Consultant | ISO:27001 | Bengaluru | Cyber Strategy & Transformation
Deloitte
Deloitte
Join a leading cybersecurity team focused on empowering organizations to prevent attacks and safeguard critical assets. We prioritize a secure, vigilant, and resilient approach to cyber risk management, integrating it into strategic development for effective information and technology risk mitigation. Explore the world of Cybersecurity with us.
This role involves driving ISO 27001-based Information Security Management System implementation and ensuring its ongoing effectiveness. You will assess client information security postures, identify vulnerabilities and risks, and devise robust solutions for mitigation. The position requires assisting clients in reviewing and implementing key information security controls across various domains.
Key responsibilities include conducting client vendor risk assessments for a comprehensive view of outsourcing-related risk exposure. You will also advise and support clients in developing and implementing an effective information classification framework. The role demands the ability to work independently on projects with minimal supervision and leverage firm tools and methodologies effectively.
Further responsibilities involve managing day-to-day client relationships at mid and lower levels, participating in proposal development, and identifying opportunities to enhance engagement economics. You will play a role in designing and implementing business development plans, contributing to professional retention, and building team capabilities through recruiting and staff development initiatives. Proactive involvement in people and practice development is also expected.
We are seeking individuals with a Bachelor’s degree in computer science, Information Security, or a related field, or equivalent experience. Essential skills include conducting security assessments of IT systems, applications, and networks, along with performing risk and gap analyses against frameworks like ISO 27001, NIST CSF, and PCI-DSS. Demonstrated knowledge in security domains such as IT, Information Security, Regulatory Compliance, Risk Management, Access Control, and Network Security is crucial.
Proficiency in information and cyber security controls and risk management processes is required. The role demands experience serving as a technical lead or subject matter specialist in security and privacy implementation projects, encompassing design, build, testing, and deployment. Strong analytical, problem-solving, and communication skills are essential. While not mandatory, relevant certifications like CISSP, CISA, CEH, or CRISC are highly advantageous.
Deloitte
Cybersecurity