IT Security Analyst

Company logo
Thornton Tomasetti
Global science‑driven engineering firm offering structural, forensic, façade, civil and applied‑science consulting.
Cyber security analyst advising dev teams and leading security improvements
19 days ago ago
Junior (1-3 years), Intermediate (4-7 years)
Full Time
Mumbai, Maharashtra, India
Office Full-Time
Company Size
1,500 Employees
Service Specialisms
structural engineering
facade engineering
forensic engineering
sustainable design
construction engineering
resilience engineering
applied science
protective design and security
Sector Specialisms
Industrial
Energy
Infrastructure
Buildings
Residential
Commercial
Water Resources
Heavy Civil
Role
What you would be doing
software evaluation
business systems
incident response
vulnerability testing
design integration
security practices
  • Understand the available commercial software/service options and configuration possibilities and identify opportunities that will benefit the firm.
  • “business” systems that help the company communicate, manage its operations, and measure performance. An example of this is a master database of our projects, current and historical, that allows staff to find relevant work that might help them and allows management to analyze trends and better sell the next generation of work.
  • Develop plans for changes, upgrades, maintenance, training, and communication.
  • Hands on participation in incident response and remediation efforts.
  • Monitor changes in external requirements including security certification programs, regulation, and industry best practices.
  • Create and maintain review checklists.
  • “design/engineering” systems that allow us to conduct our technical work of designing, evaluating, and improving buildings and other structures more efficiently around the world. This includes, for example, harvesting data from Autodesk design modeling tools to use in other analytical tools.
  • Help during planning and execution phases.
  • Coordinate vulnerability testing.
  • Evaluate the “current state” to identify strengths, weaknesses and opportunities associated with our systems and fit with our culture and business needs.
  • Assist teams in implementing security best practices.
  • Develop and maintain best practices.
  • Participate in proactive problem avoidance as well as incident investigation/lessons learned activities.
  • Develop training materials and other ways to evangelize good cyber security practices in the company.
  • Hands on management of improvement programs, re-configurations, and effectiveness of our evolving tools, including issue tracking, user support and vendor relations.
What you bring
node.js
javascript
aws
azure
cissp
5+ years
  • React, Vue, Angular front-end frameworks
  • Privacy awareness (e.g., PII/GDPR/CCPA).
  • Awareness of evolving US Government cybersecurity requirements and international standards in major markets where TT operates (especially North America, UK, India).
  • Familiarity with Web & Desktop Application Development, Cloud services, Linux & Windows System administration.
  • 5+ years in software development with significant experience in planning and design for custom software development.
  • Deep awareness of cyber issues and options for software development, with a CISSP or another credential preferred.
  • Strong knowledge of full stack javascript development and cloud services architecture (AWS and Azure services) is essential.
  • Broad understanding of big picture, software architecture, networking.
  • Node.js (most important)
  • Standardization around authentication mechanisms.
  • AWS & Microsoft Azure cloud platforms
Benefits
Information not given or found
Training + Development
Information not given or found
Interview process
Information not given or found
Visa Sponsorship
Information not given or found
Security clearance
Information not given or found
Company
Overview
Founded in 1949
Year Established
The company was established in 1949 and has since expanded into a global engineering leader.
Merged in 2015
Year of Merger
The merger of Weidlinger Associates and Thornton‑Tomasetti Group occurred in 2015, combining their expertise to form a cohesive engineering firm.
  • Delivers expertise in structural, façade, forensic, civil, bridge, and applied‑science engineering.
  • Known for high‑profile projects like Taipei 101, Petronas Towers, and disaster recovery efforts post‑9/11 and Hurricane Sandy.
  • Operates an internal R&D unit, CORE studio, driving innovation via computational modeling, AI, and software tools.
  • Services span from supertall buildings and long‑span structures to transportation infrastructure and protective design.
  • Combines deep engineering know‑how with cutting‑edge technology to tackle complex design challenges worldwide.
Culture + Values
  • Client-centered approach
  • Creative, collaborative, and innovative solutions
  • Commitment to excellence
  • Sustainability-driven design
  • Global leadership in engineering and architecture
  • Collaborative team culture
Environment + Sustainability
2050
Net Zero Target Year
Aiming to achieve net zero carbon emissions by the year 2050.
  • Developing sustainable designs for climate-resilient infrastructure
  • Use of advanced modeling and simulations to optimize building performance
  • Focus on reducing carbon emissions in projects
  • Track record of leading projects with high sustainability standards, such as LEED-certified buildings
Inclusion & Diversity
  • Promotion of diverse talent and inclusion in the workplace
  • Continual focus on creating an inclusive work environment
  • Gender diversity initiatives
  • Programs and support for career advancement of underrepresented groups
Big Kablio Logo
Kablio AIIf you're someone who helps build and power the world (or dreams to), Kablio AI is your pocket-sized recruiter that gets you hired.
Copyright © 2025 Kablio
IT Security Analyst at Thornton Tomasetti in Mumbai, Maharashtra, India