Manager | Security Frameworks and Standards | Pune | Cyber Strategy & Transformation
Deloitte
Deloitte
Join Deloitte's Cyber Strategy & Transformation team in Pune as a Manager for Security Frameworks and Standards. This role is integral to enhancing organizational cyber resilience and transforming security initiatives.
Deloitte empowers organizations to proactively defend against cyber threats and safeguard critical assets. Our approach emphasizes security, vigilance, and resilience, integrating cyber risk management into strategic development to unlock new opportunities.
Learn more about our Cyber services and how we help clients manage information and technology risks effectively.
Lead cyber capability and security control assessments using frameworks like NIST CSF, ISO 27001, and CIS Controls. Identify and address capability gaps, control deficiencies, and cybersecurity risks. Develop cyber maturity assessments and roadmaps for capability enhancement.
Support control documentation, evidence management, and remediation efforts. Evaluate various security domains including identity, endpoint, network, cloud, and application security. Assess the effectiveness of preventive, detective, and corrective security controls.
Utilize Microsoft Sentinel and KQL for security analysis and control validation. Analyze security events and trends to identify improvement areas. Contribute to cyber governance, risk management, and assurance activities, supporting transformation programs to strengthen security posture.
An experienced cybersecurity professional with 8-10 years in Cybersecurity, Cyber Risk, Security Controls, Governance, Compliance, or Cyber Transformation. A Bachelor's degree (B.E./B.Tech) from a Tier 1/2 institution or a Master's degree in Information Security, Computer Science, or a related field is required.
Demonstrated experience in leading security control reviews, risk assessments, or capability assessments. Knowledge of incident response methodologies and common attack techniques is essential. Familiarity with identity, endpoint, network, cloud, and application security domains is crucial.
Proficiency in Microsoft Sentinel and KQL for security analysis and control validation. Strong analytical, problem-solving, stakeholder engagement, documentation, reporting, and communication skills are necessary for success in this role. Experience with frameworks such as NIST CSF, ISO 27001, or CIS Controls is expected.
Deloitte
Cyber Strategy & Transformation