Job Description
Summary
Looking for an exciting opportunity in Cybersecurity Architecture and Penetration Testing? Deloitte is hiring a Senior Analyst / Consultant specializing in Threat Modeling, Security Architecture Reviews, and Application Security Assessments based in Chennai. This role is perfect for cybersecurity professionals with 3+ years’ experience in threat modeling frameworks like STRIDE and MITRE ATT&CK, cloud security (AWS, Azure, GCP), and deep expertise in secure design principles. As a Senior Analyst in Cybersecurity, you will assess application and cloud security architectures, identify vulnerabilities, recommend mitigation strategies, and collaborate with cross-functional teams to protect enterprise assets. If you have a passion for securing digital environments and applying advanced security methodologies, this is the role for you.
Job Details at a Glance
| Job Title | Senior Analyst – Cybersecurity Penetration Testing / Information Security Architect |
|---|---|
| Location | Chennai |
| Designation | Consultant / Senior Analyst |
| Employment Type | Full Time |
| Experience Required | 3+ Years in Cybersecurity Architecture, Threat Modeling, and Pen Testing |
| Key Tools & Frameworks | STRIDE, PASTA, MITRE ATT&CK, OWASP ASVS, NIST, ISO 27001, Microsoft Threat Modeling Tool |
| Certifications Preferred | CISSP, CSSLP, CCSP, CEH, OSCP, AWS/Azure Security Certifications |
| Shift | Day Shift |
Key Responsibilities
- Security Architecture Review & Threat Modeling
- Conduct thorough security architecture reviews across applications, cloud environments, and IT systems.
- Perform advanced threat modeling using STRIDE, PASTA, MITRE ATT&CK, and DREAD frameworks.
- Evaluate authentication, encryption, and access control mechanisms to uncover potential vulnerabilities.
- Assess security controls aligned with industry standards such as NIST, ISO 27001, OWASP, CIS Controls, and TISAX.
- Provide detailed, actionable recommendations to improve security posture and mitigate risks.
- Application & Cloud Security Assessment
- Assess security risks and configurations in web, mobile, and cloud-based applications.
- Review API security, microservices, and containerized environments for potential weaknesses.
- Validate IAM, Zero Trust models, network segmentation, encryption standards, and multi-factor authentication implementations.
- Security Risk & Compliance Evaluation
- Identify security gaps in systems and infrastructure, recommending compensating controls.
- Ensure compliance with GDPR, SOC 2, PCI-DSS, ISO 27001, and other key security frameworks.
- Collaboration & Reporting
- Prepare comprehensive security reports highlighting risks, mitigations, trust zones, data flows, and architectural improvements.
- Work closely with stakeholders to develop enterprise-wide security strategies and threat models.
- Mentor junior team members and promote security best practices within the organization.
Skills & Qualifications
- Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Information Technology, or related discipline.
- Minimum 3 years of professional experience in security architecture, threat modeling, and penetration testing.
- Deep expertise in threat modeling frameworks: STRIDE, PASTA, MITRE ATT&CK, OWASP ASVS.
- Strong knowledge of cloud security platforms (AWS, Azure, GCP), API security, microservices, and container security.
- Familiarity with IAM solutions, Zero Trust architecture, MFA, RBAC, PAM, and network security principles.
- Experience with secure SDLC processes, DevSecOps, and automated security assessment tools.
- Hands-on experience with security modeling and diagramming tools such as Microsoft Threat Modeling Tool and Microsoft Visio.
- Understanding of penetration testing methodologies, vulnerability assessment, and application security risks.
Preferred Certifications
- CISSP (Certified Information Systems Security Professional)
- CSSLP (Certified Secure Software Lifecycle Professional)
- CCSP (Certified Cloud Security Professional)
- AWS / Azure Security Certifications
- CEH (Certified Ethical Hacker) or OSCP (Offensive Security Certified Professional)
Soft Skills
- Strong analytical skills to assess and prioritize technical risks effectively.
- Proven experience designing scalable and robust security solutions.
- Excellent verbal and written communication skills for clear stakeholder engagement.
- Up-to-date knowledge of emerging cybersecurity technologies and best practices.
- Ability to work collaboratively within cross-functional teams and lead initiatives.
Location & Work Setup
- Based in Chennai, India.
- Full-time position with a collaborative work culture focused on innovation and security excellence.
Why Work at Deloitte?
- Join a global leader in Cybersecurity, IT Risk Management, and Digital Transformation.
- Work on cutting-edge projects that secure enterprise IT ecosystems.
- Access ongoing learning opportunities and career development programs.
- Thrive in an inclusive, diverse workplace that encourages innovation and leadership.
- Benefit from flexible work policies and employee wellness initiatives.
Apply Now
Ready to elevate your career as a Senior Analyst in Cybersecurity and Penetration Testing? Join Deloitte Chennai’s elite Cybersecurity team and help organizations strengthen their security posture and compliance frameworks.