&R I Assistant Manager | Threat Modeling | Mumbai
- Job requisition ID : 108821
- Location: Hyderabad
- Entity: Deloitte Touche Tohmatsu India LLP
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity
Your work profile
Need to be a Threat Modelling Specialist and should have a profound experience in understanding and assessing the security risks in application, network, security solutions, business logic.
Key Skills required:
- Conduct threat modelling for applications, networks, security solutions, APIs, business workflows, and processes.
- Perform security architecture reviews and identify design flaws, control gaps, and security loopholes.
- Analyze architecture diagrams, data flows, trust boundaries, and integration points.
- Identify threats, abuse cases, attack paths, and business logic weaknesses.
- Recommend practical security controls and mitigation actions.
Must have skills:
- Good knowledge on at least 2 threat modelling methodologies i.e STRIDE, PASTA, DREAD, MITRE ATT&CK based Threat Modelling.
- Familiar in security frameworks such as NIST Cybersecurity Framework, ISO 27001, ISO 42001, CIS Controls/Benchmark
- Experience with risk assessment and risk rating methodologies.
- Experience with tools used for diagramming, architecture review, or threat modelling.
- Ability to create reusable threat modelling templates, checklists, and review playbooks.
- Knowledge of threat intelligence and adversary tactics, techniques, and procedures to understand the plausibility of the threats.
- Good understanding of AI ecosystem like: Agentic AI, AI agents, A2A protocols, MCP, RAG etc
Key Deliverables:
- Security architecture review reports
- Risk and control gap assessments
- Attack path and abuse case documentation
- Data flow and trust boundary analysis
- Security recommendations and mitigation plans
- Project-specific threat libraries and checklists
- Executive-level summaries for risk stakeholders
Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.