T&T | Cyber: CST | Manager | Security Frameworks and Standards | Bengaluru

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft

Bengaluru

On-site

INR 1,800,000 - 2,400,000

Full time

26 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Deloitte Touche Tohmatsu India LLP in Bengaluru seeks a Manager for Security Frameworks and Standards to lead governance programs and risk assessments across IT and business units.

You will design and implement security controls, align with ISO27001, COBIT, and ITIL, and drive secure cloud adoption on AWS, Azure, and Google Cloud in collaboration with clients and stakeholders.

Strong communication and leadership are essential to deliver compliant, resilient security programs.

Qualifications

  • Possesses certifications such as ISO27001 LA/ LI, ISO22301 LA/LI, PMP, CISSP, CISA, CISM preferred.
  • Experience in establishing and maintaining risk governance frameworks and facilitating risk identification, evaluation, mitigation, and monitoring.

Responsibilities

  • Lead risk governance and SOM/TPRM initiatives across client environments.
  • Advise on secure cloud architectures and best practices; ensure cloud environments meet security standards.
  • Design and validate secure development lifecycle (SDLC) practices and threat modelling.
  • Plan and execute ITGC controls testing and assist remediation of control gaps.
  • Interacts with clients, managers, and partners to build strong relationships and tailor tools to client requirements.

Skills

GRC expertise
Security frameworks
Risk governance
Regulatory compliance
Cloud security
IT risk management
Secure SDLC
NIST CSF
ISO 27001
COBIT

Education

B.E./B.Tech or Masters in information security/CS

Tools

AWS
Azure
Google Cloud

Job description

Select how often (in days) to receive an alert:

Job Title: T&T | Cyber: CST | Manager | Security Frameworks and Standards | Bengaluru

T&T | Cyber: CST | Manager | Security Frameworks and Standards | Bengaluru
Job requisition ID : 112196
Location: Bengaluru
Entity: Deloitte Touche Tohmatsu India LLP

The Team

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient - not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity

  • We expect our people to embrace and live our purpose by challenging themselves to identify issues that are most important for our clients, our people, and for society.
  • Subject matter specialist in GRC and multiple security domains
  • Extensive experience in leveraging industry standards and frameworks such as ISO/IEC 27001, COBIT, ITIL, etc.
  • Establishing and maintaining risk governance frameworks, facilitating risk identification, evaluation, mitigation, and continuous monitoring
  • Designing and validating secure IT architectures, ensuring integration of application security principles throughout the software development lifecycle.
  • Experience in design, development, and roll-out of security programs, developing IT risk management strategies, compliance programs.
  • Overseeing third-party risk assessments and managing compliance with regulatory frameworks such as RBI, SEBI, IRDA, PCI DSS, and others.
  • Advising on secure cloud architecture and best practices across AWS, Azure, and Google Cloud platforms, ensuring cloud environments meet compliance and security standards.
  • Experience in building vulnerability management programs for organizations. Planning and executing IT and OT security audits alongside IT General Controls (ITGC) testing, identifying gaps, and collaborating with teams to remediate vulnerabilities.
  • Experience in designing Secure Development Lifecycle for organizations (Strategic roadmap and implementation)
  • Assessing the organization’s cybersecurity maturity (using frameworks like NIST CSF) and developing strategic roadmaps to strengthen security posture over time.
  • Cyber Threat and Risk Assessment - Ability to identify business implications and identifying tactical and strategic recommendations to mitigate the risk.
  • Possesses certifications such as ISO27001 LA/ LI, ISO22301 LA/LI, PMP, CISSP, CISA, CISM certification- preferred.
  • Ability to define the business & technical scope of a project. Should be able to independently lead delivery teams to deliver projects according to client specifications after such scope is defined.
Key Skills Required
  • Develop, implement, andmaintainrisk and governance frameworks.
  • Guide teams/Handleclient information security posture,identifythe gaps/risks in the existingenvironmentand develop solutions to mitigate the identified gaps/risk.
  • Recommend security solutions and enhancements aligned with business goals and threat landscape.
  • Conduct security risk assessments of third-party vendors and service providers.
  • Define TPRM frameworks and integrate them into the overall risk managementprogram.
  • Perform cybersecurity maturity assessments using established frameworks such as NIST CSF,NIST-800-53,ISO 27001
  • Frontend teams for ISO 27001 based Information Security Management System implementation andsustenance-basedprojects.
  • Lead risk identification, evaluation, mitigation, and monitoring activities.
  • Deliver actionable insights and improvement roadmaps based on assessmentresults.
  • Understand and evaluate application security architectures, including secure SDLC practices, threatmodellingand secure codingstandards.
  • Plan, execute, and report on comprehensive ITand cybersecurity audits.
  • Lead teamsorwork as teammemberto conduct Information Systems audits covering IT infrastructure assets.
  • Manages security andcyber strategyprojects, guides the team on a day-to-daybasisand ensures that assigned tasks and responsibilities are fulfilled ina timelyfashion.
  • Responsible to assist client in review / implement Information Security controls in areas as mentioned, but not limited to: Change management process, Incidentmanagementprocess, Backup process, User identity and access management, Antivirus management, SLA performance and monitoring, Media handling & Exchange of information, Physical and environmental Security, and Media & Information Handling.
  • Conduct and support PCI DSS assessments and gap analysis.
  • Provide guidance for remediation efforts to ensure ongoing compliance.
  • Demonstrates understanding of complex business and information technology managementprocesses.
  • Ensure compliance with cybersecurity guidelines and regulations issued by RBI, SEBI, IRDA, BCAS, NCIIPC, and other relevant bodies.
  • Track evolving regulatory requirements and integrate changes into the cybersecurityprogram.
  • Plan and execute ITGC control testing covering areas such as access management, change management, and operations controls.Identifycontrol gaps and support remediationefforts.
  • Interacts with clients,managers,and partners to build and nurture strongrelationships.
  • Tailors firm tools and methodologies as per clientrequirements.
  • In-depth knowledge of security frameworks and standards (e.g., NIST, ISO 27001, COBIT).
  • Understanding ofcloud service models and security controls across major platforms (AWS, Google Cloud, Azure).
  • Strong analytical, communication, and stakeholder management skills
  • B. E/ B-Tech (Tier 1/2)ormaster's degree in information security, Computer Science, or a related field
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

