Back to Job Portal
D

Consultant | Web/Mobile/API Application Security | Mumbai | Cyber Defense & Resilience | Security Op

Deloitte · Mumbai, India
Posted August 4, 2026 via Deloitte

No

CLIENT SITE Scope

Major Activities

Activity Details

 Reports

Internal (CLIENT SITE Premises)

1

Source Code Review (SCR)

Annually and Adhoc as per requirement

1.       Conduct source code security assessment for all in-scope internal and external applications, server library code once in annual or when the change in code has been made (whichever applicable first).

2.       Provide report with findings, Impact, severity and recommendations.

3.       All Test cases and parameters should be covered as per the standard OWASP Secure Coding Practices checklist.

4.       Manual assessments with false positive elimination (If required).

5.       Support team for closure.

6.       Dashboard having detail of Vulnerability along with Severity and Closure status along with Customizable dashboard.

7.       Technical assistance for Audit like internal and external audit.

8.       Assistance and preparation of advisory / Threat feeds

9.       Review of Internal reports and external reports.

10.    Follow-up with respective stakeholders for the closure of open vulnerabilities.

11.    To Maintain a consolidated tracker for the activities performed on daily basis.

12.    Secure coding training to application development teams across the organization to promote the adoption of secure development practices

13.    Tool management: -

a)       Maintenance and management SCR tool and manage the user creation/deletion/dormant user removal.

b)       Follow up with OEM in case of hardware failure, firmware upgrade, raised ticket, and ensure OEM SLA is met

c)       Ensure back-up is taken on a monthly basis.

d)       Ensure tool is updated with latest updates as and when it is released by vendor.

Detailed Management level MIS and Dashboard creation to be captured on fortnight basis.

2

Application Security (Web/Mobile)

Annually and Adhoc as per requirement

1.       Conduct application security (Appsec) assessment for all in-scope internal and external web, android and iOS applications once in annual or when the change in modules/UI has been made (whichever applicable first).

2.       Provide report with findings, Impact, severity and recommendations.

3.       All Test cases and parameters should be covered as per the OWASPTop10 Application/Mobile checklist.

4.       Manual assessments with false positive elimination.

5.       Support team for closure.

6.       Dashboard having detail of Vulnerability along with Severity and Closure status along with Customizable dashboard.

7.       Technical assistance for Audit like internal and external audit.

8.       Assistance and preparation of advisory / Threat feeds

9.       Review of Internal reports and external reports.

10.    Follow-up with respective stakeholders for the closure of open vulnerabilities.

11.    To Maintain a consolidated tracker for the activities performed on daily basis.

12.    Severity should be determined based on the applicable CVSS (Common Vulnerability Scoring System) score.

13.    Tool management: -

e)       Maintenance and management Appsec tools and manage the user creation/deletion/dormant user removal.

f)        Follow up with OEM in case of hardware failure, firmware upgrade, raised ticket, and ensure OEM SLA is met

g)       Ensure back-up is taken on a monthly basis.

h)       Ensure tool is updated with latest updates as and when it is released by vendor.

Detailed Management level MIS and Dashboard creation to be captured on fortnight basis.

3

API’s Security Assessment

Annually and Adhoc as per requirement

1.       Conduct API’s Security Assessment for all in-scope internal and external API’s applications once in annual or when the change in modules/UI has been made (whichever applicable first).

2.       Provide report with findings, Impact, severity and recommendations.

3.       All Test cases and parameters should be covered as per the OWASP Top10 API checklist.

4.       Manual assessments with false positive elimination.

5.       Support team for closure.

6.       Dashboard having detail of Vulnerability along with Severity and Closure status along with Customizable dashboard.

7.       Technical assistance for Audit like internal and external audit.

8.       Assistance and preparation of advisory / Threat feeds

9.       Review of Internal reports and external reports.

10.    Follow-up with respective stakeholders for the closure of open vulnerabilities.

11.    To Maintain a consolidated tracker for the activities performed on daily basis.

12.    Severity should be determined based on the applicable CVSS (Common Vulnerability Scoring System) score.

13.    Tool management: -

a)       Maintenance and management Appsec tools and manage the user creation/deletion/dormant user removal.

b)       Follow up with OEM in case of hardware failure, firmware upgrade, raised ticket, and ensure OEM SLA is met

c)       Ensure back-up is taken on a monthly basis.

d)       Ensure tool is updated with latest updates as and when it is released by vendor.

Detailed Management level MIS and Dashboard creation to be captured on fortnight basis.

