As an Assistant Manager, Cybersecurity Architecture focused on Secure System Development Lifecycle (SSDLC) and Release Governance, you will help embed security into Deloitte Global’s design, build, and release processes. This hands-on role supports secure development governance and assurance while advancing automation capabilities that apply security controls consistently before release. You will also contribute to the evolution of policy-as-code and AI-assisted ways of working that strengthen security, scalability, and operational efficiency across the software development lifecycle.
Work you'll do
As an Assistant Manager, Cybersecurity Architecture on the Deloitte Global Cybersecurity team, you will be responsible for:
- Support and continually improve day-to-day SSDLC governance and assurance activities, including maintaining security requirements, controls, policies, standards, procedures, and supporting guidance.
- Serve as a subject matter resource for SSDLC assessments by providing practical guidance to assessors and delivery teams, identifying control gaps, exceptions, and non-compliance, and supporting remediation through resolution.
- Operate and enhance the Secure Release Framework by translating written security requirements into codified, testable policies and expanding automated control coverage over time.
- Support the integration of security checks and release gates into continuous integration/continuous deployment pipelines, working with engineering teams to promote reliable, scalable, and low-friction adoption.
- Apply AI tooling to support control mappings, release-gate policies, evidence generation, standards interpretation, and AI-assisted standards search capabilities at scale.
- Use ServiceNow to track assessments, exceptions, and risk; produce reporting on program performance, compliance posture, and control effectiveness; and support security risk assessments, risk acceptance documentation, and stakeholder enablement activities.
The team
This team helps strengthen secure development practices across Deloitte Global by embedding cybersecurity requirements into the software delivery lifecycle. Working across governance, risk, compliance, architecture, and engineering stakeholders, the team focuses on building practical, scalable approaches to security assurance. The group is also advancing automation and policy-as-code capabilities to improve control consistency, streamline release governance, and support secure adoption of emerging technologies.
Location: Hyderabad
Shift Timings: 11 AM to 8 PM
Qualifications
Required:
- 6+ years of experience in cybersecurity, application security, software security, information technology risk, or security governance
- Experience with software development lifecycle, Agile delivery practices, and continuous integration/continuous deployment concepts
- Experience with secure development principles and application security risks, including Open Worldwide Application Security Project Top 10 guidance
- Experience with security testing approaches, including static application security testing, dynamic application security testing, software composition analysis, and vulnerability management
- Experience working with configuration, code, and policy-as-code concepts in support of security automation
- Experience using artificial intelligence tooling to support technical, governance, or documentation-related work products
- Bachelor’s degree in computer science, engineering, or a technical or security discipline; or a security certification such as CompTIA Security+, ISC2 Certified in Cybersecurity, or Associate of ISC2
Preferred:
- Experience with policy-as-code tools such as Open Policy Agent/Rego and implementing security gates in continuous integration/continuous deployment pipelines
- Experience with GitHub, Azure DevOps, Snyk, ServiceNow, or comparable governance, risk, and compliance and workflow platforms
- Experience with scripting languages such as Python or PowerShell
- Experience with secure development frameworks such as National Institute of Standards and Technology Secure Software Development Framework, Open Worldwide Application Security Project Software Assurance Maturity Model, Open Worldwide Application Security Project Application Security Verification Standard, or Microsoft Security Development Lifecycle
- Experience with software supply chain security concepts, including software bill of materials and Supply-chain Levels for Software Artifacts
- Experience with artificial intelligence security and governance frameworks, cloud-native development environments, or certifications such as CSSLP, GSEC, Azure AZ-500, AWS Security, CISSP, or CCSP