Assistant Manager | Risk Management | Pune | Cyber Strategy & Transformation

Deloitte

5–10 yrs Pune Full Time Work from office
Deloitte logo
Posted : yesterday
Actively hiring

Job description

Join our team to fortify our defenses through robust Third-Party Risk Management (TPRM). This role is integral to assessing and enhancing the cybersecurity posture of our third-party suppliers, proactively identifying risks, and ensuring compliance with stringent organizational policies and regulatory mandates.

We are seeking skilled cybersecurity professionals dedicated to evaluating supplier security, pinpointing vulnerabilities, and driving effective remediation strategies. Your expertise will be crucial in maintaining a secure ecosystem for our operations and protecting sensitive information.

Responsibilities

Conduct comprehensive cybersecurity risk assessments for third-party suppliers across diverse domains like information security, infrastructure, application security, data protection, IAM, and cloud security.

Critically review and evaluate supplier responses to security questionnaires and frameworks, ensuring alignment with established control requirements.

Analyze crucial evidence, including SOC reports, ISO 27001 certificates, penetration testing results, and business continuity plans, to identify control gaps and assess inherent and residual risks.

Validate remediation plans and meticulously track findings to their successful closure, mitigating potential exposure.

Support informed decision-making by identifying compensating controls and managing risk acceptance processes.

Contribute to the ongoing enhancement of TPRM methodologies, processes, and assessment templates, ensuring best practices are maintained and implemented.

Qualifications

A minimum of 5 to 10 years of experience in Cybersecurity, Information Security, IT Risk, Technology Risk, or Third-Party Risk Management is essential.

Demonstrated hands-on experience in conducting Third-Party Risk Management (TPRM) and cybersecurity assessments is required.

Possess a strong understanding of core cybersecurity domains, including Information Security Governance, IAM, Vulnerability Management, Network Security, Application Security, Data Protection, Cloud Security, Incident Response, and Business Continuity/Disaster Recovery.

Familiarity with assessing third parties against industry-standard frameworks such as ISO 27001, NIST CSF, CIS Controls, SOC 2, or PCI DSS is necessary.

Proficiency in interpreting SOC reports, audit findings, penetration testing results, and security certifications is expected.

Solid analytical, documentation, and stakeholder management skills are vital for success in this role. The ability to independently manage multiple assessments and adhere to defined SLAs is also a key requirement.

Essential Skills

CybersecurityInformation SecurityIT RiskTechnology RiskThird-Party Risk ManagementTPRMCybersecurity AssessmentInformation Security GovernanceIAMPrivileged Access ManagementVulnerability ManagementPatch ManagementNetwork SecurityInfrastructure SecurityApplication SecuritySDLC SecurityData ProtectionPrivacyCloud SecuritySecurity MonitoringIncident ResponseBusiness ContinuityDisaster RecoveryCryptographyKey ManagementISO 27001NIST CSFCIS ControlsSOC 2PCI DSSRisk Assessment MethodologiesControl TestingRisk RatingStakeholder ManagementAnalytical SkillsDocumentation

Good to Have

CISACISMCRISCCISSPISO 27001 Lead AuditorISO 27001 ImplementerGRC PlatformsFinancial ServicesBankingInsuranceOperational Resilience

Highlights

  • Actively hiring

More Details

RoleAssistant Manager | Risk Management | Pune | Cyber Strategy & Transformation
DepartmentRisk Management, Cybersecurity
Employment TypeFull Time, Work from office

About the Company

Deloitte logo

Deloitte

IT Consulting

Assistant Manager | Risk Management | Pune | Cyber Strategy & Transformation at Deloitte | SkillMX | SkillMX