Job Title:  Senior Executive | IT Audits | Chennai | Cyber Strategy & Transformation

Senior Executive | IT Audits | Chennai | Cyber Strategy & Transformation
Job requisition ID : 111186 
Location: Chennai
Entity: Deloitte Touche Tohmatsu India LLP 

The Team  

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity  

 

 

Your Work Profile

 Responsible for ISO 27001 based Information Security Management System implementation and sustenance and assess client information security posture, identify the gaps/risks in the existing environment and develop solutions to mitigate the identified gaps/risk Responsible to assist client in review / implement Information Security controls in areas as mentioned, but not limited to: Change management process, Incident management process, Backup process, User identity and access management, Antivirus management, SLA performance and monitoring, Media handling & Exchange of information, Physical and environmental Security, and Media & Information Handling. Responsible for conducting clients’ vendors risk assessment and providing a holistic view of client’s risk exposure due to outsourcing. Responsible for advising and assisting clients to develop and implement Information classification framework. Demonstrates ability to work independently on projects with limited supervision. Demonstrates working knowledge of firm tools and methodologies that may be suitable for the engagement.  

 

 

Key Required Skills:

  • Conduct security assessments of IT systems, applications, and networks to identify vulnerabilities and risks.
  • Perform risk assessments and gap analyses to evaluate compliance with frameworks such as ISO 27001, NIST CSF, PCI-DSS etc.
  • Working knowledge in one or more security domains such as: Information Technology, Information Security, Regulatory Compliance, Security Governance policies and procedures, Risk Management, Compliance, Access Control, Network Security, Security Architecture Review, IT General Controls, Third Party Risk Management
  • Demonstrates in-depth knowledge of information and cyber security controls and risk management process.
  • Serves as technical lead or subject matter specialist on security and privacy implementation projects, responsible for design, build, testing and deployment of solutions.
  • Demonstrates ability to work independently on projects with limited supervision.
  • Demonstrates understanding of complex business and information technology management processes.
  • Demonstrates working knowledge of firm tools and methodologies that may be suitable for the engagement.
  • Manages day-to-day client relationships at mid and lower levels.
  • Participates in proposal development efforts to sell "add-on" work to clients.
  • Identifies opportunities to improve engagement economics.
  • Plays substantive role in designing and implementing business development plan for the service line.
  • Plays substantive/lead role in retention of professionals and in building staff complement, mix, and recruiting.
  • Undertakes initiatives in people and practice development.
  • Develop and recommend security measures, policies, and procedures to mitigate identified risks.
  • Collaborate with cross-functional teams to implement cybersecurity best practices and resolve vulnerabilities.
  • Stay updated on the latest cyber threats, trends, and regulatory requirements.
  • Bachelor’s degree in computer science, Information Security, or a related field (or equivalent experience).
  • In-depth knowledge of security frameworks and standards (e.g., ISO 27001, NIST SP 800-53, CIS Controls).
  • Relevant certifications such as CISSP, CISA, CEH, or CRISC are highly preferred.
  • Strong analytical, problem-solving, and communication skills.