T&T | Cyber: CST | Assistant Manager | Risk Management | Bengaluru (Bengaluru, IN)
Deloitte
Deloitte
Join Deloitte's Cyber Team as an Assistant Manager focused on Risk Management in Bengaluru. This role is crucial in helping organizations prevent cyberattacks and protect valuable assets. You will embed cyber risk management into strategy development for effective information and technology risk management.
As a key member of the Risk Advisory team, you will build strong client relationships and exceed expectations. This position offers a dynamic environment to contribute to cutting-edge cybersecurity solutions and client success.
Implement and monitor Information Security Management Systems (ISMS) aligned with ISO 27001 standards. Execute Third-Party Risk Management (TPRM) activities, including vendor risk assessments and due diligence. Conduct risk assessments and gap analyses for cyber strategy, controls, and compliance frameworks. Liaise effectively with clients and manage stakeholder expectations across various departments. Identify and document client requirements and obligations by working with compliance, auditing, and regulatory teams.
Perform risk assessments and audits focusing on people, process, and technology. Identify gaps, risks, and opportunities for policy and process improvement. Document security risks, recommendations, and controls in assessment reports. Collaborate with engagement teams on vendor information security reviews and develop evaluation models. Manage the full assessment/audit lifecycle, including planning, execution, reporting, and quality review. Provide guidance and share knowledge with team members, addressing complex issues.
We are seeking candidates with 3 to 5 years of experience in Third-Party Risk Management, preferably from a Big 4 firm or industry. A strong background in IT Audits and Cybersecurity gap assessments is essential. Experience with ISO27001 and ISO22301 implementation and audits is highly desirable. Understanding of Data Protection & Privacy risks related to Third Parties and relevant control frameworks is crucial.
Possess excellent written and verbal communication skills, along with strong documentation and presentation abilities. Candidates should be highly motivated and comfortable working in local and global environments. A Bachelor's degree in Information Technology, Computer Science, Business Administration, Engineering, or a related field is required. Relevant certifications such as CBCI, CBCP, ISO22301 LI/LA, Offensive Security Certified Professional, CISA, CISSP, CISM, or CEH are preferred.
Deloitte
Cybersecurity