T&T | Cyber: CST | Deputy Manager | Certified Information Security Manager (CISM) | Bangalore
Deloitte
Deloitte
Join Deloitte's Cyber team as a Deputy Manager, focusing on cyber risk and security. This role is integral to protecting valuable assets and ensuring resilience against cyber threats. You will collaborate with teams and clients to embed cyber risk management into strategy development, fostering effective information and technology risk management.
As part of the Cyber Strategy team, you will be instrumental in building strong client relationships and exceeding expectations through strategic risk mitigation and expert consultation. This is an opportunity to shape security strategies and enhance operational resilience.
Lead the definition, creation, and support of the Cyber Risk Exception handling process, ensuring a risk-based approach is consistently applied. Establish a schedule of authority for risk exception approvals and oversee the full lifecycle management of Risk Exceptions and findings. Implement lightweight assurance to guarantee consistent framework operation across the organization and define the Risk Exception Governance Framework. Ensure risks identified through exception handling are integrated into the broader Cyber Risk Management framework.
Perform risk assessments of business processes, security controls, and technology architecture based on industry standards. Continuously improve the firm’s security risk assessment methodology. Research and consult with subject-matter experts to recommend risk-mitigating solutions, and drive process teams to understand reporting situations and reach consensus on preferred solutions.
Possess a Bachelor's or Master's degree in Information Security or a related field, with advanced degrees and relevant certifications being highly advantageous. Bring 7 to 9 years of domain experience, with proven expertise in third-party risk management, vendor assessments, or ISMS. Deep knowledge of information security principles, Data Protection & Privacy regulations, and control frameworks like ISO 27001 and NIST 800-53 is essential.
Demonstrate strong abilities in liaising with clients, managing stakeholder expectations, and collaborating across departments. Excellent written and verbal communication skills are required for articulating complex concepts to diverse audiences. Detail-oriented organizational skills are crucial for managing multiple client engagements. Proficiency in risk management tools such as ServiceNow, Archer, or OneTrust is expected.
Deloitte
Information Technology & Services