Seeking a Cyber Security Senior Analyst to support secure software development through application security assessments across the software development lifecycle. This role will help identify vulnerabilities, guide remediation, and work closely with engineering and DevOps teams to strengthen secure coding and DevSecOps practices. The role is well suited for a professional with hands-on experience in static application security testing, dynamic application security testing, software composition analysis, threat modeling, and modern application environments.
Work you'll do
As a Cyber Security Senior Analyst on the IT Security team, you will be responsible for strengthening application security across the software development lifecycle and helping teams address risk early and effectively.
-
Perform application security assessments across design, development, testing, and deployment phases of the software development lifecycle.
-
Use tools such as Snyk, StackHawk, and similar platforms to conduct static application security testing, dynamic application security testing, and software composition analysis.
-
Conduct threat modeling, participate in design and code reviews, and identify vulnerabilities in applications, dependencies, and runtime environments.
-
Partner with engineering, DevOps, and architecture teams to embed security into continuous integration and continuous deployment pipelines and promote DevSecOps practices.
-
Prepare assessment reports, communicate risk severity, track remediation progress, and provide guidance on prioritized fixes.
The team
At Deloitte, we’re all about collaboration. And nowhere is this more apparent than among our 2,000-strong internal services team. With our combined specialist skills, we provide all the essential support and advice our client-facing colleagues need, right across the firm. This enables them to focus all of their efforts on delivering the best service possible to their clients. Covering seven distinct areas; Human Resources, Clients & Industries, Finance & Legal, Practice Support Services, Quality & Risk Services, IT Services, and Workplace Services & Real Estate, together we live, breathe and deliver the Deloitte experience.
Location: Hyderabad
Shift Timings: 2 PM to 11 PM
Qualifications
Required:
-
Bachelor’s degree or equivalent
-
4-5 years of experience in application security, secure software development life cycle, or product security
-
Experience performing static application security testing, dynamic application security testing, and software composition analysis using tools such as Snyk, StackHawk, Burp Suite, or OWASP ZAP
-
Experience conducting threat modeling, vulnerability triage, and remediation tracking
-
Experience integrating security practices into continuous integration and continuous deployment pipelines
-
Experience working with containerized environments such as Docker or Kubernetes
-
Experience applying OWASP Top 10, Common Weakness Enumeration, and Common Vulnerability Scoring System in security assessments
Preferred:
-
Experience participating in secure design reviews and code reviews
-
Experience preparing security assessment reports for technical and leadership stakeholders
-
Experience working in Agile or DevOps environments
-
Experience providing security guidance or training to development teams
-
Security certification such as Certified Ethical Hacker, GIAC Web Application Penetration Tester, or Certified Secure Software Lifecycle Professional