Senior Cyber Security Consultant
6 days ago
Job Requisition ID: 39356
- Thrive in an innovative, collaborative people culture
- Mentoring, coaching and leadership programs to help you make an impact that matters
- We support flexibility and choice. We encourage you to find the right balance between connecting in person with your clients and teams and meeting your own personal needs
Are you a Cyber Security expert with an architectural mindset and 6+ years of experience embedding security practices early in the Software Development Lifecycle (SDLC)?
What will your typical day look like?
This role focuses on secure architectural design, cloud security, and DevSecOps enablement, with opportunities to work on AI security and other emerging technologies. You will play a key role in left-shifting security, ensuring robust architectures for applications, infrastructure, and multi-cloud environments (AWS, Azure, Kubernetes).
We require a strategic thinker who can embed security early in the SDLC, conduct architectural reviews, and integrate security into CI/CD pipelines, along with the ability to communicate complex security concepts to diverse stakeholders.
Key responsibilities include:
- Architectural Security Review: Design and review secure architectures for enterprise and multi-cloud environments.
- Cloud Security: Implement and enforce best practices for AWS and Azure, including IAM, encryption, logging, and incident response. Secure Kubernetes clusters and containerized workloads.
- Authentication & Authorization: Design and review solutions using SAML, OIDC, OAuth2, and implement RBAC/ABAC models.
- Encryption & Data Protection: Ensure use of strong encryption standards (TLS 1.2/1.3, AES-256) and key management best practices.
- Logging & Auditing: Define and implement centralized logging, monitoring, and auditing strategies for compliance and incident response.
- Threat Modeling & Risk Analysis: Apply frameworks like MITRE ATT&CK and STRIDE to identify and mitigate risks.
- DevSecOps & Security Testing: Integrate security into CI/CD pipelines using Azure DevOps (ADO) and GitHub; and perform and automate security testing, including penetration testing, SAST, DAST, IAST, and IaC scanning
- Secure SDLC & Code Review: Promote SSDLC practices and conduct secure code reviews.
- AI Security: Define security measures for AI/ML development and deployment.
- Compliance & Standards: Align with frameworks such as NIST, CIS, ISO 27001, PCI-DSS, ASD Essential 8, and ISM.
- Incident Response: Develop and manage incident response strategies and investigations.
About the team
Our CISO team is a diverse and highly skilled group dedicated to securing Deloitte against evolving cyber threats. We operate across multiple security disciplines to govern, design, defend, operate, and enhance our cybersecurity capabilities, ensuring resilience and regulatory compliance. Within the CISO function, our specialized teams include Governance, Risk, and Compliance; Cyber Assurance; Cyber Defence; Cyber Operations; and Vendor Cyber Risk Management.
Enough about us, let's talk about you.
You may have all or some of the following skills / experiences / attributes:
- 5+ years in Security Architecture, designing and implementing secure network architectures in large-scale enterprise or multi-cloud environments.
- Bachelor's degree in Cybersecurity, Information Technology, or related field.
- Certifications (Preferred): CISSP, CCSP, CCSK, AWS/Azure Security Specialty, Kubernetes Security Specialist (CKS). Offensive Security certifications (OSCP, OSWE, GPEN) are highly desirable.
- Strong understanding of networking protocols (TCP/IP, VPN, BGP, OSPF, MPLS, VLANs, VXLANs) and cloud networking (AWS VPC, Azure Virtual Network, ExpressRoute, Direct Connect).
- Proficiency in authentication and authorization protocols (SAML, OIDC, OAuth2), encryption standards, and logging/auditing frameworks.
- Experience with cloud security tools (AWS Security Hub, Azure Security Center) and DevSecOps tools (Azure DevOps, GitHub, Prisma Cloud, Qualys, Checkmarx).
- Penetration Testing Expertise: Web, API, and cloud environments.
- Threat Modeling: Experience with MITRE ATT&CK, STRIDE.
- Regulatory Knowledge: GDPR, ISO 27001, PCI-DSS, ASD Essential 8, ISM.
- Strong communication skills to articulate complex security concepts to non-technical stakeholders.
Why Deloitte?
At Deloitte, we focus our energy on interesting and impactful work. We're always learning, innovating and setting the standard; making a positive difference to our clients and our society. We put coaching at the heart of what we do, helping our people grow their careers in any direction – whether it be up, moving into something new, or even moving across the world.
We embrace diversity, equity and inclusion. We have a diverse collection of people from different backgrounds, with different experiences, gender identities, abilities and thinking styles. What binds us together is a shared commitment to value everyone's perspective and to cultivate inclusion; so that our work environment is a safe space we can all belong.
We support flexibility and choice. We encourage you to find the right balance between connecting in person with your clients and teams and meeting your own personal needs.
We help you live and work well. To support your personal and professional life, we offer a range of perks and benefits, including retail discounts, wellbeing leave, paid volunteering days, twelve flexible working options, market-leading parental leave and return to work support package.
