T&T | Cyber: CST | Deputy Manager | Certified Information Security Manager (CISM) | Bangalore

Deloitte

7–9 yrs Coimbatore Full Time Work from office
Deloitte logo
Posted : yesterday
Actively hiring

Job description

Join Deloitte's Cyber team as a Deputy Manager, focusing on cyber risk and security. This role is integral to protecting valuable assets and ensuring resilience against cyber threats. You will collaborate with teams and clients to embed cyber risk management into strategy development, fostering effective information and technology risk management.

As part of the Cyber Strategy team, you will be instrumental in building strong client relationships and exceeding expectations through strategic risk mitigation and expert consultation. This is an opportunity to shape security strategies and enhance operational resilience.

Responsibilities

Lead the definition, creation, and support of the Cyber Risk Exception handling process, ensuring a risk-based approach is consistently applied. Establish a schedule of authority for risk exception approvals and oversee the full lifecycle management of Risk Exceptions and findings. Implement lightweight assurance to guarantee consistent framework operation across the organization and define the Risk Exception Governance Framework. Ensure risks identified through exception handling are integrated into the broader Cyber Risk Management framework.

Perform risk assessments of business processes, security controls, and technology architecture based on industry standards. Continuously improve the firm’s security risk assessment methodology. Research and consult with subject-matter experts to recommend risk-mitigating solutions, and drive process teams to understand reporting situations and reach consensus on preferred solutions.

Qualifications

Possess a Bachelor's or Master's degree in Information Security or a related field, with advanced degrees and relevant certifications being highly advantageous. Bring 7 to 9 years of domain experience, with proven expertise in third-party risk management, vendor assessments, or ISMS. Deep knowledge of information security principles, Data Protection & Privacy regulations, and control frameworks like ISO 27001 and NIST 800-53 is essential.

Demonstrate strong abilities in liaising with clients, managing stakeholder expectations, and collaborating across departments. Excellent written and verbal communication skills are required for articulating complex concepts to diverse audiences. Detail-oriented organizational skills are crucial for managing multiple client engagements. Proficiency in risk management tools such as ServiceNow, Archer, or OneTrust is expected.

Essential Skills

Cyber Risk ManagementInformation Security StandardsRisk Exception HandlingGlobal Best Practice Standards (NISTCISISO)Three Lines of Defense ModelNetwork SecurityApplication SecurityVulnerability ManagementPatch ManagementData SecurityRisk Exception Governance FrameworkRisk Assessment MethodologySecurity ControlsTechnology ArchitectureStakeholder ManagementInterpersonal SkillsCollaborative EnvironmentProcess ImprovementRisk Mitigating SolutionsPresentation SkillsThird-Party Risk ManagementVendor AssessmentsISMSData Protection RegulationsPrivacy RegulationsISO 27001NIST 800-53GDPRRisk Management Tools (ServiceNowArcherOneTrustCoupa)

Good to Have

Certified Third-Party Risk Professional (CTPRP)Certified Third Party Risk Assessor (CTPRA)Certified Information Systems Security Professional (CISSP)Certified Information Systems Auditor (CISA)Certified Information Security Manager (CISM)ISO 22301

Highlights

  • Actively hiring

More Details

RoleT&T | Cyber: CST | Deputy Manager | Certified Information Security Manager (CISM) | Bangalore
IndustryInformation Technology & Services, Cybersecurity
DepartmentRisk Management
Employment TypeFull Time, Work from office

About the Company

Deloitte logo

Deloitte

Information Technology & Services

T&T | Cyber: CST | Deputy Manager | Certified Information Security Manager (CISM) | Bangalore at Deloitte | SkillMX | SkillMX