T&T | Consultant | ISO:27001 | Bengaluru | Cyber Strategy & Transformation (Bengaluru, IN)
Deloitte
Deloitte
Join a leading firm as a Cybersecurity Consultant specializing in Cyber Strategy & Transformation. This role focuses on strengthening information security postures for clients, ensuring robust protection of critical assets. You will play a pivotal role in helping organizations navigate the complex landscape of cyber threats and compliance, enabling them to embrace new opportunities securely.
Our team is dedicated to providing organizations with the expertise to prevent cyberattacks, protect valuable assets, and build resilience. We integrate cyber risk management into the core of strategy development, ensuring effective management of information and technology risks.
Implement and sustain ISO 27001-based Information Security Management Systems. Assess client information security, identify gaps and risks, and develop mitigation strategies. Assist clients in reviewing and implementing controls for change management, incident response, backup, access management, and physical security. Conduct vendor risk assessments to provide a comprehensive view of outsourcing-related risks. Advise clients on developing and implementing information classification frameworks.
Contribute to project success with minimal supervision, leveraging firm methodologies. Manage day-to-day client relationships and participate in proposal development to secure additional engagements. Identify opportunities for process improvement and drive business development initiatives within the service line. Play a key role in talent retention, team building, and recruiting efforts, while also fostering professional and practice development.
Key requirements include conducting security assessments for IT systems, applications, and networks to uncover vulnerabilities. Perform comprehensive risk and gap analyses against frameworks like ISO 27001, NIST CSF, and PCI-DSS. Possess working knowledge in at least one of the following security domains: IT, Information Security, Regulatory Compliance, Governance, Risk Management, Access Control, Network Security, Security Architecture, IT General Controls, or Third Party Risk Management.
Demonstrate deep understanding of information and cyber security controls and risk management processes. Serve as a technical lead or subject matter expert for security and privacy implementation projects, overseeing design, build, testing, and deployment. Exhibit the ability to work autonomously and understand complex business and IT management processes. Familiarity with firm tools and methodologies is expected.
Develop and recommend security policies and procedures to address identified risks. Collaborate with cross-functional teams to implement cybersecurity best practices and resolve vulnerabilities. Stay abreast of the latest cyber threats, trends, and regulatory changes. A Bachelor’s degree in Computer Science, Information Security, or a related field is required, or equivalent experience. Relevant certifications such as CISSP, CISA, CEH, or CRISC are highly preferred. Strong analytical, problem-solving, and communication skills are essential.
Deloitte
IT Consulting