Job Description
As a part this team, you will:
- Work as a Senior Analyst in the ITS Cybersecurity Team supporting Deloitte .
- Deploy, configure, and maintain security tools such as SAST, DAST, SCA, and secret scanning tools within the CI/CD pipeline.
- Ensure security tools are integrated seamlessly into the development workflow to provide real-time feedback to developers.
- Perform static and dynamic security testing on codebases to identify vulnerabilities.
- Conduct software composition analysis to detect and manage open-source vulnerabilities.
- Implement secret scanning to identify and mitigate the exposure of sensitive information.
- Analyze and triage security findings from various security tools.
- Work closely with development teams to prioritize and remediate vulnerabilities based on risk assessment and business impact.
- Collaborate with developers to understand the code and provide guidance on secure coding practices.
- Conduct training sessions and workshops to educate development teams on security best practices and the use of security tools.
- Build or maintain CI/CD building blocks and shared libraries proactively for development teams to enable quicker build and deployment.
- Monitor and evaluate the effectiveness of security tools and processes, and implement improvements as needed.
Work Location: Hyderabad
Shift Timings: 06.30 AM to 03.30 PM
The Team:
The Cybersecurity team at Deloitte, part of ITS group, is dedicated to protecting the company's digital assets and infrastructure. With a focus on maintaining a secure and resilient security posture, the team uses industry-standard security practices and tools to manage risks and respond to security incidents. Their goal is to ensure the confidentiality, integrity, and availability of Deloitte Australia's data, systems, and applications.
Qualifications
Required:
- 3+ years of experience in a DevSecOps, Application Security, or related role.
- Comprehensive technical expertise in a variety of DevSecOps toolkits
- Proficiency in security testing tools such as SAST (e.g., Checkmarx, SonarQube), DAST (e.g., OWASP ZAP, Burp Suite), SCA (e.g., Black Duck, Snyk), and secret scanning (e.g., GitGuardian).
- Strong understanding of CI/CD pipelines and experience with tools like Jenkins, GitLab CI, or CircleCI.
- Familiarity with container security and orchestration tools (e.g., Docker, Kubernetes).
- Hold a bachelor’s degree in computer science, Information Technology, Cybersecurity or related field.
- Excellent problem-solving and analytical skills.
- Strong communication skills with the ability to explain technical concepts to non-technical stakeholders.