Assistant Manager | Risk Management | Pune | Cyber Strategy & Transformation
Deloitte
Deloitte
Join our team to fortify our defenses through robust Third-Party Risk Management (TPRM). This role is integral to assessing and enhancing the cybersecurity posture of our third-party suppliers, proactively identifying risks, and ensuring compliance with stringent organizational policies and regulatory mandates.
We are seeking skilled cybersecurity professionals dedicated to evaluating supplier security, pinpointing vulnerabilities, and driving effective remediation strategies. Your expertise will be crucial in maintaining a secure ecosystem for our operations and protecting sensitive information.
Conduct comprehensive cybersecurity risk assessments for third-party suppliers across diverse domains like information security, infrastructure, application security, data protection, IAM, and cloud security.
Critically review and evaluate supplier responses to security questionnaires and frameworks, ensuring alignment with established control requirements.
Analyze crucial evidence, including SOC reports, ISO 27001 certificates, penetration testing results, and business continuity plans, to identify control gaps and assess inherent and residual risks.
Validate remediation plans and meticulously track findings to their successful closure, mitigating potential exposure.
Support informed decision-making by identifying compensating controls and managing risk acceptance processes.
Contribute to the ongoing enhancement of TPRM methodologies, processes, and assessment templates, ensuring best practices are maintained and implemented.
A minimum of 5 to 10 years of experience in Cybersecurity, Information Security, IT Risk, Technology Risk, or Third-Party Risk Management is essential.
Demonstrated hands-on experience in conducting Third-Party Risk Management (TPRM) and cybersecurity assessments is required.
Possess a strong understanding of core cybersecurity domains, including Information Security Governance, IAM, Vulnerability Management, Network Security, Application Security, Data Protection, Cloud Security, Incident Response, and Business Continuity/Disaster Recovery.
Familiarity with assessing third parties against industry-standard frameworks such as ISO 27001, NIST CSF, CIS Controls, SOC 2, or PCI DSS is necessary.
Proficiency in interpreting SOC reports, audit findings, penetration testing results, and security certifications is expected.
Solid analytical, documentation, and stakeholder management skills are vital for success in this role. The ability to independently manage multiple assessments and adhere to defined SLAs is also a key requirement.
Deloitte
IT Consulting