T&T | Cyber: CST | Assistant Manager | Security Frameworks and Standards | Bengaluru
T&T | Cyber: CST | Assistant Manager | Security Frameworks and Standards | Bengaluru

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Bengaluru

On-site
INR 2,500,000 - 4,000,000
T&T | Cyber - CST | Deputy Manager | Bangalore | GRC
T&T | Cyber - CST | Deputy Manager | Bangalore | GRC

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Bengaluru

On-site
INR 1,800,000 - 3,200,000
T&T | Cyber: CST | Assistant Manager | Risk Management | Bengaluru
T&T | Cyber: CST | Assistant Manager | Risk Management | Bengaluru

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Bengaluru

On-site
INR 1,500,000 - 2,400,000
T&T | Cyber- CST | Manager | Delhi | TPRM
T&T | Cyber- CST | Manager | Delhi | TPRM

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Delhi

On-site
INR 2,500,000 - 4,000,000
T&T | Cyber - CST | Consultant | Bangalore | TPRM
T&T | Cyber - CST | Consultant | Bangalore | TPRM

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Bengaluru

On-site
INR 1,200,000 - 2,400,000
Manager | Security Frameworks and Standards | Pune | Cyber Strategy & Transformation
Manager | Security Frameworks and Standards | Pune | Cyber Strategy & Transformation

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Maharashtra

On-site
INR 6,000,000 - 9,000,000
Consultant | Security Frameworks and Standards | Pune | Cyber Strategy & Transformation
Consultant | Security Frameworks and Standards | Pune | Cyber Strategy & Transformation

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Maharashtra

On-site
INR 900,000 - 1,300,000
Assistant Manager | Security Frameworks and Standards | Pune | Cyber Strategy & Transformation
Assistant Manager | Security Frameworks and Standards | Pune | Cyber Strategy & Transformation

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Maharashtra

On-site
INR 1,500,000 - 2,100,000
Deputy Manager | Security Frameworks and Standards | Pune | Cyber Strategy & Transformation
Deputy Manager | Security Frameworks and Standards | Pune | Cyber Strategy & Transformation

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Maharashtra

On-site
INR 1,800,000 - 3,000,000
T&T | Cyber: D&R | Assistant Manager | Network Security | Mumbai
T&T | Cyber: D&R | Assistant Manager | Network Security | Mumbai

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Mumbai

On-site
INR 1,400,000 - 2,300,000