T&T | Cyber: CST | Manager | Security Frameworks and Standards | Bengaluru (Bengaluru, IN)
Deloitte
Deloitte
Join a leading cybersecurity team focused on helping organizations prevent cyberattacks and protect valuable assets. We champion a secure, vigilant, and resilient approach, integrating cyber risk management into strategic development to unlock new opportunities. Our mission is to embed robust security from the outset for effective information and technology risk management.
This role is ideal for a Subject Matter Specialist in GRC and multiple security domains, with extensive experience in leveraging industry standards and frameworks. You will establish and maintain risk governance, design secure IT architectures, and oversee security programs. Advising on secure cloud architecture and developing vulnerability management programs are also key aspects of this position.
Establish and maintain risk governance frameworks, facilitating risk identification, evaluation, mitigation, and continuous monitoring. Design and validate secure IT architectures, ensuring application security principles are integrated throughout the software development lifecycle. Oversee third-party risk assessments and ensure compliance with regulatory frameworks such as RBI, SEBI, IRDA, and PCI DSS. Advise on secure cloud architecture and best practices across AWS, Azure, and Google Cloud platforms. Build vulnerability management programs, plan and execute IT and OT security audits, and collaborate on remediation efforts. Develop strategic roadmaps to enhance the organization's cybersecurity maturity using frameworks like NIST CSF. Conduct cyber threat and risk assessments, identifying business implications and providing mitigation recommendations.
Possess extensive experience in leveraging industry standards and frameworks such as ISO/IEC 27001, COBIT, and ITIL. Demonstrate experience in establishing risk governance, designing secure IT architectures, and developing security programs. Familiarity with cloud security best practices across AWS, Azure, and Google Cloud platforms is essential. Experience in building vulnerability management programs and conducting IT and OT security audits is required. Ability to assess cybersecurity maturity using frameworks like NIST CSF and develop strategic roadmaps. Certifications such as ISO27001 LA/LI, ISO22301 LA/LI, PMP, CISSP, CISA, or CISM are preferred. B.E/B-Tech (Tier 1/2) or a Master's degree in Information Security, Computer Science, or a related field is necessary.
Deloitte
Information Technology & Services