T&T | Cyber: CST | Assistant Manager | Risk Management | Bengaluru
Deloitte
Deloitte
Join our Cybersecurity team at Deloitte Touche Tohmatsu India LLP in Bengaluru, where we empower organizations to proactively prevent cyberattacks and safeguard critical assets. We focus on building secure, vigilant, and resilient strategies by integrating cyber risk management into the core of business development, enabling the exploration of new opportunities.
Our approach embeds cyber risk considerations from the outset of strategy formulation, ensuring more effective management of information and technology risks. We offer a dynamic environment for professionals passionate about shaping the future of cyber resilience.
Support the implementation and ongoing monitoring of Information Security Management Systems (ISMS) aligned with ISO 27001 standards. Conduct Third-Party Risk Management (TPRM) activities, including vendor risk assessments and due diligence. Perform comprehensive risk assessments and gap analyses for cyber strategy, controls, and compliance frameworks.
Effectively liaise with clients, manage stakeholder expectations, and collaborate with diverse client teams, including compliance, auditing, and regulatory bodies. Identify and document various requirements and obligations through diligent engagement. Conduct thorough risk assessments and audits covering people, processes, and technology, identifying gaps, risks, and opportunities for improvement in policies and procedures. Document findings and recommendations in detailed assessment and audit reports.
We are seeking candidates with 3 to 5 years of experience in third-party risk management, ideally from a Big 4 firm or industry. Relevant experience in IT Audits and Cybersecurity gap assessments is essential. Familiarity with ISO27001 and ISO22301 implementation and audits is highly valued.
Demonstrated understanding of third-party/vendor/supplier risk management principles and knowledge of data protection and privacy risks related to third parties are crucial. Excellent written and verbal communication, documentation, and presentation skills are a must. We are looking for highly motivated individuals willing to work in diverse environments. Experience in infrastructure/application security, IT audit, or information risk management is advantageous. Preferred certifications include CBCI, CBCP, ISO22301 LI/LA, CISA, CISSP, CISM, or CEH.
Deloitte
Information Technology & Services