Job Title: T&T | Cyber: CST | Deputy Manager | Risk Management | Bengaluru

T&T | Cyber: CST | Deputy Manager | Risk Management | Bengaluru
• Job requisition ID : 112601
• Location: Bengaluru
• Entity: Deloitte Touche Tohmatsu India LLP
The team
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Lear more about Cybersecurity
Your work profile
- As a Deputy Manager in our Cyber Team, you’ll build and nurture positive working relationships with teams and clients with the intention of exceeding client expectations.
- Support clients in assessing and implementing data localisation and cross-border data transfer requirements in accordance with applicable laws, regulations and regulatory guidelines.
- Conduct data localisation and cross-border data transfer assessments to identify regulatory, privacy and information security risks and recommend appropriate mitigation strategies.
- Assess data flows, data storage, processing locations, hosting arrangements and third-party/service-provider dependencies to determine localisation and data residency requirements.
- Develop and implement data localisation frameworks, policies, standards, controls and governance processes aligned with client requirements and applicable regulations.
- Support clients in data discovery, data classification, data mapping and data-flow assessments to identify where sensitive, personal and regulated data is collected, processed, stored and transferred.
- Perform risk and impact assessments covering data residency, cross-border transfers, privacy, third-party processing, cloud environments and regulatory compliance.
- Provide guidance on privacy and data protection requirements, including DPIAs/PIAs, data governance, data retention, data minimization and protection of personal and sensitive information.
- Design and implement risk management and compliance frameworks, including risk identification, assessment, treatment, remediation tracking, risk acceptance and management reporting.
- Work with business, technology, legal, privacy, compliance and security stakeholders to develop practical remediation roadmaps for identified data localisation, privacy and cyber/data risks.
- Support development of governance mechanisms, control frameworks, monitoring metrics and management reporting to ensure continued compliance with data localisation and privacy requirements.
Key skills required:
· Minimum 6+ years of experience in Data Localisation, Data Privacy, Data Protection, Cyber/Technology Risk, GRC or related areas.
· Strong understanding of data localisation, data residency, cross-border data transfers and data sovereignty concepts.
· Good understanding of Indian and global data protection/privacy regulations and regulatory requirements, including the Digital Personal Data Protection Act (DPDP Act), GDPR and relevant sector-specific requirements.
· Experience in data-flow mapping, data discovery/classification, data inventories, processing assessments and cross-border transfer assessments.
· Experience in privacy and data protection assessments, including DPIA/PIA and privacy risk assessments.
· Experience in risk management, including risk identification, inherent and residual risk assessment, control evaluation, risk treatment, remediation and risk acceptance.
· Understanding of cloud environments, third-party/service-provider risks, data storage/hosting models, encryption, access management, DLP and other data protection controls.
. Knowledge of relevant standards/frameworks such as ISO 27001, ISO 27701, ISO 31000, NIST and COBIT would be preferred.
· Certifications such as CIPP/E, CIPM, CIPT, ISO 27001, ISO 27701, CISA, CISM or equivalent would be preferred.
· Strong analytical, problem-solving, stakeholder-management and communication skills.
. Bachelor’s degree in Information Technology, Computer Science, Law, Cybersecurity or a related field.
