T&T | Cyber - CST | Deputy Manager | Third Party Risk Management | Delhi

Deloitte

6–9 yrs New Delhi Full Time Work from office
Deloitte logo
Posted : yesterday
Actively hiring

Job description

Join Deloitte's Cyber Risk team as a Deputy Manager and play a pivotal role in safeguarding organizations against cyber threats. This position focuses on Third Party Risk Management within our Cybersecurity, GRC, and Technology Risk practices. You will engage with diverse clients, driving strategic initiatives to enhance their security posture and manage evolving cyber risks effectively.

Deloitte empowers clients to navigate the complex landscape of cyber threats, ensuring their assets are protected. We advocate for a proactive approach, integrating cyber risk management into strategic development to foster resilience and unlock new opportunities. Become part of a team that helps businesses embed robust security measures into their operations.

Responsibilities

Lead critical engagements in Cyber Security Advisory, GRC, Cyber Risk Management, and Technology Risk across various client environments.

Conduct comprehensive cybersecurity risk, maturity, control, compliance, IT, and third-party risk assessments for IT, OT, Cloud, and emerging technologies.

Develop and refine Cyber Risk Management Frameworks (CRMF), TPRM frameworks, governance models, policies, and procedures, including end-to-end third-party lifecycle management.

Define and implement robust cyber risk tiering, assessment criteria, quantification, escalation processes, and reporting mechanisms aligned with regulatory standards.

Drive ISO/IEC 27001 implementation, gap assessments, and continuous improvement initiatives.

Evaluate cybersecurity controls across diverse environments, covering areas like access management, encryption, vulnerability management, incident response, and resilience.

Perform control maturity and compliance assessments against leading frameworks such as ISO/IEC 27001, NIST CSF, and PCI DSS.

Interpret and apply regulatory requirements, translating them into actionable control and remediation strategies.

Identify risks, control gaps, and improvement opportunities, developing pragmatic remediation plans and transformation roadmaps.

Facilitate client workshops, stakeholder interviews, and deliver impactful executive presentations.

Manage engagement workstreams, project timelines, resources, and ensure high-quality deliverables.

Lead and mentor consulting teams, providing technical guidance and fostering capability development.

Contribute to proposal development, client pursuits, and identify new advisory opportunities.

Collaborate with internal stakeholders to achieve strategic cybersecurity and risk transformation outcomes.

Research emerging threats, regulatory changes, and technology trends to inform client programs.

Leverage AI-enabled tools and analytics to enhance risk assessment and GRC effectiveness.

Qualifications

A Bachelor's or Master's degree is required.

We are seeking candidates with 6 to 9 years of relevant experience in Cyber Security Advisory, GRC, Cyber Risk Management, Technology Risk, IT Audit, Information Security, or Cybersecurity Consulting.

Experience with Big 4 firms, management consulting, or cybersecurity consulting is strongly preferred.

Demonstrated success in leading cybersecurity assessment, risk management, governance, compliance, and transformation engagements is essential.

Possess a strong understanding of ISO/IEC 27001, NIST Cybersecurity Framework (CSF), cyber risk management principles, security controls, and governance practices.

Proven experience managing client workstreams, engagement teams, senior stakeholders, and communicating effectively at the executive level.

Excellent analytical, problem-solving, stakeholder management, report writing, and presentation skills are crucial.

Experience in developing executive-level presentations, strategic roadmaps, governance frameworks, and risk reporting dashboards is expected.

Relevant professional certifications such as CISSP, CISM, CISA, CRISC, ISO/IEC 27001 Lead Implementer, or ISO/IEC 27001 Lead Auditor are advantageous.

AI Governance or AI Security certifications will be an added benefit.

Essential Skills

Cyber Security AdvisoryGRCCyber Risk ManagementTechnology RiskIT AuditInformation SecurityCybersecurity ConsultingISO/IEC 27001NIST Cybersecurity Framework (CSF)Risk ManagementSecurity ControlsGovernance PracticesThird-Party Risk Management (TPRM)Client Engagement ManagementStakeholder ManagementReport WritingPresentation SkillsAI GovernanceAI Security

Good to Have

CISSPCISMCISACRISCISO/IEC 27001 Lead ImplementerISO/IEC 27001 Lead AuditorISO/IEC 42001NIST AI RMF

Highlights

  • Actively hiring

More Details

RoleT&T | Cyber - CST | Deputy Manager | Third Party Risk Management | Delhi
IndustryInformation Technology & Services, Financial Services, Management Consulting
DepartmentRisk Management, Consulting
Employment TypeFull Time, Work from office

About the Company

Deloitte logo

Deloitte

Information Technology & Services

T&T | Cyber - CST | Deputy Manager | Third Party Risk Management | Delhi at Deloitte | SkillMX | SkillMX