Next Steps
Sound like the sort of role for you? Apply now, we'd love to hear from you
#LI-Hybrid
By applying for this job, you'll be assessed against the Deloitte Talent Standards. We've designed these standards so that you can grow in your career, and we can provide our clients with a consistent and exceptional Deloitte employee experience globally. The preferred candidate will be subject to background screening by Deloitte or by their external third-party provider.
By applying for this job, you'll be assessed against the Deloitte Talent Standards. We've designed these standards so that you can grow in your career, and we can provide our clients with a consistent and exceptional Deloitte employee experience globally. The preferred candidate will be subject to background screening by Deloitte or by their external third-party provider.
-
Lead Cyber Security Consultant
6 days ago
Sydney, New South Wales, Australia Skylight Cyber Security Full timeAbout Skylight CyberAt Skylight Cyber, we're young, transparent, and culture-focused boutique cyber security firm specialising in providing high-end services to enterprises globally. We provide our customers with world class expertise to build and continuously evolve an effective security stack across people, process, and technology.We thrive and are...
-
Cyber Security Consultant
2 weeks ago
Sydney, New South Wales, Australia Phronesis Security Full time $80,000 - $120,000 per yearPhronesis Security is Australia's first B Corp certified cyber security company, committed to delivering world-class cyber security consulting with a tangible social and environmental impact. To do so, we have built sharing our profits with some of Australia's highest impact charities into our core operating model.We provide tailored, pragmatic advice,...
-
Senior GRC Consultant
6 days ago
Sydney, New South Wales, Australia e2 Cyber Full timeWe are seeking aCyber Security GRC Consultantto join a growing advisory team delivering high impact security and compliance outcomes for clients across Australia. This is aclient facing consulting rolewhere you will work directly with stakeholders across financial services, healthcare, critical infrastructure, and government sectors to strengthen cyber...
-
Lead Cyber Security Consultant
2 hours ago
Sydney, New South Wales, Australia Decipher Bureau Full time $120,000 - $180,000 per yearThe CompanyWe're partnering with a fast-growing Australian consultancy recognised for helping organisations rethink their approach to cyber risk. Their advisory and technical team is known for combining technical expertise with pragmatic, risk-led strategies that make a lasting impact.They don't believe in cookie-cutter, box-ticking engagements. Instead,...
-
Cyber Security Consultant
2 weeks ago
Sydney, New South Wales, Australia ViCyber Full time $90,000 - $120,000 per yearCompany DescriptionViCyber specializes in cyber loss prediction, risk quantification, and cyber security solutions tailored specifically for small and medium-sized enterprises (SMEs). The company is dedicated to improving the cyber health and awareness of businesses through proactive prevention and comprehensive cyber fix strategies. ViCyber also aids...
-
Senior Director, Cyber Security
6 days ago
Sydney, New South Wales, Australia FTI Consulting Full timeAbout The RoleFTI Consulting is the number one global expert firm for organisations facing crisis, transformation and moments of truth. The Cybersecurity Practice within FTI Consulting is a leading provider of independent cyber and risk management advisory services with a core offering focused on (but not limited to) Cyber Readiness, Incident Response and...
-
Senior Cyber Security Engineer
2 weeks ago
Sydney, New South Wales, Australia NSW Department of Customer Service Full time $129,464 - $142,665 per yearSenior Cyber Security Engineer Salary range: $129,464- $142,665 + super Duration: Ongoing Location: Hybrid working arrangements in place - in office requirement to attend Sydney McKell offices on Tuesdays and Thursdays, which is subject to change based on applicable DCS workplace policies. **About the team This role sits within the NSW Telco Authority...
-
Senior Cyber Security Engineer
1 week ago
Sydney, New South Wales, Australia NSW Government Full time $129,464 - $142,665 per yearSenior Cyber Security Engineer Grade: 9/10Salary range: $129,464- $142,665 + superDuration: OngoingLocation: Hybrid working arrangements in place – in office requirement to attend Sydney McKell offices on Tuesdays and Thursdays, which is subject to change based on applicable DCS workplace policies. About the team This role sits within the NSW Telco...
-
Cyber Security Consultant
6 days ago
Sydney, New South Wales, Australia Calleo Full timeCalleo is seeking aCyber Security Consultantfor one of our Federal clients.Contract position - 12 month with possibility of extensionLocation - NSW/ACT/QLD/SAMust hold NV1 Security ClearanceRequirements:We are looking for a Security Cyber Consultant withCyberArk PAMCDE certification.CyberArk Certified Delivery Engineer or CPC-CDE: CyberArk Privilege Cloud...
-
Cyber Security Consultant
4 days ago
Sydney, New South Wales, Australia QBE Insurance Full time $120,000 - $150,000 per yearPrimary DetailsTime Type: Full timeWorker Type: EmployeeLocation: SydneyType: Permanent, full timeHybrid role, Happy to talk flexible workingClick here to discover what it's like to be a part of QBE GroupThe opportunityWe're looking for an experienced and forward-thinking Cyber Security Consultant to join our expanding team. In this role, you'll collaborate...