Senior Cyber Security Consultant

4 days ago


Sydney, New South Wales, Australia Deloitte Full time $120,000 - $180,000 per year

Date: 8 Sept 2025

Location:

Sydney, NSW, AU

Department: Enabling Areas

Description:

Job Requisition ID: 39356

Thrive in an innovative, collaborative people culture

Mentoring, coaching and leadership programs to help you make an impact that matters

We support flexibility and choice. We encourage you to find the right balance between connecting in person with your clients and teams and meeting your own personal needs

Are you a Cyber Security expert with an architectural mindset and 6+ years of experience embedding security practices early in the Software Development Lifecycle (SDLC)?

What will your typical day look like?

This role focuses on secure architectural design, cloud security, and DevSecOps enablement, with opportunities to work on AI security and other emerging technologies. You will play a key role in left-shifting security, ensuring robust architectures for applications, infrastructure, and multi-cloud environments (AWS, Azure, Kubernetes).

We require a strategic thinker who can embed security early in the SDLC, conduct architectural reviews, and integrate security into CI/CD pipelines, along with the ability to communicate complex security concepts to diverse stakeholders.

Key responsibilities include:

Architectural Security Review: Design and review secure architectures for enterprise and multi-cloud environments.

Cloud Security: Implement and enforce best practices for AWS and Azure, including IAM, encryption, logging, and incident response. Secure Kubernetes clusters and containerized workloads.

Authentication & Authorization: Design and review solutions using SAML, OIDC, OAuth2, and implement RBAC/ABAC models.

Encryption & Data Protection: Ensure use of strong encryption standards (TLS 1.2/1.3, AES-256) and key management best practices.

Logging & Auditing: Define and implement centralized logging, monitoring, and auditing strategies for compliance and incident response.

Threat Modeling & Risk Analysis: Apply frameworks like MITRE ATT&CK and STRIDE to identify and mitigate risks.

DevSecOps & Security Testing: Integrate security into CI/CD pipelines using Azure DevOps (ADO) and GitHub; and perform and automate security testing, including penetration testing, SAST, DAST, IAST, and IaC scanning

Secure SDLC & Code Review: Promote SSDLC practices and conduct secure code reviews.

AI Security: Define security measures for AI/ML development and deployment.

Compliance & Standards: Align with frameworks such as NIST, CIS, ISO 27001, PCI-DSS, ASD Essential 8, and ISM.

Incident Response: Develop and manage incident response strategies and investigations.

About the team

Our CISO team is a diverse and highly skilled group dedicated to securing Deloitte against evolving cyber threats. We operate across multiple security disciplines to govern, design, defend, operate, and enhance our cybersecurity capabilities, ensuring resilience and regulatory compliance. Within the CISO function, our specialized teams include Governance, Risk, and Compliance; Cyber Assurance; Cyber Defence; Cyber Operations; and Vendor Cyber Risk Management.

Enough about us, let's talk about you.

You may have all or some of the following skills / experiences / attributes:

5+ years in Security Architecture, designing and implementing secure network architectures in large-scale enterprise or multi-cloud environments.

Bachelor's degree in Cybersecurity, Information Technology, or related field.

Certifications (Preferred): CISSP, CCSP, CCSK, AWS/Azure Security Specialty, Kubernetes Security Specialist (CKS). Offensive Security certifications (OSCP, OSWE, GPEN) are highly desirable.

Strong understanding of networking protocols (TCP/IP, VPN, BGP, OSPF, MPLS, VLANs, VXLANs) and cloud networking (AWS VPC, Azure Virtual Network, ExpressRoute, Direct Connect).

Proficiency in authentication and authorization protocols (SAML, OIDC, OAuth2), encryption standards, and logging/auditing frameworks.

Experience with cloud security tools (AWS Security Hub, Azure Security Center) and DevSecOps tools (Azure DevOps, GitHub, Prisma Cloud, Qualys, Checkmarx).

Penetration Testing Expertise: Web, API, and cloud environments.

Threat Modeling: Experience with MITRE ATT&CK, STRIDE.

Regulatory Knowledge: GDPR, ISO 27001, PCI-DSS, ASD Essential 8, ISM.

Strong communication skills to articulate complex security concepts to non-technical stakeholders.

Why Deloitte?

At Deloitte, we focus our energy on interesting and impactful work. We're always learning, innovating and setting the standard; making a positive difference to our clients and our society. We put coaching at the heart of what we do, helping our people grow their careers in any direction – whether it be up, moving into something new, or even moving across the world.

