Deloitte’sCybersecurity Services helpourclientstobesecure,vigilant,andresilientinthefaceofanever-increasing array of cyber threats and vulnerabilities. Our Cybersecurity practice helps organizations with the management of information and technology risks by delivering end-to-end solutions using proven methodologies and tools in a consistentmanner.Ourserviceshelporganizationstoaddress,inatimelymanner,pervasiveissues,suchasidentity theft, data security breaches, data leakage, and system outages across organizations of diverse sizes and industries with the goal of enabling ongoing, secure, and reliable operations across the enterprise.
Workyou will do
- Perform comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system, Artificial Intelligence (AI) system, and Operational Technology (OT) system to determine the overall effectiveness of the controls in accordance with industry standards and frameworks
- Prepare, review, and analyze documents such as Plans of Actions and Milestones (POAMs), Security Assessment Reports (SAR), Security Assessment Plans (SAP)
- Develop and implement AI Security Framework standardizing security/privacy integration into AI/ML-powered applications
- Design secure reference architectures for AI-enabled systems, incorporating guardrails and runtime protections
- Integrate AI security controls into enterprise architecture, including encryption, access management, and adversarial robustness measures
- Draft and maintain AI security policies covering data privacy, bias mitigation, and explainability
- Monitor compliance of AI systems with global regulations (NIST AI RMF, ISO 42001, EU AI Act) and internal governance standards
- Manageandexecutecyberriskengagementsacrossthedevelopmentlifecycle –strategy,design, implementation, and managed services
- Facilitateenterprisedecisionmakingbyprovidingaholisticviewofenterprise-widecyberrisk,assessingthe level of risk, and providing input into the management of risk
- Developandtailorapproaches,methods,andtoolstosupportclientscyberriskprogramsandinitiatives
- Strategically drive the development and execution of risk assessments and mitigation plans to enhance the client's ability to identify, evaluate, prioritize, and mitigate risks
- Design and develop cyber security strategies and programs for large and complex organizations adhering to industry standards and frameworks
- Assess, develop, and implement cyber security programs, including organizational design, cyber resilience, and other key processes for our clients
- Reviewclients’cyberposture,strengths,andweaknessesinthecontextofbusinessenvironment,goals,and objectives. Develop prioritized recommendations based on gaps and clients’ priorities andconstraints
- Driveorganizationalchangesandestablishgovernancestructurestoachievecybergoalsandobjectives
- Develop impactful reports and presentations that support the achievement of engagement goals and objectives
- Work with senior management stakeholders to define and implement overall future state philosophy and capabilities for the clients’ cyber security programs
- Lead project workstream and manage deliverables from inception to delivery, ensuring timelines, and quality standards are met
- Perform peer reviews and mentor team members
TheTeam
Deloitte’s Cyber Strategy and Transformation practice is focused on helping our clients to design and implement transformational programs to reduce and manage cyber threats. We help our clients to define their overall cyber strategy, design global, pan-enterprise programs that focus on mitigating threats, evaluating their objectives, priorities, strengths, and weaknesses, and roll out large scale organizational changes to achieve goals.
QualificationsandExperience
Required:
- Bachelor’sdegreeininformationtechnologyorrelatedfield
- 5-9years of informationsecurityexperience
- Excellent communication (verbalandwritten) and interpersonal skills
- Proficiency in Microsoft Office (Excel, PowerPoint, and Word)
- Hands-on experience working with industrystandardsandframeworks(e.g., ISO 27001, NIST, HIPAA, FedRAMP, PCI)
- Foundational understanding of AI/GenAI security frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act)
- Understanding of security requirements, contributions to security design and hands-on implementation of multiple security technologies and capabilities
- Hands-on experience developing cyber security policies and standards
- Hands-on experience working with stakeholders in identifying, prioritizing, and developing plans and roadmaps for cyber security programs
- Broad domain knowledge and strong understanding of three or more cyber security domains including (but not limited to):
- Cyberriskstrategy
- Cyber security maturity assessments
- Cybersecurityoperations
- Securityarchitecture
- Dataprotection and privacy
- Applicationsecurity/SDLC
- Cloudsecurity
- Cloud infrastructure security
- Incident response
- Cyberresilience
- Zero Trust
Preferred:
- B.E./B. Tech+MBA(Preferred)
- CISSP/CISM(orequivalent)