Job Title:  Assistant Manager | Security Frameworks and Standards | Bengaluru | Cyber Strategy & Transformation

Assistant Manager | Security Frameworks and Standards | Bengaluru | Cyber Strategy & Transformation
Job requisition ID : 112195 
Location: Bengaluru
Entity: Deloitte Touche Tohmatsu India LLP 

The team

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks.

 

Your work profile

 

We expect our people to embrace and live our purpose by challenging themselves to identify issues that are most important for our clients, our people, and for society. 

Establishing and maintaining risk governance frameworks, facilitating risk identification, evaluation, mitigation, and continuous monitoring

Designing and validating secure IT and OT architectures, ensuring integration of application security principles throughout the software development lifecycle.

Experience in design, development, and roll-out of security programs, developing IT risk management strategies, compliance programs. 

Overseeing third-party risk assessments and managing compliance with regulatory frameworks such as RBI, SEBI, IRDA, PCI DSS, and others.

Planning and executing IT and OT security audits alongside IT General Controls (ITGC) testing, identifying gaps, and collaborating with teams to remediate vulnerabilities.

Assessing the organization’s cybersecurity maturity (using frameworks like NIST CSF) and developing strategic roadmaps to strengthen security posture over time.

Cyber Threat and Risk Assessment - Ability to identify business implications and identifying tactical and strategic recommendations to mitigate the risk. 

Possesses certifications such as ISO27001 LA/ LI, ISO22301 LA/LI, PMP, CISSP, CISA, CISM certification- preferred. 

Ability to define the business & technical scope of a project. Should be able to independently lead delivery teams to deliver projects according to client specifications after such scope is defined. 

 

Key Skills Required

 

  • Develop, implement, and maintain risk and governance frameworks. 
  • Guide teams/Handle client information security posture, identify the gaps/risks in the existing environment and develop solutions to mitigate the identified gaps/risk.  
  • Recommend security solutions and enhancements aligned with business goals and threat landscape. 
  • Perform cybersecurity maturity assessments using established frameworks such as NIST CSF, NIST-800-53, ISO 27001, ISO/IEC 42001 etc
  • Lead risk identification, evaluation, mitigation, and monitoring activities. 
  • Deliver actionable insights and improvement roadmaps based on assessment results. 
  • Understand and evaluate application security architectures, including secure SDLC practices, threat modelling and secure coding standards. 
  • Plan, execute, and report on comprehensive IT and OT security audits.  
  • Lead teams or work as team member to conduct Information Systems audits covering IT infrastructure assets.  
  • Manages security and cyber strategy projects, guides the team on a day-to-day basis and ensures that assigned tasks and responsibilities are fulfilled in a timely fashion.  
  • Responsible to assist client in review / implement Information Security controls in areas as mentioned, but not limited to: Change management process, Incident management process, Backup process, User identity and access management, Antivirus management, SLA performance and monitoring
  • Provide guidance for remediation efforts to ensure ongoing compliance. 
  • Demonstrates understanding of complex business and information technology management processes.  
  • Ensure compliance with cybersecurity guidelines and regulations issued by RBI, SEBI, IRDA, BCAS, NCIIPC, and other relevant bodies. 
  • Track evolving regulatory requirements and integrate changes into the cybersecurity program. 
  • Plan and execute ITGC control testing covering areas such as access management, change management, and operations controls. Identify control gaps and support remediation efforts. 
  • Interacts with clients, managers, and partners to build and nurture strong relationships.  
  • Tailors firm tools and methodologies as per client requirements.