Job Title: Deputy Manager | Third Party Risk Management | Delhi | Cyber Strategy & Transformation
The team
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity
Your work profile
- Lead engagement teams in executing TPRM assessments, technology risk reviews, security audits, and advisory engagements across diverse client environments.
- Develop and enhance TPRM policies, procedures, SOPs, governance frameworks, operating models, and playbooks, including vendor lifecycle processes covering onboarding, due diligence, risk assessment, contracting, monitoring, renewal, and offboarding.
- Define and implement risk tiering methodologies, assessment criteria, escalation mechanisms, exception management, and reporting structures aligned with regulatory expectations and industry best practices.
- Conduct technical control assessments across infrastructure, cloud environments, applications, databases, and network components, evaluating controls related to access management, encryption, logging and monitoring, vulnerability management, patch management, backup security, and incident response.
- Assess third-party security posture against ISO 27001, NIST, PCI DSS, and other applicable cybersecurity frameworks, and support secure design reviews and technology risk evaluations for critical systems and outsourced services.
- Interpret and apply regulatory requirements related to outsourcing, information security, data protection, and operational resilience, ensuring alignment with client control environments and remediation initiatives.
- Perform quality reviews of engagement deliverables to ensure accuracy, completeness, and adherence to Deloitte quality standards.
- Support proposal preparation, RFP responses, solution development, and identification of new advisory opportunities, while guiding and mentoring team members during assessments, audits, and advisory engagements.
- Drive capability building initiatives by strengthening technical and process-oriented competencies and promoting AI-enabled GRC automation, analytics, and continuous monitoring capabilities within the team
Key skills required
- Bachelor's degree in computer science, Information Technology or related field.
- Relevant experience of 6+ years in IT Audits, Cloud security
- Cyber TPRM experience ranging from 3 year to 7yrs is mandatory