T&T | Assistant Manager | Third Party Risk Management | Hyderabad | Cyber Strategy & Transformation
Deloitte
Deloitte
Join our Cyber Strategy and Transformation team to drive impactful cybersecurity initiatives. We focus on building secure, vigilant, and resilient organizations, integrating cyber risk management into strategic development to unlock new opportunities.
This role involves collaborating with technology, security, and risk experts to manage and enhance Governance, Risk, and Compliance (GRC) and Third-Party Risk Management (TPRM) solutions. You will play a crucial part in assessing control effectiveness, identifying gaps, and ensuring robust security postures across applications, systems, and networks.
As an Assistant Manager in Third-Party Risk Management, you will lead and support security audits, compliance reviews, and comprehensive risk assessments. A key focus will be managing the TPRM lifecycle, from vendor onboarding to ongoing monitoring and conducting cybersecurity due diligence questionnaires. You will also coordinate with internal stakeholders to gather accurate responses, ensuring alignment with organizational policies and regulatory frameworks.
Your role will involve collecting, validating, and documenting evidence for control compliance and third-party assessments. You will analyze assessment results, identify control weaknesses, and escalate critical risks. Additionally, you'll support regulatory activities and recommend improvements to TPRM processes and documentation. Maintaining up-to-date knowledge of evolving threats and regulatory landscapes, particularly within the BFSI sector, is essential.
We are seeking an experienced professional with a Bachelor’s degree in Computer Science, Information Technology, or a related field, complemented by over 4 years of experience in Cybersecurity GRC, Cyber control reviews and assessments, or Third-Party Risk Management. A strong understanding of security frameworks like NIST CSF, CIS, and ISO 27001, along with knowledge of regulatory standards such as APRA, ASIC, and GDPR, is vital.
Exceptional analytical and problem-solving abilities are required, alongside excellent communication and documentation skills. The capacity to manage multiple priorities and work independently is crucial for success in this role. Familiarity with security frameworks (NIST CSF, CIS, ISO 27001) and a strong grasp of control frameworks and standards (e.g., ISO 27001, NIST, SOX, COBIT, GDPR, APRA) are key qualifications.
Deloitte
Cybersecurity