Assistant Manager | Third Party Risk Management | Hyderabad | Cyber Strategy & Transformation
Deloitte
Deloitte
Join Deloitte's Cyber Strategy & Transformation team as an Assistant Manager in Third-Party Risk Management. This role focuses on preventing cyberattacks and protecting valuable assets, ensuring organizations are secure, vigilant, and resilient. You will embed cyber risk into strategy development for effective information and technology risk management, enabling new opportunities while managing risks.
Learn more about the impact of Cyber at Deloitte and how we help clients navigate the complex landscape of cybersecurity.
Drive key cybersecurity initiatives within the Cyber Strategy team. Cultivate and maintain robust relationships with internal stakeholders and clients to ensure superior project delivery and satisfaction. Uphold security governance frameworks and oversee the implementation of security controls across diverse applications, systems, and network infrastructures. Lead and contribute to security audits, compliance reviews, and critical risk assessment activities.
Work collaboratively with technology, security, and risk teams to effectively manage and support GRC and TPRM solutions. Translate control requirements into actionable control validation approaches to thoroughly assess effectiveness. Identify implementation gaps and manage the entire Third-Party Risk Management (TPRM) lifecycle, from vendor onboarding to ongoing monitoring.
Manage cybersecurity due diligence questionnaires from clients, partners, and vendors, coordinating with internal teams for accurate and timely responses. Ensure all responses align with organizational policies, regulatory expectations, and control frameworks. Track project status, timelines, and outcomes diligently.
Validate and document evidence to support control compliance, third-party assessments, and audit requirements. Analyze control validation and TPRM results, identify weaknesses, and escalate critical risks to senior management. Support regulatory and audit activities by collecting and validating evidence and tracking remediation efforts.
Develop and maintain comprehensive knowledge of regulatory frameworks such as APRA, ASIC, ISO 27001, NIST, and other applicable financial services regulations. Recommend and implement process improvements for control validation, TPRM, documentation, and reporting. Foster a strong understanding of cybersecurity controls, third-party risk, and compliance across teams. Stay abreast of evolving threats, regulations, and best practices in the BFSI sector.
This role requires a Bachelor’s degree in Computer Science, Information Technology, or a related field, coupled with 4+ years of experience in Cybersecurity GRC, Cyber control reviews, Third-Party Risk Management (TPRM), or a comparable position. Proficiency with security frameworks like NIST CSF, CIS, and ISO 27001 is essential, along with a solid understanding of control frameworks and standards (ISO 27001, NIST, SOX, COBIT, GDPR, APRA). Strong analytical, problem-solving, communication, and documentation skills are expected, as is the ability to manage multiple priorities independently.
Deloitte
Cybersecurity