T&T | Cyber: CST | Assistant Manager | Risk Management | Bengaluru

Deloitte

3–5 yrs Bengaluru Full Time Work from office
Deloitte logo
Posted : yesterday
Actively hiring

Job description

Join our Cybersecurity team at Deloitte Touche Tohmatsu India LLP in Bengaluru, where we empower organizations to proactively prevent cyberattacks and safeguard critical assets. We focus on building secure, vigilant, and resilient strategies by integrating cyber risk management into the core of business development, enabling the exploration of new opportunities.

Our approach embeds cyber risk considerations from the outset of strategy formulation, ensuring more effective management of information and technology risks. We offer a dynamic environment for professionals passionate about shaping the future of cyber resilience.

Responsibilities

Support the implementation and ongoing monitoring of Information Security Management Systems (ISMS) aligned with ISO 27001 standards. Conduct Third-Party Risk Management (TPRM) activities, including vendor risk assessments and due diligence. Perform comprehensive risk assessments and gap analyses for cyber strategy, controls, and compliance frameworks.

Effectively liaise with clients, manage stakeholder expectations, and collaborate with diverse client teams, including compliance, auditing, and regulatory bodies. Identify and document various requirements and obligations through diligent engagement. Conduct thorough risk assessments and audits covering people, processes, and technology, identifying gaps, risks, and opportunities for improvement in policies and procedures. Document findings and recommendations in detailed assessment and audit reports.

Qualifications

We are seeking candidates with 3 to 5 years of experience in third-party risk management, ideally from a Big 4 firm or industry. Relevant experience in IT Audits and Cybersecurity gap assessments is essential. Familiarity with ISO27001 and ISO22301 implementation and audits is highly valued.

Demonstrated understanding of third-party/vendor/supplier risk management principles and knowledge of data protection and privacy risks related to third parties are crucial. Excellent written and verbal communication, documentation, and presentation skills are a must. We are looking for highly motivated individuals willing to work in diverse environments. Experience in infrastructure/application security, IT audit, or information risk management is advantageous. Preferred certifications include CBCI, CBCP, ISO22301 LI/LA, CISA, CISSP, CISM, or CEH.

Essential Skills

Information Security Management System (ISMS)ISO 27001Third-Party Risk Management (TPRM)Vendor Risk AssessmentCybersecurity ControlsCompliance FrameworksRisk AssessmentGap AnalysisClient Relationship ManagementStakeholder ManagementISO 22301Data ProtectionPrivacy RisksIT AuditInformation Risk ManagementInfrastructure SecurityApplication Security

Good to Have

CBCICBCPISO22301 LIISO22301 LAOffensive Security Certified ProfessionalCISACISSPCISMCEH

Highlights

  • Actively hiring

More Details

RoleT&T | Cyber: CST | Assistant Manager | Risk Management | Bengaluru
IndustryInformation Technology & Services, Cybersecurity, Management Consulting
DepartmentRisk Management, Cybersecurity
Employment TypeFull Time, Work from office

About the Company

Deloitte logo

Deloitte

Information Technology & Services

T&T | Cyber: CST | Assistant Manager | Risk Management | Bengaluru at Deloitte | SkillMX | SkillMX