Deloitte

Zero Trust Engineer

Deloitte  •  Tampa, FL / Indianapolis, IN / Kansas City, MO / Cincinnati, OH / Hermitage, TN / Nashville, TN / San Antonio, TX (Onsite)  •  4 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Zero Trust Engineer

Cyber and Technology Risk

Same job available in 8 locations

Cincinnati, Ohio, United States

Hermitage, Tennessee, United States

Indianapolis, Indiana, United States

Kansas City, Missouri, United States

Nashville, Tennessee, United States

San Antonio, Texas, United States

St. Louis, Missouri, United States

Tampa, Florida, United States

Position Summary

Deloitte Global is the engine of the Deloitte network. Our professionals reach across disciplines and borders to develop and lead global initiatives. We deliver strategic programs and services that unite our organization.

Work you'll doThe Application Security Engineer candidate will have a strong background in cybersecurity and understanding of web application and zero trust proxy security practices. The primary responsibility of the Engineer will be to ensure the effective deployment, configuration, and maintenance of our systems for Global customers. This role requires expertise in Web Application Firewalls, Zero Trust Proxy, Cloud security as well as experience with alerts and detections and data log analysis. This role will be part of the Application Edge Protection Service within the CyberSecurity pillar. Role Specific Responsibilities: Web Application Firewall Management: Deploy, configure, and maintain web application firewall systems to protect our web applications against potential threats and vulnerabilities. Zero Trust Proxy: Deploy, configure, and Zero Trust Proxy systems to support identity gates to include defining and maintaining policies and connectors. Security Incident Response: Monitor and analyze security events, alerts, and logs generated by the web application firewall systems. Investigate and respond to potential security incidents, working closely with the Security Operations Center (SOC) and other Cybersecurity teams. Detection and Analysis: Develop and maintain detection rules, alerts, and reports to proactively identify and mitigate risks utilizing logs. Provides investigation findings to relevant business units to help improve information security posture. CDN Integration: Collaborate with the infrastructure and application teams to integrate the web application firewall with CDNs such Akamai and Radware, ensuring seamless traffic management and content delivery. Vulnerability Assessment: Utilize WAF data to identify potential vulnerabilities and recommend appropriate remediation measures to customers. Documentation and Reporting: Maintain accurate documentation of WAF configurations, policies, and procedures. Prepare reports and metrics related to web application security, including trends, incident summaries, and mitigation strategies, as needed. Collaboration: This role requires ability to explain security details to non- security teams such as application and engineering teams. Must be able to collaborate with cross-functional teams to ensure effective communication, knowledge sharing, and alignment of security objectives. Provide guidance to application teams on application security best practices and security awareness, as needed.

The teamDeloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in what is but rather what can be to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.

QualificationsRequired: Bachelor's Degree/University Degree and/or Undergraduate Diploma in Information Security, Information Technology, Computer Science, Engineering or equivalent years in experience 4+ years with minimum 2 years in network security and 2 years in application security Strong knowledge of web application security concepts, OWASP Top 10 vulnerabilities, and related mitigation techniques Understanding of authentication and authorization flows (OAuth, SAMAL, OIDC) Strong technical background with Web Application Firewall (WAF), Zero Trust Network Access, APIs, and Cloud security policies Understanding of API security issues and API authentication Good understanding of information security principles and policy enforcement. Solid comprehension of HTTP protocol and demonstrated ability to troubleshoot using HTTP logs Strong technical background in web development and familiarity with potential attack vectors/methods Understanding of Authentication, DNS, Networks, Firewalls, SSL Certificates Excellent written and oral communication and presentation skills for technical and business audiences Strong analytical skills with high attention to detail and accuracy Experience with and the ability to thrive in a complex and fast-paced technology and/or information security organization, within a large enterprise environment Experience in the following areas are strongly preferred: Previous experience in a Security Operations Center (SOC) or performing cybersecurity analysis, log analysis, and threat detection is highly desirable. Knowledge of Web Application Firewall technologies (Akamai) Knowledge of Zero Trust framework and technologies Experience integrating zero trust with WAF Familiarity with cloud security services, concepts, and best practices (AWS, Azure, GCP) Infrastructure as code (Terraform) Ethical hacking ServiceNow experience Technical documentation experience CISSP, CISM, CISA, GIAC or other security certifications are desired Bi-lingual a plus (Spanish/Japanese) Automation/Scripting experience Experience with CI/CD pipelines

Limited immigration sponsorship may be available.

Deloitte is committed to providing reasonable accommodations for people with disabilities. If you require a reasonable accommodation to participate in the recruiting process, please direct your inquiries to the Global Call Center (GCC) at USTalentCICInbox@deloitte.com.

Recruiting tips

From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.

Our people and culture

Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ways of thinking, ideas, and perspectives, and bring more creativity and innovation to help solve our clients' most complex challenges. This makes Deloitte one of the most rewarding places to work.

Our purpose

Deloitte’s purpose is to make an impact that matters for our people, clients, and communities. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. Our purpose comes through in our work with clients that enables impact and value in their organizations, as well as through our own investments, commitments, and actions across areas that help drive positive outcomes for our communities. Learn more.

Professional development

From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.

Requisition code: 368421

Job ID 368421

Deloitte

About Deloitte

Deloitte drives progress. Our firms around the world help clients become leaders wherever they choose to compete. Deloitte invests in outstanding people of diverse talents and backgrounds and empowers them to achieve more than they could elsewhere. Our work combines advice with action and integrity. We believe that when our clients and society are stronger, so are we.

Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited (“DTTL”), its global network of member firms, and their related entities. DTTL (also referred to as “Deloitte Global”) and each of its member firms are legally separate and independent entities. DTTL does not provide services to clients. Please see www.deloitte.com/about to learn more.

The content on this page contains general information only, and none of Deloitte Touche Tohmatsu Limited, its member firms, or their related entities (collectively the “Deloitte Network”) is, by means of this publication, rendering professional advice or services. Before making any decision or taking any action that may affect your finances or your business, you should consult a qualified professional adviser. No entity in the Deloitte Network shall be responsible for any loss whatsoever sustained by any person who relies on content from this page.

Industry
Consulting & Advisory
Company Size
10,000+ employees
Headquarters
Worldwide, OO
Year Founded
1845
Social Media