Deputy Manager | AI governance-organisation design, policy, controls | Bengaluru | Cyber Strategy &
Deloitte
Deloitte
Join Deloitte's Cyber Strategy & Risk team as a Deputy Manager, focusing on AI governance, organization design, policy, and controls. You will be instrumental in helping organizations navigate complex cyber risks and leverage new opportunities by embedding security into strategic development.
This role offers a dynamic environment where you'll collaborate with various teams to enhance cyber resilience and manage information technology risks effectively. Become part of a leading cybersecurity practice that safeguards valuable assets and empowers clients.
Collaborate with technology, security, and risk teams to enhance GRC and TPRM solutions. Translate control requirements into technical specifications and validation approaches, assessing effectiveness and identifying gaps.
Manage the TPRM lifecycle, including vendor onboarding, risk assessments, and ongoing monitoring. Oversee cybersecurity due diligence questionnaires, coordinating with stakeholders for accurate responses aligned with policies and regulatory expectations.
Validate and document evidence for control compliance and third-party assessments. Analyze risk assessment results, identify weaknesses, and escalate critical risks. Support regulatory and audit activities, including evidence collection and remediation tracking.
Develop expertise in regulatory frameworks like APRA, ASIC, ISO 27001, NIST, and CPS regulations. Recommend and implement process improvements for control validation, TPRM, and reporting. Foster a strong understanding of cybersecurity controls and compliance across teams. Stay updated on evolving threats and best practices in the BFSI sector.
A Bachelor's or Master's degree is required, coupled with over 4 years of experience in Cybersecurity GRC, cyber control reviews, testing, or Third-Party Risk Management. Proficiency in security frameworks such as NIST CSF, CIS, and ISO 27001 is essential.
Strong understanding of control frameworks and standards including ISO 27001, NIST, SOX, COBIT, GDPR, and APRA is necessary. Candidates should possess excellent analytical, problem-solving, communication, and documentation skills, with the ability to manage multiple priorities independently.
Experience with GRC tools and familiarity with cloud environments (AWS/Azure) are advantageous. Exposure to AI-enabled GRC capabilities and scripting for automation is a plus. Preferred certifications include CISSP, CISA, CRISC, or ISO 27001 Lead Auditor/Implementer.
Deloitte
Cybersecurity