Job Title:  Deputy Manager | ISO:27001 | Coimbatore | Cyber Strategy & Transformation

Deputy Manager | ISO:27001 | Coimbatore | Cyber Strategy & Transformation
Job requisition ID : 111549 
Location: Coimbatore
Entity: Deloitte Touche Tohmatsu India LLP 

The team

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks.

 

Your work profile

 

We are seeking an experienced Cyber Security Subject Matter Expert (SME) to support a Security Findings Lifecycle Management program for a large enterprise client. The role will be responsible for providing technical security expertise throughout the lifecycle of security findings, including validation of remediation plans, assessment of compensating controls, exception reviews, and verification of closure evidence.

The SME will serve as the primary technical advisor for Application Security, Cloud Security, Network Security, and Infrastructure Security findings, ensuring that identified risks are effectively mitigated and closed in accordance with security standards and risk management requirements.

 

Key Skills Required

  • Security Findings Lifecycle Management
  • Act as the technical SME for security findings throughout their lifecycle from identification to closure.
  • Review and validate security findings originating from vulnerability assessments, security reviews, audits, cloud security assessments, and compliance assessments.
  • Assess the risk and technical impact of identified security findings.
  • Collaborate with application, infrastructure, cloud, and network teams to drive remediation activities.
  • Ensure findings are appropriately categorized, prioritized, tracked, and resolved within defined SLA timelines.
  • Provide technical guidance to stakeholders on remediation strategies and risk reduction approaches.
  • Support governance processes related to finding management and closure.

 

  • Perform risk assessments for security policy, standard, and control exceptions across applications, infrastructure, network, cloud, and third-party environments.
  • Evaluate the business justification, technical exposure, threat likelihood, and potential impact associated with exception requests.
  • Identify and assess compensating controls to reduce residual risk when standard security requirements cannot be met.
  • Document risk ratings, recommendations, and approval requirements for exception requests.
  • Facilitate review and approval workflows with security leadership, risk owners, and business stakeholders.
  • Track exception validity, expiration dates, renewal requirements, and associated remediation plans.
  • Monitor and report on exception-related risk exposure, trends, and aging metrics.
  • Ensure risk acceptance decisions are appropriately documented and approved in accordance with organizational governance requirements.
  • Challenge exception requests where viable remediation options exist and recommend alternative security controls.
  • Support periodic reviews of approved exceptions to assess continued business need and changing risk posture.
  • Review requests for security policy, standard, or control exceptions.
  • Assess risks associated with exception requests and determine overall security impact.
  • Evaluate and recommend compensating controls to minimize residual risk.
  • Validate effectiveness and implementation feasibility of proposed compensating controls.
  • Document risk assessments, exception recommendations, and residual risk evaluations.
  • Participate in exception review boards and stakeholder discussions.
  • Support risk acceptance processes by providing technical security assessments.
  • Review remediation plans proposed by application, cloud, and infrastructure teams.
  • Validate whether proposed remediation actions effectively address the root cause of security findings.
  • Recommend alternative remediation approaches where proposed solutions do not adequately mitigate risk.
  • Ensure remediation recommendations align with organizational security standards and industry best practices.
  • Evaluate security architecture changes introduced as part of remediation activities.
  • Provide technical consultation for complex or high-risk security findings.
  • Evaluate changes to the validated state of systems through change control procedures and participate in the planning and implementation of changes
  • Support and provide input into system administration and maintenance procedures to ensure adequate controls for maintaining the validated state
  • Acts as a quality contact and primary Subject Matter Expert (SME) for Computer System Validation (CSV) and Quality Risk Management
  • Educational Qualification: Any Graduate BE / B.Tech (Tier 1 / Tier 2) in CS / IT / EC / E, OR MCA from a recognized university