T&T | Cyber CST | Deputy Manager | Security Frameworks and Standards | Pune | (Pune, IN)
Deloitte
Deloitte
Join a leading cybersecurity team dedicated to safeguarding valuable assets and preventing cyberattacks. We focus on building resilient systems that manage cyber risk effectively, enabling new opportunities. This role is crucial for enhancing cyber resilience, governance, and security maturity across the enterprise.
Leverage your expertise to assess cybersecurity capabilities, evaluate control effectiveness, and identify areas for improvement. Support strategic initiatives that fortify our defense against evolving threats and ensure robust cyber governance.
Conduct comprehensive cyber capability and security control assessments within diverse technology environments. Review and benchmark security controls against industry-leading frameworks like NIST CSF, ISO 27001, and CIS Controls. Identify critical capability gaps, control deficiencies, and emerging cybersecurity risks to drive transformation.
Develop and refine cyber maturity assessments and capability development roadmaps. Facilitate control documentation, evidence management, and remediation tracking. Evaluate security across identity, endpoint, network, cloud, and application domains, assessing the efficacy of preventive, detective, and corrective controls. Analyze security telemetry and events using tools like Microsoft Sentinel and KQL to validate controls and identify enhancement opportunities.
We are seeking experienced cybersecurity professionals with 5-8 years in Cybersecurity, Cyber Risk, Security Controls, Governance, Compliance, or Cyber Transformation. A strong understanding of cybersecurity control frameworks and industry standards, including NIST CSF, ISO 27001, or CIS Controls, is essential.
Proficiency in Microsoft Sentinel and KQL for security analysis and control validation is required. Experience in security control reviews, risk assessments, and evaluating security domains such as identity, endpoint, network, cloud, and applications is necessary. Excellent analytical, problem-solving, stakeholder engagement, documentation, reporting, and communication skills are expected.
Candidates should possess a B.E./B.Tech (Tier 1/2) or Master’s degree in Information Security, Computer Science, or a related field. Knowledge of incident-response methodologies and common attack techniques is beneficial for supporting control effectiveness assessments and capability improvement initiatives.
Deloitte
Information Technology & Services