Information Security Architect
Deloitte- Posted 18 hours ago
- Be among the first 10 applicants
Job Description
Required Qualifications
• Bachelor's degree in Computer Science, Information Technology, Engineering,
Information Security, Cybersecurity, or a related field is required.
• CISSP, CCSP, or CSSLP certification is mandatory.
Required Experience
• Minimum 6–8 years of relevant experience in cybersecurity architecture, security
engineering, application security, or a related field, including hands-on experience
in application threat modeling.
Key Responsibilities
• Conduct application threat modeling and architecture assessments across key
information security domains to ensure security-by-design.
• Document identified threats and recommend appropriate mitigation strategies.
• Evaluate technologies and solutions to strengthen security capabilities.
• Identify security gaps and clearly communicate related business risks to relevant
stakeholders.
• Provide security solutions aligned with business objectives, risk appetite, and
compliance requirements.
• Validate the effectiveness of security controls in mitigating identified risks.
• Support application teams in analyzing, prioritizing, and mitigating application-level
vulnerabilities identified through security assessments, code reviews, penetration
testing, and vulnerability scans.
• Provide implementation guidance for DevSecOps practices, including secure CI/CD
pipelines, automated security testing, vulnerability management, and security
control integration within development workflows.
• Track and report DevSecOps security metrics, including vulnerability remediation
SLA adherence, security scan coverage, open critical and high vulnerabilities, falsepositive rates, and recurring vulnerability trends.
• Partner with application and engineering teams to reduce critical and high-risk
application vulnerabilities within agreed remediation timelines and drive closure of
security findings through documented action plans.
• Increase adoption of automated security controls in CI/CD pipelines by integrating
SAST, DAST, SCA, container scanning, secrets detection, and policy-based build
gates across applicable application portfolios.
• Review DevSecOps performance dashboards with stakeholders on a regular basis
and recommend corrective actions to improve security testing effectiveness,
remediation velocity, and secure release readiness.
• Support engineering projects throughout the Secure Software Development Life
Cycle (SSDLC) and collaborate with teams to prioritize product security
requirements effectively.
