T&T | Cyber: CST | Assistant Manager | Risk Management | Bengaluru (Bengaluru, IN)
Deloitte
Deloitte
Join Deloitte's Cyber team as an Assistant Manager in Risk Management, based in Bengaluru. We empower organizations to prevent cyberattacks and safeguard critical assets. Our approach focuses on security, vigilance, and resilience, integrating cyber risk management early in strategy development to effectively manage information and technology risks. Discover more about our Cybersecurity services.
This role offers a dynamic environment to contribute to cutting-edge risk management strategies.
Key responsibilities include supporting the implementation and monitoring of ISO 27001-based Information Security Management Systems (ISMS). You will also assist in Third-Party Risk Management (TPRM) activities, such as vendor risk assessments and due diligence. Performing risk assessments, gap analyses for cybersecurity controls and compliance frameworks, and liaising with clients and internal teams are crucial. Additionally, you'll conduct risk assessments on people, processes, and technology, identify improvement areas, and document findings in comprehensive reports. Collaboration on engagement planning, work papers, and handling the full audit lifecycle from planning to tracking are expected.
This role also involves mentoring team members and addressing complex risk-related issues.
We are seeking candidates with 3 to 5 years of experience in Third-Party Risk Management, ideally from a Big 4 firm or industry. A strong background in IT Audits and Cybersecurity gap assessments, along with experience in ISO 27001 and ISO 22301 implementation and audits, is essential. Understanding of vendor risk management considerations, data protection, and privacy risks is required. Excellent written and verbal communication, documentation, and presentation skills are vital. A Bachelor's degree in Information Technology, Computer Science, Business Administration, Engineering, or a related field is necessary. Security certifications such as CISSP, CISA, CISM, CEH, or ISO 27001 are preferred.
Experience in Infrastructure/Application Security or Information Risk Management is a plus. The ability to thrive in a cross-functional, cross-cultural matrix environment is also valued.
Deloitte
Information Technology & Services