USI - FY26 - Cyber Enterprise Security - API Security - SSA

5 years

0 Lacs

Posted:3 days ago| Platform: Linkedin logo

Apply

Work Mode

On-site

Job Type

Full Time

Job Description

Summary

Position Summary

Job title:

API Security – Senior Consultant

About

At Deloitte, we do not offer you just a job, but a career in the highly sought-after risk Management field. We are one of the business leaders in the risk market. We work with a vision to make the world more prosperous, trustworthy, and safe. Deloitte’s clients, primarily based outside of India, are large, complex organizations that constantly evolve and innovate to build better products and services. In the process, they encounter various risks and the work we do to help them address these risks is increasingly important to their success—and to the strength of the economy and public security.By joining us, you will get to work with diverse teams of professionals who design, manage, and implement risk-centric solutions across a variety of domains. In the process, you will gain exposure to the risk-centric challenges faced in today’s world by organizations across a range of industry sectors and become subject matter experts in those areas.Our Risk and Financial Advisory services professionals help organizations effectively navigate business risks and opportunities—from strategic, reputation, and financial risks to operational, cyber, and regulatory risks—to gain competitive advantage. We apply our experience in ongoing business operations and corporate lifecycle events to help clients become stronger and more resilient. Our market-leading teams help clients embrace complexity to accelerate performance, disrupt through innovation, and lead in their industries. We use cutting-edge technology like AI/ML techniques, analytics, and RPA to solve Deloitte’s clients ‘most complex issues. Working in Risk and Financial Advisory at Deloitte US-India offices has the power to redefine your ambitions.

The Team

Cyber & Strategic Risk

Deloitte’s API Security is aligned with the industry preferred practices and leverages security framework to address the API security challenges in a comprehensive manner. This process enables the client to address key vulnerabilities and risks associated with APIs at different stages of their development lifecycle.Deloitte plays a crucial role in identifying and remediating vulnerabilities in APIs accessible from within an organization, exposed to the internet, or in the client’s API infrastructure that may potentially become a threat to an organization.

Work you’ll do

Roles & Responsibilities:

As a Senior Consultant in the API Security domain, you are responsible for adhering to the defined operating procedures and guidelines in the API security services, which includes the following:
  • Support and consult with development and engineering teams in the areas of API security to discover and inventory all APIs and their exposed data across environments.
  • Integrate automated security testing (e.g., SAST, DAST, API-specific scanners) into CI/CD pipelines.Provide remediation guidance and support to development teams for identified vulnerabilities.
  • Implement and enforce security guardrails for API development, including authentication, authorization, and data protection.
  • Collaborate with DevOps, cloud, and security teams to ensure consistent delivery of secure APIs and microservices.
  • Stay current with emerging API security threats, tools, and best practices.
  • Monitor API traffic for anomalous behavior and potential threats.
  • Research and help develop security solutions to help secure applications (API Security, Data Protection, Identity Protection)
  • Experience working with AWS or other cloud environments (development/architecture)
  • Experience with cloud and API security standards (OWASP API Top 10, CIS Top 20)
  • Perform security risk assessments for all proposed application-related (APIs) changes.

Required Skills

        • 5+ years of experience in software development in one or more of the following programming languages, .NET, Python, Java/Springboot (REST), JavaScript (Node/React), and/or Go
        • Experience with tools like OWASP ZAP, Veracode, Postman, etc.
        • 3+ years of experience with API Security (Design patterns, Architecture, B2B/A2A/B2C Integration)
        • Experience with API security tools like Noname, Salt, Neosec, etc.
        • Experience with API Management solutions like Mulesoft, Apigee, etc.
        • Technical and foundational knowledge of software engineering, computer systems, security engineering, authentication, and/or applied cryptography.
        • Excellent knowledge of all web technologies, especially web services, web applications, Service Oriented Architectures, and network/web protocols
        • Knowledge of application threat modeling, Remediation of OWASP API Top 10, CIS Top 10, SANS Top 25 a plus
        • Strong understanding of authentication (OAuth2, JWT), authorization, and encryption for APIs.
        • Familiarity with cloud-native environments, containers, and microservices architectures.
        • Experience with attacker tactics, techniques, and procedures, and corresponding mitigation methods.
        • Sound knowledge of all procedures, standards, and regulations for authorization and authentication, applied cryptography, and security vulnerabilities.

Qualification

  • Bachelor's degree or higher in Computer Science, or equivalent experience.
  • Experience with application monitoring, Managed Services business primarily on DevOps, Threat and Vulnerability Management for Application infrastructure, source code verification, link analysis, and threat modeling.
  • Solid and demonstrable comprehension of Information Security including OWASP/SANS, Security Test Case development (or mis-use case), OOAD notations, emerging threats, attacks, and vulnerability management.
  • Experience with automated monitoring, alerting, and incident response for APIs.
  • Knowledge of regulatory and compliance requirements relevant to API security.
  • Ability to research and characterize security threats to include identification and classification of application related threat indicators.
  • Certification such as SANS Secure Coding, Security Engineering, Web Application Security, ISC2 CSSLP, OSCP etc. are preferred.

