Job Title:  T&T | Cyber: CST | Assistant Manager | Risk Management | Bengaluru

T&T | Cyber: CST | Assistant Manager | Risk Management | Bengaluru
Job requisition ID : 112603 
Location: Bengaluru
Entity: Deloitte Touche Tohmatsu India LLP 

The team

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks.

 

Your work profile

•     Support the implementation, and monitoring of the Information Security Management System (ISMS) based on ISO 27001 standards

•     Assist in the execution of Third-Party Risk Management (TPRM) activities, including vendor risk assessments, due diligence, and ongoing monitoring

•     Help perform risk assessments and gap analyses related to Cyber Strategy, cybersecurity controls and compliance frameworks

•     Ability to effectively liaise with clients and manage stakeholder expectations

•     Work with client teams from various depts. Such as compliance teams, auditing and regulators to identify and document various requirements/obligations

•     Conducting risk assessments and audits with respect to people, process and technology

•     Identification of gaps/observations, risks, opportunities and improvement of policies, processes, procedures and standards

•     Documenting information security risk, recommendation and compensating controls in the form of assessment/audit reports

•     Collaborate with other members of the engagement team to plan and develop relevant work papers/deliverables for vendor information security reviews, define approach for vendor assessment and develop vendor evaluation model

•     Handle key activities of assessment/ audit life cycle: planning, execution, reporting, quality review and tracking

•     Provide guidance and share knowledge with team members and participate in performing procedures especially focusing on complex, judgmental and/or specialized issues

 

Desired qualifications

·      3 to 5 years of experience in Third party risk management from Big 4 firm or from industry

·      Relevant years of experience in IT Audits, Cybersecurity gap assessments

·      Experience with ISO27001 implementation and audits

·      Experience with ISO22301 implementation and audits

·      Preferred certifications CBCI / CBCP / ISO22301 LI or LA Offensive Security Certified Professional, CISA to work in a cross-functional, cross-cultural matrix environment\

·      Understanding of Third party/vendor/supplier risk management considerations

·      Knowledge of Data Protection & Privacy related risks associated with Third-Party and relevant control frameworks for Third party risk management

·      Excellent written/verbal communication

·      Excellent documentation and presentation skills

·      Highly motivated and willing to work in local and global environments

·      Security certifications like CISSP, CISA, CISM, CEH, ISO27001

·      Work experience in Infrastructure / Application Security

·      Work experience in IT Audit

·      Work experience in Information Risk Management