4

Software Composition Analysis (SCA)

Annually and Adhoc as per requirement

1.       Conduct Software Composition Analysis (SCA) for all in-scope internal and external applications, server library code once in annual or when the change in code has been made (whichever applicable first).

2.       Provide report with findings, Impact, severity and recommendations.

3.       All Test cases and parameters should be covered as per the standard OWASP SCA checklist.

4.       Manual assessments with false positive elimination (If required).

5.       Support team for closure.

6.       Dashboard having detail of Vulnerability along with Severity and Closure status along with Customizable dashboard.

7.       Technical assistance for Audit like internal and external audit.

8.       Assistance and preparation of advisory / Threat feeds

9.       Review of Internal reports and external reports.

10.    Follow-up with respective stakeholders for the closure of open vulnerabilities.

11.    To Maintain a consolidated tracker for the activities performed on daily basis.

12.    Tool management: -

a)       Maintenance and management SCA tool and manage the user creation/deletion/dormant user removal.

b)       Follow up with OEM in case of hardware failure, firmware upgrade, raised ticket, and ensure OEM SLA is met

c)       Ensure back-up is taken on a monthly basis.

d)       Ensure tool is updated with latest updates as and when it is released by vendor.

5

Secret Scan

Annually and Adhoc as per requirement

1.       Conduct Secret Scan assessment for all in-scope internal and external applications, server library code once in annual or when the change in code has been made (whichever applicable first).

2.       Provide report with findings, Impact, severity and recommendations.

3.       All Test cases and parameters should be covered as per the standard Secret Scan checklist.

4.       Manual assessments with false positive elimination (If required).

5.       Support team for closure.

Dashboard having detail of Vulnerability along with Severity and Closure status along with Customizable dashboard.

6.       Technical assistance for Audit like internal and external audit.

7.       Assistance and preparation of advisory / Threat feeds

8.       Review of Internal reports and external reports.

9.       Follow-up with respective stakeholders for the closure of open vulnerabilities.

10.    To Maintain a consolidated tracker for the activities performed on daily basis.

11.    Tool management: -

a)       Maintenance and management Secret Scan tool and manage the user creation/deletion/dormant user removal.

b)       Follow up with OEM in case of hardware failure, firmware upgrade, raised ticket, and ensure OEM SLA is met

c)       Ensure back-up is taken on a monthly basis.

d)       Ensure tool is updated with latest updates as and when vendor releases it.

6

Container Image Security Assessment

Annually and Adhoc as per requirement

1.       Perform vulnerability assessment of all container images hosted in private and public registries.

2.       Scan images for OS packages, application libraries, misconfigurations, malware, exposed secrets, hardcoded credentials, weak packages, and known CVEs.

3.       Validate compliance against CIS Docker Benchmark, NIST, and industry best practices.

4.       Manual validation and false positive elimination (if required).

5.       Re-scan after remediation and support application teams in vulnerability closure.

6.       Maintain image inventory, image risk rating, fix availability status, and remediation tracker.

7.       Manage container security platform and ensure latest vulnerability feeds and signatures are updated.

8.       Support audit activities and security advisory preparation.

9.       Follow up with stakeholders for closure of critical/high findings.

10.    Maintain centralized dashboard for image vulnerabilities, compliance status, remediation status, affected applications, and trends.

11.    Tool administration, user management, backup, and OEM coordination.

12.    Follow up with Cluster Owners, Infrastructure Teams, and application owners for closure of container image vulnerabilities findings.

13.    Escalate aging Critical and High-risk findings to concerned stakeholders.

14.    Track remediation progress against agreed SLA timelines

15.    Conduct periodic review meetings and provide closure status report.

16.    Maintain consolidated remediation, exception and execution tracker

17.    Identification of End-of-Life/Support (EOL/S) of container images and packages

18.    Maintain exception/risk acceptance register for deviations approved by CLIENT SITE

1.       Monthly vulnerability dashboard

2.       Executive MIS

3.       Image Risk Report

4.       Fix Availability Report

5.       Compliance Report

6.       Remediation Closure Tracker

7.       Audit Support Report

8.       Adhoc Requested Report

7

Kubernetes Cluster Vulnerability Assessment (VA) & Compliance Assessment (CA)

Annually and Adhoc as per requirement

1.       Perform security assessment of Kubernetes clusters including control plane, worker nodes, etc., ingress, storage, networking, and cluster configurations.