Good to have:

        • Experience with integrating and operating SAST tools to identify code-level vulnerabilities early in the development lifecycle.
        • Familiarity with DAST tools and methodologies for identifying runtime vulnerabilities in web applications and APIs.
        • Proficiency in using SCA tools to detect and manage risks from third-party and open-source components,
        • CI/CD integration
        • Hands-on experience embedding security controls and automated testing (SAST, DAST, SCA) into CI/CD pipelines

How You’ll Grow

At Deloitte, we’ve invested a great deal to create a rich environment in which our professionals can grow. We want all our people to develop in their own way, playing to their own strengths as they hone their leadership skills. And, as a part of our efforts, we provide our professionals with a variety of learning and networking opportunities—including exposure to leaders, sponsors, coaches, and challenging assignments—to help accelerate their careers along the way. No two people learn in the same way. So, we provide a range of resources including live classrooms, team-based learning, and eLearning. DU: The Leadership Center in India, our state-of-the-art, world-class learning Center in the Hyderabad offices is an extension of the Deloitte University (DU) in Westlake, Texas, and represents a tangible symbol of our commitment to our people’s growth and development. Explore DU: The Leadership Center in India .

Deloitte’s culture

Our positive and supportive culture encourages our people to do their best work every day. We celebrate individuals by recognizing their uniqueness and offering them the flexibility to make daily choices that can help them to be healthy, centered, confident, and aware. Deloitte is committed to achieving diversity within its workforce, and encourages all qualified applicants to apply, irrespective of gender, age, sexual orientation, disability, culture, religious and ethnic background. We offer well-being programs and are continuously looking for new ways to maintain a culture that is inclusive, invites authenticity, leverages our diversity, and where our people excel and lead healthy, happy lives. Learn more about Life at Deloitte.

Corporate citizenship

Deloitte is led by a purpose: to make an impact that matters. This purpose defines who we are and extends to relationships with Deloitte’s clients, our people and our communities. We believe that business has the power to inspire and transform. We focus on education, giving, skill-based volunteerism, and leadership to help drive positive social impact in our communities. Learn more about Deloitte’s impact on the world.

Recruiting tips

Finding the right job and preparing for the recruitment process can be tricky. Check out tips from our Deloitte recruiting professionals to set yourself up for success. Check out recruiting tips from Deloitte recruiters .

Benefits

We believe that to be an undisputed leader in professional services, we should equip you with the resources that can make a positive impact on your well-being journey. Our vision is to create a leadership culture focused on the development and well-being of our people. Here are some of our benefits and programs to support you and your family’s well-being needs. Eligibility requirements may be based on role, tenure, type of employment and/ or other criteria. Learn more about what working at Deloitte can mean for you .

Our people and culture

Our people and our culture make Deloitte a place where leaders thrive. Get an inside look at the rich diversity of background, education, and experiences of our people. What impact will you make? Check out our professionals’ career journeys and be inspired by their stories.

Professional development

You want to make an impact. And we want you to make it. We can help you do that by providing you the culture, training, resources, and opportunities to help you grow and succeed as a professional. Learn more about our commitment to developing our people .© 2025. See Terms of Use for more information.Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee ("DTTL"), its network of member firms, and their related entities. DTTL and each of its member firms are legally separate and independent entities. DTTL (also referred to as "Deloitte Global") does not provide services to clients. In the United States, Deloitte refers to one or more of the US member firms of DTTL, their related entities that operate using the "Deloitte" name in the United States and their respective affiliates. Certain services may not be available to attest clients under the rules and regulations of public accounting. Please see www.deloitte.com/about to learn more about our global network of member firms.

Our purpose

Deloitte’s purpose is to make an impact that matters for our people, clients, and communities. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. Our purpose comes through in our work with clients that enables impact and value in their organizations, as well as through our own investments, commitments, and actions across areas that help drive positive outcomes for our communities.

Our people and culture

Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ideas and perspectives, and bring more creativity and innovation to help solve our clients' most complex challenges. This makes Deloitte one of the most rewarding places to work.

Professional development

At Deloitte, professionals have the opportunity to work with some of the best and discover what works best for them. Here, we prioritize professional growth, offering diverse learning and networking opportunities to help accelerate careers and enhance leadership skills. Our state-of-the-art DU: The Leadership Center in India, located in Hyderabad, represents a tangible symbol of our commitment to the holistic growth and development of our people. Explore DU: The Leadership Center in India .

Benefits To Help You Thrive

At Deloitte, we know that great people make a great organization. Our comprehensive rewards program helps us deliver a distinctly Deloitte experience that helps that empowers our professionals to thrive mentally, physically, and financially—and live their purpose. To support our professionals and their loved ones, we offer a broad range of benefits. Eligibility requirements may be based on role, tenure, type of employment and/ or other criteria. Learn more about what working at Deloitte can mean for you.

Recruiting tips

From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.Requisition code: 301332

Mock Interview

Practice Video Interview with JobPe AI

Start DevOps Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Python Skills

Practice Python coding challenges to boost your skills

Start Practicing Python Now
Deloitte logo
Deloitte

Professional Services

New York

RecommendedJobs for You