T&T | Cyber: CST | Assistant Manager | Security Frameworks and Standards | Bengaluru
Deloitte
Deloitte
Join a leading cybersecurity team dedicated to safeguarding organizations and their critical assets. We focus on proactive security, resilience, and managing cyber risk to enable new business opportunities. Our approach integrates cyber risk into strategic planning, ensuring effective management of information and technology.
This role involves embracing challenges to identify and address key issues for clients, our people, and society. We are seeking individuals who are passionate about protecting against cyber threats and building robust security postures.
Establish and maintain robust risk governance frameworks, leading the identification, evaluation, mitigation, and ongoing monitoring of risks. Design and validate secure IT and OT architectures, ensuring application security principles are embedded throughout the software development lifecycle. Develop and implement comprehensive security programs, including IT risk management strategies and compliance initiatives. Oversee third-party risk assessments and ensure adherence to regulatory frameworks like RBI, SEBI, IRDA, and PCI DSS. Conduct IT and OT security audits, including ITGC testing, identifying vulnerabilities, and collaborating on remediation efforts. Assess cybersecurity maturity using frameworks such as NIST CSF and develop strategic roadmaps for continuous improvement. Perform cyber threat and risk assessments, providing actionable recommendations to mitigate business implications.
Demonstrated experience in designing, developing, and rolling out security programs, coupled with expertise in IT risk management and compliance. Ability to define business and technical project scopes, and independently lead delivery teams to meet client specifications. Strong understanding of application security architectures, secure SDLC practices, threat modeling, and secure coding standards. Proficiency in performing cybersecurity maturity assessments using frameworks like NIST CSF, NIST-800-53, and ISO 27001. Proven ability to lead risk identification, evaluation, mitigation, and monitoring activities, delivering actionable insights. Experience in planning and executing comprehensive IT and OT security audits, including ITGC control testing. Familiarity with cybersecurity guidelines and regulations from bodies such as RBI, SEBI, IRDA, and NCIIPC, with the ability to track evolving requirements. Excellent client interaction skills, with the capability to build and nurture strong relationships.
Deloitte
Information Technology & Services