T&T | Cyber: CST | Associate Director | CISSP | GRC | Gurgaon
Deloitte
Deloitte
Join Deloitte T&T Cyber as an Associate Director in Gurgaon, focusing on Cyber Security and Governance, Risk, and Compliance (GRC). This role is crucial in helping organizations enhance their cybersecurity posture and manage risks effectively.
Deloitte empowers businesses to proactively prevent cyberattacks and safeguard critical assets. We advocate for a secure, vigilant, and resilient approach by integrating cyber risk management into strategic development, enabling better management of information and technology risks. Explore more about Cyber | Deloitte.
This position offers a dynamic environment to lead and contribute to cutting-edge cybersecurity initiatives, making a significant impact on client security strategies.
Develop and implement robust risk and governance frameworks. Guide teams in assessing client information security, identifying vulnerabilities, and designing mitigation strategies.
Recommend tailored security enhancements aligned with business objectives and the evolving threat landscape. Conduct thorough security risk assessments for third-party vendors and service providers, and establish comprehensive Third-Party Risk Management (TPRM) frameworks.
Perform cybersecurity maturity assessments using leading frameworks like NIST CSF, NIST-800-53, and ISO 27001. Lead Information Security Management System implementation and sustenance projects based on ISO 27001.
Spearhead risk identification, evaluation, mitigation, and monitoring activities, delivering actionable insights and improvement roadmaps. Assess application security architectures, including secure SDLC, threat modeling, and coding standards.
Plan and execute IT and OT security audits, and lead teams in conducting Information Systems audits for IT infrastructure. Manage security and cyber strategy projects, providing day-to-day guidance to ensure timely task completion.
Assist clients in reviewing and implementing information security controls for areas such as change management, incident management, access management, and physical security. Support PCI DSS assessments and provide remediation guidance.
We seek individuals with a Bachelor’s degree in Information Security, Computer Science, or a related discipline, with a Master’s degree in Cybersecurity or Business Management being a strong preference.
Candidates should possess 9 to 15 years of experience in cybersecurity consulting, risk management, and compliance. Professional certifications like CISSP, CISA, CISM, CRISC, or ISO 27001 certifications are highly valued.
Demonstrated in-depth knowledge of security frameworks such as NIST, ISO 27001, and COBIT is essential. Strong analytical, communication, and stakeholder management skills are required for effective client interaction and team leadership.
Understanding of cloud security models across AWS, Google Cloud, and Azure, as well as experience with ITGC control testing, is expected. Maintaining compliance with evolving cybersecurity guidelines from regulatory bodies like RBI, SEBI, and IRDA is critical.
Deloitte
Information Technology & Services