Job Title: Deputy Manager | Third Party Risk Management | Delhi | Cyber Strategy & Transformation

Deputy Manager | Third Party Risk Management | Delhi | Cyber Strategy & Transformation
• Job requisition ID : 112317
• Location: Delhi
• Entity: Deloitte Touche Tohmatsu India LLP
Deputy Manager | Third Party Risk Management | Delhi | Cyber Strategy & Transformation
As a part of our Cyber Strategy & Transformation team, you'll build and nurture positive working relationships with teams and clients with the intention to exceed client expectations. You'll:
- Independently lead Cyber Security Advisory, GRC, Cyber Risk Management, Technology Risk, and Cyber TPRM engagements across diverse client environments.
- Lead cybersecurity risk assessments, maturity assessments, control reviews, compliance assessments, IT audits, and third-party risk assessments across IT, OT, Cloud, IoT, and emerging technology environments.
- Develop and enhance Cyber Risk Management Frameworks (CRMF), TPRM frameworks, governance models, policies, standards, procedures, SOPs, playbooks, and risk treatment methodologies, including third-party lifecycle processes covering onboarding, due diligence, risk assessment, contracting, monitoring, renewal, and offboarding.
- Define and implement cyber risk tiering, assessment criteria, risk quantification, escalation and exception management, risk reporting, and governance mechanisms aligned with regulatory expectations and industry practices.
- Lead ISO/IEC 27001 implementation, gap assessments, internal assessments, certification readiness, and continual improvement initiatives.
- Assess cybersecurity controls across infrastructure, cloud, applications, databases, networks, and outsourced environments, covering areas such as identity and access management, encryption, vulnerability and patch management, logging and monitoring, backup security, incident response, and resilience.
- Conduct control maturity and compliance assessments against leading frameworks and standards including ISO/IEC 27001, NIST CSF, NIST SP 800-53, CIS Controls, PCI DSS, ISO 22301, ISO 27701, COBIT, SOC 2, and CSA CCM, as applicable.
- Interpret and apply regulatory and industry requirements related to cybersecurity, outsourcing, information security, data protection, technology risk, and operational resilience, translating requirements into practical control and remediation initiatives.
- Identify cybersecurity risks, control gaps, compliance deficiencies, and improvement opportunities, and develop pragmatic remediation plans, transformation roadmaps, and risk treatment recommendations.
- Facilitate client workshops, stakeholder interviews, risk discussions, and executive presentations, effectively communicating assessment findings, key risks, recommendations, and strategic priorities.
- Manage engagement workstreams, project timelines, resources, stakeholder expectations, and deliverable quality, while performing quality reviews to ensure accuracy, completeness, and adherence to Deloitte standards.
- Lead and mentor consulting teams, provide technical direction, review work products, and drive capability development across cybersecurity, GRC, TPRM, and technology risk.
- Support proposal development, RFP responses, solution design, client pursuits, thought leadership, and identification of new cybersecurity advisory opportunities.
- Collaborate with stakeholders across Information Security, Risk, Compliance, Internal Audit, Technology, and Business functions to deliver strategic cybersecurity and risk transformation outcomes.
- Research emerging cyber threats, regulatory developments, technology trends, and industry practices, and assess their implications for client cybersecurity and risk management programs.
- Leverage AI-enabled tools, automation, analytics, and continuous monitoring capabilities to improve cybersecurity risk assessment and GRC effectiveness, while supporting initiatives related to AI governance and AI security risks.
Qualifications & Certifications
- 6 to 9 years of relevant experience in Cyber Security Advisory, GRC, Cyber Risk Management, Technology Risk, IT Audit, Information Security, or Cybersecurity Consulting.
- Strong preference for candidates with Big 4, management consulting, or cybersecurity consulting experience.
- Demonstrated experience leading cybersecurity assessment, risk management, governance, compliance, and transformation engagements.
- Strong knowledge of ISO/IEC 27001, NIST Cybersecurity Framework (CSF), cyber risk management principles, security controls, and governance practices.
- Experience leading cybersecurity maturity assessments, compliance assessments, audits, third-party assessments, and risk management programs.
- Proven experience managing client workstreams, engagement teams, senior stakeholders, and executive-level communications.
- Strong analytical, problem-solving, stakeholder management, report writing, and presentation skills.
- Experience developing executive-level PowerPoint presentations, strategic roadmaps, governance frameworks, and risk reporting dashboards.
- Professional certifications such as CISSP, CISM, CISA, CRISC, ISO/IEC 27001 Lead Implementer, or ISO/IEC 27001 Lead Auditor are preferred.
- AI Governance or AI Security certifications (e.g., ISO/IEC 42001, NIST AI RMF, or equivalent) will be an added advantage.
