CBS Security Consultant

On-siteSalary not specified

Tech Stack

Agile

Job Description, Responsibilities & Requirements

CBS Security Consultant

Location

  • Bengaluru, India

Salary

  • Competitive

Job Summary

At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

As an Information Security Consultant, the individual will be responsible for providing security guidance to projects and operations teams responsible for delivering, respectively maintaining, IT cloud-based solutions. The Consultant will support the entire system development lifecycle (SDLC) of business IT solutions with information security expertise and guidance. This includes performing a risk assessment of the solution and the underpinning cloud infrastructure in order to derive adequate risk treatment options, driving the security assurance activities with cloud vendors, specifying and prioritizing security requirements, directing the design of security controls, supervising the security attestation activities and effectively articulating all related findings, issues, recommendations to team members and management, assessing the security impact of change requests and providing the operations teams with related recommendations and decisions.

Key Responsibilities

  • Directing and managing solution-specific information security assurance efforts with 3rd parties and vendors, like backend reviews, controls verification and validation, etc., oriented on standards and frameworks like ISO, COBIT, NIST, TSC, etc.
  • Risk assessments (threats, vulnerabilities) of cloud services and applications
  • Risk assessments of cloud hosting infrastructure underpinning the services and applications
  • Security assessment of architecture and networking supporting the services and applications
  • Derivation of risk treatment options from risk assessments and effectively facilitating the implementation of the optimal security-usability trade-off in interactions with project teams and management
  • Identifying, specifying and prioritizing security requirements in new applications and services deployment, as well as specifying and facilitating security changes in DevOps operations mode of existent applications
  • Directing the design of security controls to satisfy the approved security requirements
  • Supervising and managing various types of security attestation activities (scans, pentests, audits), including the definition of scope, pass criteria, contribution to test scenarios, articulating and formalizing findings and decisions
  • Assessing the security posture impact of change requests and providing the operations teams with related recommendations and decisions
  • Effectively communicating the findings, recommendations and decisions from all above activities, by adapting the form and depth of statements adequately to audiences and stakeholders
  • Translating technical security terms and concepts into business risk terminology to facilitate making objective and security-aware risk decisions by management
  • Providing knowledge sharing and technical assistance to other team members
  • Acting as an agile team member according to established agile development best practices and guidelines

Skills and Attributes for Success

  • Knowledge of various IT system architectures and technologies like cloud, virtualization, containerization, mobile, as well as expertise and experience in security subject matter areas such as IAM, network and perimeter security, web applications security, user account management, privileged access, auditing & logging, and others as outlined in ISO 27001, OWASP, NIST and related guidelines and standards.
  • Experience in conduction of 3rd party security assessments, in particular within the scope of SOC1, SOC2 reports, and in vendor risk management.
  • Significant security working experience and knowledge in the design, implementation and operation of security controls in any two or more of the following areas:
    • Agile & DevOps Methodologies
    • Application Security
    • Cloud Security
    • Infrastructure Security
    • Identity and Access Management

Qualifications

  • A BSc or MSc degree in Computer Science, Information Technology or a related discipline, or equivalent work experience, with preference towards advanced degrees.
  • Seven or more years of experience in Information Technology disciplines.
  • Five or more years of experience in Information Security subject matter area with demonstrated experience in:
    • Providing and validating security requirements related to applications and information system design and implementation
    • Providing and validating security requirements related to cloud services and underlying networking and architectures
    • Conducting risk assessments, vulnerability assessments, vendor and third party risk assessments and recommending risk remediation strategies
    • Using tools and methods to identify security exposures and business risks
    • Knowledge of common information security standards, such as: ISO, NIST, COBIT
    • Familiarity with information system attack methods and vulnerabilities and threat modelling
    • Working experience with web technologies and programming languages
    • Working experience with more than one of these technologies and products - Java,.NET, NodeJS, Angular, Power Apps, Kubernetes

Ideal Candidate

  • A vendor-neutral security certification of DoD IAT Level II-III or DoD IAM Level II-III is strongly preferred (SSCP, Security+, CEH, CISSP, CISM)
  • A vendor-specific cloud security certification would be an additional asset (Microsoft AZ-500, AWS Security Specialty, …)
  • Proven experience as a standing member of an agile development team (in any agile role) or as DevOps operations mode contributor would be an additional asset
  • Proven experience with either of the Adobe cloud products would be an additional asset

What We Look For

  • Ability to team well with others to facilitate and enhance the understanding & compliance to security policies
  • Ability to work effectively with customers, management, staff members, vendors, and consultants and articulate findings and recommendations
  • Strong English communication and writing skills are required
  • Strong judgment and analytical ability
  • Excellent interpersonal, communication, organizational, and project management skills
  • Flexibility to adjust to multiple demands, shifting priorities, ambiguity, and rapid change

What Working at EY Offers

We offer a competitive remuneration package where you’ll be rewarded for your individual and team performance. Our comprehensive Total Rewards package includes support for flexible working and career development, and with FlexEY you can select benefits that suit your needs, covering holidays, health and well-being, insurance, savings and a wide range of discounts, offers and promotions. Plus, we offer:

  • Support, coaching and feedback from some of the most engaging colleagues around
  • Opportunities to develop new skills and progress your career
  • The freedom and flexibility to handle your role in a way that’s right for you

EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

Job Details

Company name:
EY Ukraine
Location:
India
Work Mode:
On-site
Posted on TheJob:
Aug 14, 2026
Last checked:
Aug 14, 2026
Apply Now