We embrace diversity, equity and inclusion. We have a diverse collection of people from different backgrounds, with different experiences, gender identities, abilities and thinking styles. What binds us together is a shared commitment to value everyone's perspective and to cultivate inclusion; so that our work environment is a safe space we can all belong.

We support flexibility and choice. We encourage you to find the right balance between connecting in person with your clients and teams and meeting your own personal needs.

We help you live and work well. To support your personal and professional life, we offer a range of perks and benefits, including retail discounts, wellbeing leave, paid volunteering days, twelve flexible working options, market-leading parental leave and return to work support package.



  • Sydney, New South Wales, Australia Skylight Cyber Security Full time

    About Skylight CyberAt Skylight Cyber, we're young, transparent, and culture-focused boutique cyber security firm specialising in providing high-end services to enterprises globally. We provide our customers with world class expertise to build and continuously evolve an effective security stack across people, process, and technology.We thrive and are...


  • Sydney, New South Wales, Australia e2 Cyber Full time

    We are seeking aCyber Security GRC Consultantto join a growing advisory team delivering high impact security and compliance outcomes for clients across Australia. This is aclient facing consulting rolewhere you will work directly with stakeholders across financial services, healthcare, critical infrastructure, and government sectors to strengthen cyber...


  • Sydney, New South Wales, Australia Decipher Bureau Full time $130,000 - $150,000 per year

    The CompanyWe're partnering with a fast-growing Australian consultancy that's building a reputation as a leader in cyber strategy, governance, and risk. Following an internal promotion, we're now looking for aLead Cyber Strategy & GRC Consultantto join a high-performing team that thrives on solving complex problems and shaping the future of cyber for...


  • Sydney, New South Wales, Australia FTI Consulting Full time

    About The RoleFTI Consulting is the number one global expert firm for organisations facing crisis, transformation and moments of truth. The Cybersecurity Practice within FTI Consulting is a leading provider of independent cyber and risk management advisory services with a core offering focused on (but not limited to) Cyber Readiness, Incident Response and...


  • Sydney, New South Wales, Australia FTI Consulting, Inc. Full time $120,000 - $250,000 per year

    About The RoleFTI Consulting is the number one global expert firm for organisations facing crisis, transformation and moments of truth. The Cybersecurity Practice within FTI Consulting is a leading provider of independent cyber and risk management advisory services with a core offering focused on (but not limited to) Cyber Readiness, Incident Response and...


  • Sydney, New South Wales, Australia CyberCX Full time $120,000 - $180,000 per year

    Position Summary & Primary ObjectivesReporting to the Managing Security Consultant – STAorTeam Lead – STA, the Senior Security Consultant – STA is responsible for carrying out penetration testing and technical security assessments against complex environments and providing security expertise to CyberCX clients.The Senior Security Consultant – STA...


  • Sydney, New South Wales, Australia Calleo Full time

    Calleo is seeking aCyber Security Consultantfor one of our Federal clients.Contract position - 12 month with possibility of extensionLocation - NSW/ACT/QLD/SAMust hold NV1 Security ClearanceRequirements:We are looking for a Security Cyber Consultant withCyberArk PAMCDE certification.CyberArk Certified Delivery Engineer or CPC-CDE: CyberArk Privilege Cloud...


  • Sydney, New South Wales, Australia FUJIFILM Business Innovation Australia Full time $120,000 - $180,000 per year

    • Exciting opportunity to be part of our growth transformation  • Looking for candidates with experience in MSP/MSSP• Open to candidates from Sydney/ Melbourne or BrisbaneOUR STORYFUJIFILM have a proud history of providing innovative products and services that contribute to the advancement of culture, science, technology and industry, as well as...


  • Sydney, New South Wales, Australia Reserve Bank of Australia Full time $120,000 - $180,000 per year

    Senior Cyber Security Analyst (Cyber Hunt and Incident Response Team)Play an important part shaping the future of our iconic Australian institution.Hybrid work environment.Permanent position.Join a team focused on remaining at the forefront of technology.About the RoleThe Reserve Bank of Australia is hiring for a Senior Cyber Security Analyst to join a newly...


  • Sydney, New South Wales, Australia NSW Education Standards Authority Full time $120,000 - $180,000 per year

    Join us to make a difference for all students in NSWPosition detailsClerk Grade 9/10Ongoing, full time roleClose to Wynyard station & hybrid work arrangements availableAbout the roleWe are seeking a skilled Senior Cyber Security Officer to join NESA's growing Cyber Security team. This is an exciting opportunity to play a pivotal role in strengthening...