2.       Conduct vulnerability assessment of Kubernetes components, nodes, operating systems, and cluster services.

3.       Perform CIS Kubernetes Benchmark assessment and compliance validation against security baselines.

4.       Validate security controls such as TLS configuration, namespace isolation, pod security standards, network segmentation, logging, monitoring, secret management, and admission controls.

5.       Manual verification and false positive elimination (if required).

6.       Assist cluster owners in remediation activities and provide technical recommendations.

7.       Maintain consolidated tracker of findings, compliance deviations, and closure status.

8.       Review internal and external security advisories affecting Kubernetes environments.

9.       Tool management including platform updates, OEM coordination, backup, and user administration.

10.    Follow up with Cluster Owners, Infrastructure Teams, and application owners for closure of K8s cluster VA/CA findings.

11.    Escalate aging Critical and High-risk findings to concerned stakeholders.

12.    Track remediation progress against agreed SLA timelines

13.    Conduct a periodic review meeting and provide closure status report

14.    Maintain consolidated remediation and exception tracker

15.     Maintain exception/risk acceptance register for deviations approved by CLIENT SITE

1.       Cluster VA Report

2.       Compliance Assessment Report

3.       CIS Benchmark Report

4.       Executive Dashboard

5.       Remediation Tracker

6.       Risk Trending Report

7.       Audit Support Reports

8.       Adhoc Requested Report

8

Kubernetes IAM Security Posture Assessment

Annually and Adhoc as per requirement

1.       Perform Kubernetes Identity and Access Management (IAM) security posture assessment across all in-scope clusters.

2.       Review RBAC configurations, Cluster Roles, Roles, Role Bindings, Cluster Role Bindings, Service Accounts, Privileged Access, and Excessive Permissions.

3.       Identify privilege escalation paths, toxic permission combinations, workload-to-service account mappings, cross-namespace access risks, cluster-admin exposure, and orphaned permissions.

4.        Assess Kubernetes security posture against Zero Trust and Least Privilege principles.

5.        Validate access governance and authorization controls.

6.       Review admission control policies and security configurations affecting access controls.

7.       Provide recommendations for remediation and privilege reduction.

8.       Maintain centralized dashboard of IAM risks, critical attack paths, exposed identities, and remediation progress.

9.       Support internal/external audits and prepare advisory recommendations.

10.    Manage posture assessment platform, user administration, updates, backup, and OEM coordination.

11.    Follow up with Cluster Owners, Infrastructure Teams, and application owners for closure of RBAC/IAM and Security Posture findings.

12.    Escalate aging Critical and High-risk findings to concerned stakeholders.

13.    Track remediation progress against agreed SLA timelines

14.    Conduct a periodic review meeting and provide closure status report

15.    Maintain consolidated remediation and exception tracker

1.       IAM Risk Assessment Report

2.       Privilege Escalation Report

3.       RBAC Review Report

4.        Attack Path Analysis Report

5.       Executive Dashboard

6.       Compliance Status Dashboard

7.       Remediation Tracker

8.       Audit Support Reports

9.       Adhoc Requested Report

9

Security Tools Implementation and Support

Implementation of in house security tools procured by CLIENT SITE

a)       Maintenance and management of Source Code, Web Appsec, Mobile Appsec, API’s, SCA and Secret Scan.

b)       Follow up with OEM in case of hardware failure, firmware upgrade, raised ticket, and ensure OEM SLA is met

c)       Ensure back up is taken on a monthly basis.

d)       Ensure tool is updated with latest updates as and when vendor releases it.

e)       Dormant users are removed on a monthly basis.

f)        Decommissioned/Powered-off devices to be tracked on a monthly basis.

Detailed Management level MIS and Dashboard creation to be captured on fortnight basis.

10

Risk Assessment of Application

Identify the overall risk charter for all the applications.

Publish monthly report MIS and dashboard.

External/Prod Assessment

1

Web I Mobile Appsec

Source Code Review

Software Composition Analysis (SCA)

Secret Scan

API Assessment

Prod/Live App testing

1.       Conduct Appsec on Production Environment.

2.       Provide external closure report (in PDF) with findings, impact, recommendations and POC’s.

3.       Assist & Support  team for closing the vulnerability (if any)

4.       External Assessment (Onsite & Offsite) quarterly, monthly rescan should be performed.

5.       Assessment should be performed based on security standards such as OWASP Top 10, NIST.

Detailed Management level MIS and Dashboard creation to be captured on fortnight basis.

Client Office
Applying to this role?

Book a mock interview matched to your skills and get a written scorecard before the real thing.

Book interview prep