T&T | Deputy Manager | Security Frameworks and Standards | Pune | Cyber Strategy & Transformation
Deloitte
Deloitte
Join Deloitte Touche Tohmatsu India LLP as a Deputy Manager in our Cyber Strategy & Transformation team in Pune. This role is pivotal in helping organizations prevent cyberattacks and protect their valuable assets by building secure, vigilant, and resilient systems. You will embed cyber risk management into strategic development, enabling effective information and technology risk management while unlocking new opportunities for our clients.
Conduct comprehensive cyber capability and security control assessments across diverse technology landscapes. Evaluate control effectiveness against industry-leading frameworks like NIST CSF, ISO 27001, and CIS Controls. Identify critical capability gaps, control deficiencies, and cybersecurity risks to drive strategic transformation initiatives. Support cyber maturity assessments and develop actionable roadmaps for capability enhancement. Assist in control documentation, evidence management, and remediation tracking.
Evaluate security postures across identity, endpoint, network, cloud, and application domains. Assess the performance of preventive, detective, and corrective security controls. Leverage Microsoft Sentinel and KQL for robust control validation, capability assessment, and security effectiveness reviews. Analyze security events and trends to pinpoint areas for improvement and contribute to cyber governance, risk management, and assurance activities.
This role requires a seasoned cybersecurity professional with 5-8 years of experience in Cybersecurity, Cyber Risk, Security Controls, Governance, Compliance, or Cyber Transformation. A strong understanding of cybersecurity control frameworks such as NIST CSF, ISO 27001, and CIS Controls is essential. Proficiency in Microsoft Sentinel and KQL for security analysis and control validation is a must. Experience in security control reviews, risk assessments, or capability assessments is highly valued, as is knowledge of identity, endpoint, network, cloud, and application security domains. Excellent analytical, problem-solving, stakeholder engagement, documentation, reporting, and communication skills are expected.
Candidates should possess a B.E./B.Tech (Tier 1/2) or a Master's degree in Information Security, Computer Science, or a related field. Knowledge of incident-response methodologies and common attack techniques will be beneficial for security control reviews and capability improvement initiatives.
Deloitte
Cybersecurity