T&T | Cyber: CST | Consultant | Third Party Risk Management | Pune
Deloitte
Deloitte
Deloitte Touche Tohmatsu India LLP is seeking a Consultant for their Cyber Security team in Pune, specializing in Third Party Risk Management. This role involves helping organizations proactively prevent cyberattacks and safeguard critical assets. We focus on integrating cyber risk management into strategic development, enabling effective handling of information and technology risks. Explore the world of Cybersecurity with us.
This position offers a unique opportunity to contribute to Deloitte's mission of building secure, vigilant, and resilient systems. You will be instrumental in developing strategies that not only mitigate risks but also unlock new business opportunities through robust cybersecurity practices.
You will conduct comprehensive Third-Party Risk Assessments and manage Information Security Management Systems (ISMS). Effectively engage with clients, managing stakeholder expectations and collaborating with diverse client teams. Work with compliance, auditing, and regulatory departments to identify and document various requirements. Perform thorough risk assessments and audits covering people, processes, and technology. Identify gaps, risks, and opportunities for improvement in policies, processes, and standards. Document risk assessments and recommendations in detailed reports.
Key responsibilities include understanding vendor and supplier risk management, analyzing data protection and privacy risks associated with third parties, and applying relevant control frameworks. Your role will involve detailed documentation and reporting of findings, ensuring clear communication of risks and proposed solutions to clients and internal teams.
A Bachelor's degree in Computer Science, Information Technology, or a related field is required. You should possess at least 2 years of relevant experience in IT Audits and Cloud Security. Mandatory Cyber Third-Party Risk Management (TPRM) experience is required, ranging from 1 to 7 years. Experience with ISO22301 implementation and audits is also essential. Excellent written and verbal communication, documentation, and presentation skills are crucial. A highly motivated individual willing to work in local and global environments is ideal.
Preferred qualifications include certifications such as CBCI, CBCP, ISO22301 LI/LA, Offensive Security Certified Professional, or CISA. Experience in cross-functional, cross-cultural matrix environments is advantageous. Familiarity with security certifications like CISSP, CISA, CISM, CEH, or ISO27001, as well as work experience in Infrastructure/Application Security, IT Audit, and Information Risk Management, will strengthen your application.
Deloitte
Management Consulting