Deloitte

Zero Trust Engineer

Deloitte • $110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's in Information Security, IT, Computer Science, or related field
  • 4+ years in cybersecurity; 2 years in network security and 2 years in application security
  • Strong knowledge of web application security concepts and OWASP Top 10 vulnerabilities
  • Understanding of authentication flows (OAuth, SAML, OIDC)
  • Technical experience with Web Application Firewalls and Zero Trust Network Access
  • Good grasp of API security issues and information security principles
  • Excellent communication skills for both technical and non-technical audiences

Responsibilities

  • Deploy, configure, and maintain web application firewall systems
  • Implement and manage Zero Trust Proxy systems, including policy and connector maintenance
  • Monitor and analyze security events and logs; respond to potential incidents
  • Develop detection rules and alerts to identify and mitigate risks
  • Collaborate on integrating web application firewalls with CDNs like Akamai
  • Utilize WAF data for vulnerability assessment and remediation recommendations
  • Maintain documentation and prepare reports on web application security

Benefits

  • Opportunity to work in a leading global technology environment
  • Exposure to cutting-edge security technologies and practices
  • Collaboration with cross-functional teams
  • Professional development opportunities within a large enterprise
  • Potential for limited immigration sponsorship available
Full Job Description
Work you'll do

The Application Security Engineer candidate will have a strong background in cybersecurity and understanding of web application and zero trust proxy security practices. The primary responsibility of the Engineer will be to ensure the effective deployment, configuration, and maintenance of our systems for Global customers. This role requires expertise in Web Application Firewalls, Zero Trust Proxy, Cloud security as well as experience with alerts and detections and data log analysis. This role will be part of the Application Edge Protection Service within the CyberSecurity pillar.

Role Specific Responsibilities:
  • Web Application Firewall Management: Deploy, configure, and maintain web application firewall systems to protect our web applications against potential threats and vulnerabilities.
  • Zero Trust Proxy: Deploy, configure, and Zero Trust Proxy systems to support identity gates to include defining and maintaining policies and connectors.
  • Security Incident Response: Monitor and analyze security events, alerts, and logs generated by the web application firewall systems. Investigate and respond to potential security incidents, working closely with the Security Operations Center (SOC) and other Cybersecurity teams.
  • Detection and Analysis: Develop and maintain detection rules, alerts, and reports to proactively identify and mitigate risks utilizing logs. Provides investigation findings to relevant business units to help improve information security posture.
  • CDN Integration: Collaborate with the infrastructure and application teams to integrate the web application firewall with CDNs such Akamai and Radware, ensuring seamless traffic management and content delivery.
  • Vulnerability Assessment: Utilize WAF data to identify potential vulnerabilities and recommend appropriate remediation measures to customers.
  • Documentation and Reporting: Maintain accurate documentation of WAF configurations, policies, and procedures. Prepare reports and metrics related to web application security, including trends, incident summaries, and mitigation strategies, as needed.
  • Collaboration: This role requires ability to explain security details to non- security teams such as application and engineering teams. Must be able to collaborate with cross-functional teams to ensure effective communication, knowledge sharing, and alignment of security objectives. Provide guidance to application teams on application security best practices and security awareness, as needed.
The team

Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in what is but rather what can be to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.

Qualifications

Required:
  • Bachelor's Degree/University Degree and/or Undergraduate Diploma in Information Security, Information Technology, Computer Science, Engineering or equivalent years in experience
  • 4+ years with minimum 2 years in network security and 2 years in application security
  • Strong knowledge of web application security concepts, OWASP Top 10 vulnerabilities, and related mitigation techniques
  • Understanding of authentication and authorization flows (OAuth, SAMAL, OIDC)
  • Strong technical background with Web Application Firewall (WAF), Zero Trust Network Access, APIs, and Cloud security policies
  • Understanding of API security issues and API authentication
  • Good understanding of information security principles and policy enforcement.
  • Solid comprehension of HTTP protocol and demonstrated ability to troubleshoot using HTTP logs
  • Strong technical background in web development and familiarity with potential attack vectors/methods
  • Understanding of Authentication, DNS, Networks, Firewalls, SSL Certificates
  • Excellent written and oral communication and presentation skills for technical and business audiences
  • Strong analytical skills with high attention to detail and accuracy
  • Experience with and the ability to thrive in a complex and fast-paced technology and/or information security organization, within a large enterprise environment
Experience in the following areas are strongly preferred:
  • Previous experience in a Security Operations Center (SOC) or performing cybersecurity analysis, log analysis, and threat detection is highly desirable.
  • Knowledge of Web Application Firewall technologies (Akamai)
  • Knowledge of Zero Trust framework and technologies
  • Experience integrating zero trust with WAF
  • Familiarity with cloud security services, concepts, and best practices (AWS, Azure, GCP)
  • Infrastructure as code (Terraform)
  • Ethical hacking
  • ServiceNow experience
  • Technical documentation experience
  • CISSP, CISM, CISA, GIAC or other security certifications are desired
  • Bi-lingual a plus (Spanish/Japanese)
  • Automation/Scripting experience
  • Experience with CI/CD pipelines
Limited immigration sponsorship may be available.

Requisition code: 368421

Job ID 368421

About Deloitte

Deloitte is a multinational professional services network that provides audit, tax, consulting, enterprise risk and financial advisory services. The company was founded in London in 1845 and has since grown to become one of the largest professional services firms in the world. Deloitte has over 330,000 employees in more than 150 countries and territories. The company's mission is to help clients achieve their goals and make an impact that matters in their businesses and communities.
Learn more about Deloitte
Size
330,000 employees
Industry
Founded
1999

Similar Jobs

More Jobs at Deloitte

More Information Technology Jobs

Find similar Zero Trust Engineer jobs: