Assistant Manager | Security Frameworks and Standards | Bengaluru | Cyber Strategy & Transformation
Deloitte
Deloitte
Join our Cyber Strategy & Transformation team as an Assistant Manager in Bengaluru, focusing on Security Frameworks and Standards. Deloitte empowers organizations to proactively prevent cyberattacks and safeguard critical assets. We champion a secure, vigilant, and resilient approach, embedding cyber risk management early in strategy development to effectively manage information and technology risks and unlock new opportunities.
Our people are driven by a purpose to challenge themselves, identifying critical issues for clients, our communities, and society. This role offers the chance to make a significant impact in a dynamic environment.
Establish and maintain robust risk governance frameworks, facilitating risk identification, evaluation, and continuous monitoring. Design and validate secure IT and OT architectures, integrating application security principles throughout the software development lifecycle. Develop and roll out comprehensive security programs and IT risk management strategies.
Oversee third-party risk assessments and ensure compliance with key regulatory frameworks. Plan and execute IT and OT security audits, including ITGC testing, identifying vulnerabilities, and collaborating on remediation. Assess cybersecurity maturity using frameworks like NIST CSF and develop strategic roadmaps for enhancement. Conduct cyber threat and risk assessments, providing tactical and strategic recommendations.
Lead delivery teams to execute projects according to client specifications, ensuring timely and effective project completion. Manage security and cyber strategy projects, guiding teams daily to meet assigned tasks and responsibilities. Assist clients in reviewing and implementing essential information security controls, including change management, incident management, access management, and more.
Demonstrate a strong ability to develop, implement, and maintain risk and governance frameworks. Guide teams in assessing client information security postures, identifying gaps and risks, and developing mitigation solutions. Recommend security solutions and enhancements aligned with business objectives and the evolving threat landscape.
Perform cybersecurity maturity assessments using established frameworks such as NIST CSF, NIST-800-53, ISO 27001, and ISO/IEC 42001. Lead risk identification, evaluation, mitigation, and monitoring activities, delivering actionable insights and improvement roadmaps.
Possess a solid understanding of application security architectures, including secure SDLC practices and threat modeling. Plan, execute, and report on comprehensive IT and OT security audits, leading teams or working collaboratively on information systems audits. Ensure compliance with cybersecurity guidelines and regulations from bodies like RBI, SEBI, IRDA, and others, tracking evolving requirements.
Experience with ITGC control testing in areas like access and change management is crucial. The role involves interacting with clients, managers, and partners to build strong relationships and tailoring firm methodologies to meet client needs. Possession of certifications such as ISO27001 LA/LI, ISO22301 LA/LI, PMP, CISSP, CISA, or CISM is preferred.
Deloitte
Cybersecurity