T&T | Cyber: D&R | Assistant Manager | Compliance (ISO 27001, PCI DSS) | Mumbai (Mumbai, IN)
Deloitte
Deloitte
Join our dynamic team as an Assistant Manager specializing in Cybersecurity Compliance. This role is pivotal in ensuring our adherence to critical frameworks like ISO 27001 and PCI DSS. You'll be instrumental in strengthening our security posture and managing cyber risks proactively.
Deloitte helps organizations defend against cyber threats and safeguard critical assets. We champion a secure, vigilant, and resilient approach, moving beyond mere prevention and response to effectively manage cyber risk and unlock new opportunities. By embedding cyber risk considerations early in strategy development, we enhance the management of information and technology risks. Explore more about Cybersecurity.
Lead and optimize SOC governance, cybersecurity compliance, and regulatory reporting. Drive accurate data collection for SOC Efficacy and Cyber Capability Index, aligning with CSCRF requirements.
Assess and report on SOC performance, detection capabilities, and incident response effectiveness. Develop and maintain essential documentation including SOPs, reaction plans, and incident response strategies. Manage audit trackers, compliance registers, and control evidence.
Coordinate and support external and customer audits, leading evidence collection and closure of audit observations. Identify process gaps and drive corrective actions. Ensure alignment with regulatory mandates, cybersecurity frameworks, and organizational policies. Prepare comprehensive management reports and dashboards to highlight key findings and improvement areas. Support continuous improvement initiatives for enhanced SOC maturity and cyber resilience.
We are seeking an experienced cybersecurity professional with a minimum of 6 years of experience, including hands-on work in Security Operations Centers (SOC). A strong understanding of cybersecurity governance, compliance, audits, and security operations is essential.
Key skills include proficiency in SIEM, EDR, incident response, threat detection, and SOC processes. Familiarity with CSCRF and various cybersecurity regulatory requirements is crucial. Experience with security audits, compliance assessments, and managing evidence is required. Excellent documentation, governance, and stakeholder management skills are paramount.
Candidates with a blend of practical SOC experience and expertise in governance, compliance, and independent management of CSCRF reporting, SOC efficacy assessment, audit readiness, and documentation will be highly valued. A mandatory CEH certification is required, with additional certifications like ISO 27001 or Security+ being advantageous.
Deloitte
Cybersecurity