T&T | Consultant | ISO:27001 | Bengaluru | Cyber Strategy & Transformation
Deloitte
Deloitte
Join our Cybersecurity practice to help organizations strengthen their defenses against cyber threats and protect critical assets. We focus on building resilient systems that enable new opportunities by integrating cyber risk into strategic development. Discover more about how we manage information and technology risks.
This role involves implementing and maintaining ISO 27001-based Information Security Management Systems. You will assess client security postures, identify gaps and risks, and propose effective mitigation solutions. Collaboration with cross-functional teams to implement cybersecurity best practices and resolve vulnerabilities is key. Staying updated on emerging threats and regulatory landscapes is essential.
Implement and sustain ISO 27001 based Information Security Management Systems. Assess client information security posture and identify gaps/risks. Develop and propose solutions to mitigate identified security gaps and risks. Assist clients in reviewing and implementing information security controls across various domains like change management, incident management, access control, physical security, and media handling. Conduct vendor risk assessments to provide a comprehensive view of outsourcing-related risks. Advise and assist clients in developing and implementing an information classification framework. Work independently on projects with minimal supervision, utilizing firm tools and methodologies.
Conduct security assessments of IT systems, applications, and networks. Perform risk assessments and gap analyses against frameworks like ISO 27001, NIST CSF, PCI-DSS. Possess working knowledge in security domains such as Information Technology, Information Security, Regulatory Compliance, Security Governance, Risk Management, Access Control, Network Security, Security Architecture, IT General Controls, and Third Party Risk Management. Demonstrate in-depth knowledge of information and cyber security controls and risk management processes. Serve as a technical lead or subject matter specialist in security and privacy implementation projects. Exhibit strong analytical, problem-solving, and communication skills. Hold a Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent experience). In-depth understanding of security frameworks like ISO 27001, NIST SP 800-53, CIS Controls. Relevant certifications (CISSP, CISA, CEH, or CRISC) are highly preferred.
Deloitte
Information Technology & Services