T&T | Cyber: CST | Assistant Manager | Risk Management | Bengaluru

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft

Bengaluru

On-site

INR 1,500,000 - 2,400,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Deloitte is seeking an experienced cybersecurity risk advisory professional to support ISMS implementation, vendor risk management, and risk assessments across cyber strategy and controls. You will liaise with clients and cross-functional teams to identify obligations and document findings.

The role involves collaborating with engagement teams on vendor reviews, ensuring compliance with ISO27001/22301, and delivering risk reports with clear recommendations.

Qualifications

  • Experience in third-party risk management from Big 4 or industry
  • Experience with IT audits and cybersecurity gap assessments
  • Experience with ISO27001 and ISO22301 implementations and audits

Responsibilities

  • Support the implementation and monitoring of ISMS based on ISO 27001 standards
  • Assist in vendor risk management activities including risk assessments and due diligence
  • Help perform risk assessments and gap analyses for cyber strategy, controls and compliance frameworks
  • Liaise with clients and manage stakeholder expectations
  • Collaborate with client teams across compliance, auditing and regulators
  • Conduct risk assessments and audits across people, process and technology
  • Document gaps, risks, opportunities and remediation actions in reports
  • Develop vendor assessment approaches and evaluation models
  • Manage key lifecycle activities: planning, execution, reporting, QA and tracking
  • Provide guidance and share knowledge with team members

Skills

Third party risk management
IT audits
Cybersecurity gap assessments
ISO27001
ISO22301
Documentation and presentation
Stakeholder management
Security certifications

Education

Bachelor’s degree in information technology, Computer Science, Business Administration, Engineering, or related field

Job description

Select how often (in days) to receive an alert:

The Team

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity

  • Support the implementation, and monitoring of the Information Security Management System (ISMS) based on ISO 27001 standards
  • Assist in the execution of Third-Party Risk Management (TPRM) activities, including vendor risk assessments, due diligence, and ongoing monitoring
  • Help perform risk assessments and gap analyses related to Cyber Strategy, cybersecurity controls and compliance frameworks
  • Ability to effectively liaise with clients and manage stakeholder expectations
  • Work with client teams from various depts. Such as compliance teams, auditing and regulators to identify and document various requirements/obligations
  • Conducting risk assessments and audits with respect to people, process and technology
  • Identification of gaps/observations, risks, opportunities and improvement of policies, processes, procedures and standards
  • Documenting information security risk, recommendation and compensating controls in the form of assessment/audit reports
  • Collaborate with other members of the engagement team to plan and develop relevant work papers/deliverables for vendor information security reviews, define approach for vendor assessment and develop vendor evaluation model
  • Handle key activities of assessment/ audit life cycle: planning, execution, reporting, quality review and tracking
  • Provide guidance and share knowledge with team members and participate in performing procedures especially focusing on complex, judgmental and/or specialized issues
Key Skills Required
  • 3 to 5 years of experience in Third party risk management from Big 4 firm or from industry
  • Relevant years of experience in IT Audits, Cybersecurity gap assessments
  • Experience with ISO27001 implementation and audits
  • Experience with ISO22301 implementation and audits
  • Preferred certifications CBCI / CBCP / ISO22301 LI or LA Offensive Security Certified Professional, CISA to work in a cross-functional, cross-cultural matrix environment\
  • Understanding of Third party/vendor/supplier risk management considerations
  • Knowledge of Data Protection & Privacy related risks associated with Third-Party and relevant control frameworks for Third party risk management
  • Excellent documentation and presentation skills
  • Highly motivated and willing to work in local and global environments
  • Security certifications like CISSP, CISA, CISM, CEH, ISO27001
  • Work experience in Infrastructure / Application Security, Work experience in IT Audit
  • Work experience in Information Risk Management
  • Education: Bachelor’s degree in information technology, Computer Science, Business Administration, Engineering, or a related field. (BCA, BBA, B.COM, BTech, MTech, MCA, MSC IT, PG Degree)
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

T&T | Cyber - CST | Deputy Manager | Bangalore | GRC
T&T | Cyber - CST | Deputy Manager | Bangalore | GRC

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Bengaluru

On-site
INR 1,800,000 - 3,200,000
T&T | Cyber - CST | Consultant | Bangalore | TPRM
T&T | Cyber - CST | Consultant | Bangalore | TPRM

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Bengaluru

On-site
INR 1,200,000 - 2,400,000
T&T | Cyber: CST | Assistant Manager | Security Frameworks and Standards | Bengaluru
T&T | Cyber: CST | Assistant Manager | Security Frameworks and Standards | Bengaluru

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Bengaluru

On-site
INR 2,500,000 - 4,000,000
T&T | Cyber: CST | Manager | Security Frameworks and Standards | Bengaluru
T&T | Cyber: CST | Manager | Security Frameworks and Standards | Bengaluru

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Bengaluru

On-site
INR 1,800,000 - 2,400,000
T&T | Cyber- CST | Manager | Delhi | TPRM
T&T | Cyber- CST | Manager | Delhi | TPRM

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Delhi

On-site
INR 2,500,000 - 4,000,000
T&T | Cyber - CST | Deputy Manager | Delhi | TPRM
T&T | Cyber - CST | Deputy Manager | Delhi | TPRM

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Delhi

On-site
INR 1,800,000 - 2,600,000
T&T | Cyber: D&R | Assistant Manager | Network Security | Mumbai
T&T | Cyber: D&R | Assistant Manager | Network Security | Mumbai

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Mumbai

On-site
INR 1,400,000 - 2,300,000
Assistant Manager | ISO:27001 | Coimbatore | Cyber Strategy & Transformation
Assistant Manager | ISO:27001 | Coimbatore | Cyber Strategy & Transformation

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Coimbatore District

On-site
INR 1,200,000 - 2,000,000
T&T | Cyber - CST | Deputy Manager | Bangalore | Application Security
T&T | Cyber - CST | Deputy Manager | Bangalore | Application Security

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Deputy Manager | Third Party Risk Management | Mumbai | Cyber Strategy & Transformation
Deputy Manager | Third Party Risk Management | Mumbai | Cyber Strategy & Transformation

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Mumbai

On-site
INR 1,500,000 - 2,300,000