T&T | Cyber CST | Assistant Manager | Security Frameworks | Hyderabad |
Deloitte
Deloitte
Join Deloitte's Cyber Security Assurance & Transformation team in Hyderabad to drive enterprise-wide cyber transformation initiatives. This role involves assessing security risks, validating controls, and enhancing security governance across various technology environments, including applications and cloud platforms.
Focus on security assurance programs, cyber risk assessments, and the adoption of secure-by-design principles within APAC markets. Collaborate with diverse stakeholders to identify control gaps, mitigate cyber risks, and foster organizational resilience, ensuring alignment with regulatory compliance and strategic objectives.
Conduct comprehensive cyber security assessments and validation activities for applications, APIs, cloud platforms, and digital transformation projects. Evaluate the effectiveness of security controls through risk-based reviews and technical assessments.
Perform threat modeling and cyber risk assessments to pinpoint strategic security gaps and emerging threats. Assess security controls against industry standards and regulatory requirements. Support the development and enhancement of enterprise security assurance frameworks and governance processes.
Partner with technology and business teams to integrate security-by-design principles. Develop actionable remediation roadmaps aligned with business priorities. Contribute to cyber maturity assessments and capability reviews across APAC markets. Assist in defining security metrics and key performance indicators to track progress and control effectiveness.
A Bachelor's or Master's degree is required, coupled with a minimum of 5 years of experience in cybersecurity, security assurance, or cyber risk. A strong understanding of cybersecurity frameworks like NIST CSF, ISO 27001, and OWASP is essential.
Experience with cloud security (AWS/Azure), threat modeling, and security architecture reviews is crucial. Familiarity with secure-by-design principles, DevSecOps, and GRC initiatives is expected. Industry certifications such as CISSP, CISM, or CRISC are highly desirable.
Demonstrated ability to manage multiple projects, balance strategic advisory with hands-on assessment, and communicate effectively with both technical and executive audiences. Experience operating in highly regulated environments and supporting multi-country compliance programs is a significant advantage.
Deloitte
Information Technology & Services