Assistant Manager | Security Frameworks and Standards | Hyderabad | Cyber Strategy & Transformation

Deloitte

5+ yrs Hyderabad Full Time Hybrid (office + remote)
Deloitte logo
Posted : 1 week ago
Actively hiring

Job description

Join Deloitte's Cyber Strategy & Transformation team as an Assistant Manager specializing in Security Frameworks and Standards. This role is crucial for enhancing enterprise-wide cyber resilience by assessing security risks, validating controls, and strengthening governance across diverse technology environments.

You will drive security assurance programs and cyber risk assessments, particularly within the APAC region. Collaborating with security, technology, risk, and business stakeholders, you will identify control gaps, mature security practices, and provide strategic recommendations to ensure regulatory compliance and robust cyber resilience.

This position offers a dynamic opportunity to contribute to cutting-edge cyber transformation initiatives and shape the future of cybersecurity for leading organizations.

Responsibilities

- Conduct comprehensive cyber security assessments and validation activities for applications, APIs, cloud platforms, and digital transformation projects. - Evaluate the effectiveness of security controls through risk-based reviews and technical assessments. - Perform threat modeling and cyber risk assessments to pinpoint strategic security gaps and emerging threats. - Assess security controls against organizational standards, regulatory requirements, and industry frameworks. - Support the development and operationalization of enterprise security assurance frameworks and governance processes. - Validate security control effectiveness and identify opportunities for cyber resilience improvement. - Partner with architecture and engineering teams to embed security-by-design principles. - Develop risk-informed recommendations and remediation roadmaps aligned with business priorities. - Support security governance activities through control assessments and compliance reviews. - Contribute to cyber maturity assessments and transformation initiatives across APAC markets. - Assist in defining security metrics, KRIs, and KPIs to measure progress and control effectiveness. - Support audit readiness by ensuring proper documentation of security controls and remediation activities. - Collaborate with stakeholders to align security assurance with enterprise cyber strategy. - Facilitate workshops and forums to communicate cyber risks and strategic improvement opportunities. - Support security validation initiatives, including penetration testing and control effectiveness reviews. - Review findings from various security testing and assessment activities to identify systemic risks. - Assess security controls across cloud environments (AWS/Azure), containerized platforms, and modern application architectures. - Evaluate application security controls such as authentication, authorization, and API security. - Perform secure architecture and design assessments during technology implementation. - Provide subject matter expertise during security incidents and root-cause analysis. - Partner with leaders to support security transformation and strategic cyber programs. - Develop executive-level reports and risk summaries for senior leadership. - Support regulatory compliance by validating security controls against requirements. - Drive continuous improvement initiatives for cyber resilience and enterprise security posture. - Promote a security-first culture through knowledge sharing and engagement. - Collaborate with stakeholders across APAC and global regions.

Qualifications

- A minimum of 5 years of experience in Cyber Security, Security Assurance, Cyber Risk, Application Security, Security Architecture, or Security Testing. - Proven experience conducting cyber risk assessments, security reviews, and control assessments in enterprise environments. - Strong understanding of cybersecurity frameworks and standards such as NIST CSF, ISO 27001, CIS Controls, OWASP, and MITRE ATT&CK. - Experience assessing security controls across applications, cloud environments (AWS/Azure), and infrastructure. - Familiarity with cloud security concepts and secure-by-design principles. - Experience performing threat modeling, attack surface analysis, or cyber risk assessments. - Experience supporting governance, risk, compliance, audit, or regulatory-driven security initiatives. - Excellent analytical, problem-solving, stakeholder management, and communication skills. - Ability to produce executive-level reporting and strategic recommendations. - Prior consulting or advisory experience supporting senior executives and transformation programs is highly desirable. - Industry certifications such as CISSP, CISM, CRISC, CCSP, SABSA, TOGAF, CCSK, or equivalent are a plus. - Experience supporting cyber transformation, cloud transformation, or enterprise security modernization initiatives. - Knowledge of penetration testing, adversary simulation, or security validation methodologies. - Experience with security architecture reviews and secure solution design assessments. - Familiarity with DevSecOps, Secure SDLC, cloud-native security, and container security concepts. - Experience working within highly regulated industries like Banking, Financial Services, Healthcare, or Government. - Ability to manage multiple concurrent assessments and stakeholder engagements while maintaining quality and timelines. - Strong documentation, presentation, and communication skills, with the ability to articulate risks to both technical and executive audiences. - Ability to balance strategic advisory with hands-on security assessment activities. - Experience operating in complex, multi-country, and highly regulated environments. - Flexibility to collaborate with stakeholders across APAC and global regions. - Bachelor's or Master's degree in a relevant field.

Essential Skills

CybersecuritySecurity FrameworksRisk AssessmentSecurity ControlsGovernanceNIST CSFISO 27001CIS ControlsOWASPMITRE ATT&CKCloud Security (AWS/Azure)Threat ModelingSecure-by-DesignGRCCommunication SkillsStakeholder ManagementProblem-Solving

Good to Have

CISSPCISMCRISCCCSPSABSATOGAFCCSKPenetration TestingRed TeamingDevSecOpsSecure SDLC

Highlights

  • Actively hiring

More Details

RoleAssistant Manager | Security Frameworks and Standards | Hyderabad | Cyber Strategy & Transformation
IndustryCybersecurity, Management Consulting
DepartmentRisk Management
Employment TypeFull Time, Hybrid (office + remote)

About the Company

Deloitte logo

Deloitte

Cybersecurity

Assistant Manager | Security Frameworks and Standards | Hyderabad | Cyber Strategy & Transformation at Deloitte | SkillMX | SkillMX