T&T | Cyber CST | Assistant Manager | Security Frameworks and Standards | Pune | (Pune, IN)
Deloitte
Deloitte
Join Deloitte Touche Tohmatsu India LLP as an Assistant Manager in Cyber CST, focusing on Security Frameworks and Standards in Pune. This role is integral to our mission of safeguarding organizations against cyber threats and protecting critical assets. We empower clients to manage cyber risk effectively, enabling them to seize new opportunities while maintaining security, vigilance, and resilience.
We are seeking experienced cybersecurity professionals with a strong background in Cyber Risk, Security Controls, Cyber Capability Development, and Security Technology Enablement. Your expertise will be crucial in driving cybersecurity transformation initiatives and enhancing the cyber resilience, governance, and security maturity across enterprises.
This position involves assessing cybersecurity capabilities and the effectiveness of security controls within diverse technology environments. You will play a key role in reviewing controls against established frameworks like NIST CSF, ISO 27001, and CIS Controls. Responsibilities include supporting cyber maturity assessments, developing capability roadmaps, and assisting with control documentation and remediation tracking. Furthermore, you'll evaluate security across identity, endpoint, network, cloud, and application domains, using tools like Microsoft Sentinel and KQL to validate controls and analyze security telemetry.
You will contribute to cyber transformation programs, collaborate with various technology and business teams to implement improvements, and support the creation of cybersecurity metrics and reporting. Maintaining assessment findings and transformation deliverables is also a core part of this role. A solid understanding of incident-response methodologies and common attack techniques is essential for effective control reviews and capability enhancement.
We are looking for candidates with 2-4 years of experience in Cybersecurity, Cyber Risk, Security Controls, Governance, Compliance, or Cyber Transformation. A thorough understanding of cybersecurity control frameworks and industry standards, including exposure to NIST CSF, ISO 27001, or CIS Controls, is required. Proficiency in Microsoft Sentinel and KQL for security analysis and control validation is essential.
Experience in security control reviews, risk assessments, or capability assessments is necessary, along with knowledge of identity, endpoint, network, cloud, and application security domains. Strong documentation, reporting, and communication skills are vital. Candidates should possess a B.E./B.Tech or Master's degree in Information Security, Computer Science, or a related field.
Deloitte
Information Technology & Services