T&T | Cyber - CST | Manager | Third Party Risk Management | Delhi (Delhi, IN)
Deloitte
Deloitte
Join a leading cybersecurity advisory team in Delhi focused on safeguarding organizations from cyber threats. This role offers a unique opportunity to shape and implement robust third-party risk management strategies, ensuring resilience and enabling business growth. You will be instrumental in embedding cyber risk management into the core of strategic development.
Lead comprehensive cyber risk management initiatives, including GRC, TPRM, and cybersecurity transformation across diverse client environments. Oversee cyber risk frameworks, enterprise assessments, and third-party risk programs for various technologies like IT, OT, Cloud, and AI. Conduct detailed security control reviews, compliance assessments, and risk-based due diligence for critical vendors and service providers. Develop and refine TPRM frameworks, policies, and operating models, defining risk tiering and segmentation methodologies. Lead third-party security assessments covering information security, data privacy, cloud security, and incident response. Advise senior stakeholders on cyber risk, governance, and regulatory compliance. Manage and mentor consulting teams, fostering expertise in Cyber GRC and TPRM.
Drive business development activities, including proposal creation and solution design. Collaborate with cross-functional teams to achieve strategic cybersecurity and third-party risk objectives. Research emerging threats and industry best practices to deliver innovative client solutions. Leverage AI-enabled tools for enhanced efficiency in risk identification and reporting, while promoting awareness of AI governance and risks.
A Bachelor's or Master's degree is required, with 8-12 years of experience in Cyber Security Advisory, GRC, Cyber Risk Management, or related fields. Proven expertise in leading large-scale cybersecurity engagements and managing senior client stakeholders is essential. A strong understanding of ISO/IEC 27001, NIST CSF, and various regulatory compliance requirements is crucial.
Demonstrated experience in conducting cybersecurity maturity assessments, enterprise risk assessments, and third-party risk programs is expected. You should possess strong analytical, strategic thinking, and problem-solving skills, with the ability to develop executive-level presentations and governance frameworks. Professional certifications like CISSP, CISM, or CISA are preferred, and AI Governance or AI Security certifications will be an added advantage. Candidates with Big 4, management consulting, or dedicated cybersecurity consulting backgrounds are highly preferred.
Deloitte
Information Technology & Services