T&T | Cyber - CST | Manager | Third Party Risk Management | Delhi

Deloitte

8–12 yrs New Delhi Full Time Work from office
Deloitte logo
Posted : yesterday
Actively hiring

Job description

Join Deloitte Touche Tohmatsu India LLP as a Manager in our Cyber practice, focusing on Third Party Risk Management. This role is based in Delhi and offers an opportunity to lead critical cybersecurity advisory engagements.

Our Cyber team helps organizations build resilience against cyber threats, ensuring security and enabling new opportunities. We focus on integrating cyber risk into strategic development for effective information and technology risk management. Learn more about our Cybersecurity initiatives.

Responsibilities

Lead end-to-end Cyber Security Advisory, GRC, Cyber Risk Management, TPRM, and transformation engagements.

Oversee Cyber Risk Management Framework programs, enterprise cyber risk assessments, and governance initiatives across IT, OT, Cloud, IoT, AI, and emerging technologies.

Manage cybersecurity maturity assessments, security control reviews, compliance and regulatory assessments, IT audits, and third-party risk assessments, including due diligence for critical vendors and outsourced providers.

Drive the full TPRM lifecycle, from identification and scoping to risk assessment, control evaluation, remediation tracking, and offboarding.

Develop and enhance TPRM frameworks, policies, procedures, and operating models.

Define and implement third-party cyber risk tiering, segmentation, and assessment methodologies.

Assess third-party controls against leading frameworks like ISO/IEC 27001 and NIST CSF.

Advise senior clients and leadership on cyber and third-party risk, governance, and cybersecurity transformation.

Develop and enhance cybersecurity and TPRM governance frameworks and risk management methodologies.

Translate regulatory requirements into practical TPRM and cybersecurity controls.

Identify strategic risks, governance gaps, and operational improvement opportunities, providing actionable recommendations.

Lead workshops, steering committee discussions, and board-level presentations.

Oversee engagement delivery, ensuring quality and stakeholder satisfaction.

Manage, mentor, and develop consulting teams.

Review and approve client deliverables such as assessment reports and transformation roadmaps.

Build and maintain strong client relationships.

Support business development activities, including proposal development and solution design.

Collaborate with various internal and external stakeholders to achieve strategic outcomes.

Research emerging threats and trends to support innovative client solutions.

Leverage AI-enabled tools and analytics to enhance TPRM efficiency and risk identification.

Qualifications

Seeking professionals with 8 to 12 years of experience in Cyber Security Advisory, GRC, Cyber Risk Management, Technology Risk, Information Security, Cybersecurity Consulting, or Cybersecurity Transformation.

Big 4, management consulting, or cybersecurity consulting experience is highly preferred.

Demonstrated expertise in Cyber Risk Management, GRC, ISO/IEC 27001, cybersecurity governance, compliance, and security assessment programs is essential.

Proven ability to lead large-scale cybersecurity advisory engagements and manage senior client stakeholders and steering committees.

Strong knowledge of ISO/IEC 27001, NIST Cybersecurity Framework (CSF), cyber risk management principles, security controls, governance frameworks, and regulatory compliance requirements.

Experience leading cybersecurity maturity assessments, enterprise risk assessments, compliance reviews, audits, regulatory assessments, and third-party risk programs.

Ability to manage multidisciplinary teams, complex engagements, project financials, stakeholder expectations, and delivery quality.

Excellent analytical, strategic thinking, problem-solving, stakeholder management, report writing, and executive presentation skills are required.

Experience developing executive-level presentations, board reports, governance frameworks, operating models, risk dashboards, and cybersecurity transformation roadmaps.

Professional certifications such as CISSP, CISM, CISA, CRISC, CGEIT, ISO/IEC 27001 Lead Implementer, or ISO/IEC 27001 Lead Auditor are preferred.

AI Governance or AI Security certifications (e.g., ISO/IEC 42001, NIST AI RMF, or equivalent) will be an added advantage.

Essential Skills

Cyber Risk ManagementGRCISO/IEC 27001Cybersecurity GovernanceComplianceSecurity AssessmentStakeholder ManagementExecutive PresentationRisk ManagementInformation Security

Good to Have

CISSPCISMCISACRISCCGEITISO/IEC 27001 Lead ImplementerISO/IEC 27001 Lead AuditorAI GovernanceAI SecurityISO/IEC 42001NIST AI RMF

Highlights

  • Actively hiring

More Details

RoleT&T | Cyber - CST | Manager | Third Party Risk Management | Delhi
IndustryInformation Technology & Services, Cybersecurity
DepartmentRisk Management, General Management
Employment TypeFull Time, Work from office

About the Company

Deloitte logo

Deloitte

Information Technology & Services

T&T | Cyber - CST | Manager | Third Party Risk Management | Delhi at Deloitte | SkillMX | SkillMX