T&T | Manager | Security Frameworks and Standards | Delhi | Cyber Strategy & Transformation
Deloitte
Deloitte
Join our dynamic Cyber Strategy & Transformation team as a Manager, focusing on Security Frameworks and Standards. You will play a crucial role in helping organizations build robust defenses against cyber threats and protect their valuable assets. Our approach emphasizes security, vigilance, and resilience, integrating cyber risk management into the core of strategic development to unlock new opportunities.
This position offers the chance to embed advanced cyber risk management practices from the outset, ensuring effective oversight of information and technology risks. You will be instrumental in shaping secure strategies that empower clients to thrive in an evolving digital landscape.
As a Manager in our Cyber team, you will cultivate strong working relationships with clients and internal teams to deliver exceptional outcomes.
Key responsibilities include: - Developing, implementing, and maintaining comprehensive risk and governance frameworks. - Guiding teams in assessing client information security postures, identifying critical gaps and risks, and formulating effective mitigation solutions. - Conducting security risk assessments for third-party vendors and defining Third-Party Risk Management (TPRM) frameworks. - Performing cybersecurity maturity assessments using leading frameworks like NIST CSF and ISO 27001. - Leading Information Security Management System (ISMS) implementation projects based on ISO 27001 standards. - Driving risk identification, evaluation, mitigation, and monitoring activities, providing actionable insights and improvement roadmaps. - Evaluating application security architectures, including secure SDLC practices, threat modeling, and secure coding standards. - Planning, executing, and reporting on IT and cyber security audits, leading teams in assessing IT infrastructure assets. - Managing cybersecurity strategy projects, providing daily guidance to teams, and ensuring timely task fulfillment. - Assisting clients with the review and implementation of information security controls across various processes like change management, incident management, access management, and physical security. - Conducting PCI DSS assessments and gap analyses, providing remediation guidance for compliance. - Tracking evolving regulatory requirements and integrating them into cybersecurity programs.
We are seeking candidates with a strong background in cybersecurity consulting and risk management.
Essential qualifications include: - A Bachelor's degree in Engineering (B.E.) or Technology (B.Tech) from a Tier 1 or Tier 2 institution, or a Master's degree in Information Security, Computer Science, or a related field. - 8 to 10 years of relevant experience in cybersecurity consulting, risk management, and compliance. - In-depth knowledge of security frameworks and standards such as NIST, ISO 27001, and COBIT. - Understanding of cloud service models and security controls across major platforms (AWS, Google Cloud, Azure). - Strong analytical, communication, and stakeholder management skills. - Hands-on experience with GRC tooling like ServiceNow IRM, including control frameworks, data management, and reporting. - Familiarity with control testing methodologies, assurance practices, and evidence evaluation. - Exposure to regulatory frameworks and resilience concepts (e.g., operational resilience, DORA, technology risk standards). - Experience with Business Continuity and Scenario Testing is advantageous. - Professional certifications like CISSP, CISA, CISM, CRISC, or ISO standards are preferred.
Deloitte
Information Technology & Services