Job Title: Manager | Third Party Risk Management | Delhi | Cyber Strategy & Transformation

Manager | Third Party Risk Management | Delhi | Cyber Strategy & Transformation
• Job requisition ID : 112817
• Location: Delhi
• Entity: Deloitte Touche Tohmatsu India LLP
JD FOR MANAGER
As a part of our Cyber Strategy & Transformation team, you'll build and nurture positive working relationships with teams and clients with the intention to exceed client expectations. You'll:
- Lead end-to-end Cyber Security Advisory, Governance, Risk & Compliance (GRC), Cyber Risk Management, Cyber TPRM, and cybersecurity transformation engagements across diverse client environments.
- Lead and oversee Cyber Risk Management Framework (CRMF) programs, enterprise cyber risk assessments, cyber governance initiatives, and third-party cyber risk management programs across IT, OT, Cloud, IoT, AI, and emerging technology environments.
- Manage complex cybersecurity maturity assessments, security control reviews, compliance and regulatory assessments, IT audits, and third-party risk assessments, including risk-based security due diligence of critical vendors, technology providers, and outsourced service providers.
- Lead end-to-end Cyber TPRM lifecycle activities, including third-party identification and scoping, inherent risk assessment, risk tiering, security due diligence, control assessments, findings management, remediation tracking, periodic monitoring, reassessment, and offboarding.
- Develop and enhance TPRM frameworks, policies, procedures, SOPs, operating models, governance structures, assessment methodologies, and playbooks, covering vendor onboarding, due diligence, contracting, risk assessment, ongoing monitoring, renewal, and exit management.
- Define and implement third-party cyber risk tiering and segmentation methodologies, assessment criteria, risk scoring, escalation mechanisms, exception management, risk acceptance, and executive-level reporting aligned with business criticality and regulatory expectations.
- Lead third-party security assessments across areas including information security, data privacy, cloud security, application security, business continuity, incident response, vulnerability management, access management, encryption, and data protection.
- Assess and challenge third-party and outsourced service provider controls against leading frameworks and standards, including ISO/IEC 27001, NIST CSF, CIS Controls, PCI DSS, SOC 2, CSA CCM, and applicable regulatory requirements.
- Advise senior client stakeholders and executive leadership on cyber risk, third-party risk, governance models, security controls, regulatory compliance requirements, concentration risk, critical vendor risk, and cybersecurity transformation priorities.
- Develop and enhance cybersecurity and TPRM governance frameworks, risk management methodologies, operating models, policies, standards, procedures, and enterprise-wide risk treatment strategies.
- Interpret and translate regulatory requirements related to outsourcing, information security, data protection, technology risk, and operational resilience into practical TPRM and cybersecurity controls, processes, and governance mechanisms.
- Identify strategic cybersecurity and third-party risks, governance gaps, compliance deficiencies, and operational improvement opportunities, and provide practical, risk-based remediation and risk treatment recommendations.
- Lead executive workshops, steering committee discussions, stakeholder interviews, and board-level presentations to communicate cyber and third-party risks, assessment findings, remediation priorities, risk trends, and transformation outcomes.
- Oversee engagement delivery, ensuring quality, consistency, timeliness, effective resource utilization, and stakeholder management across multiple concurrent projects and workstreams.
- Manage, mentor, and develop consulting teams by providing coaching, technical guidance, performance feedback, and career development support, while building capabilities in Cyber GRC, TPRM, Technology Risk, and cybersecurity advisory.
- Review and approve client deliverables, including cybersecurity and TPRM assessment reports, governance frameworks, maturity assessments, risk registers, vendor risk profiles, remediation trackers, executive dashboards, transformation roadmaps, and management presentations.
- Build and maintain strong client relationships while serving as a trusted advisor to senior business, risk, compliance, procurement, information security, technology, and third-party management stakeholders.
- Support and lead business development activities, including proposal development, TPRM and cybersecurity solution design, client presentations, RFP responses, thought leadership, account development, and market development initiatives.
- Collaborate with stakeholders across Information Security, TPRM, Procurement, Risk Management, Compliance, Internal Audit, Technology, Legal, and Business functions to deliver strategic cybersecurity and third-party risk outcomes.
- Research emerging cybersecurity threats, third-party risks, supply-chain risks, regulatory developments, industry trends, and leading practices to support innovative and forward-looking client solutions.
- Leverage AI-enabled tools, automation, analytics, and continuous monitoring capabilities to enhance cybersecurity and TPRM assessment efficiency, risk identification, reporting, and ongoing monitoring, while promoting awareness of AI governance, AI-related risks, and evolving cybersecurity regulations.
Qualifications & Certifications
- 8 to 12 years of relevant experience in Cyber Security Advisory, GRC, Cyber Risk Management, Technology Risk, Information Security, Cybersecurity Consulting, or Cybersecurity Transformation programs.
- Strong preference for candidates with Big 4, management consulting, or cybersecurity consulting experience.
- Deep expertise in Cyber Risk Management, GRC, ISO/IEC 27001, cybersecurity governance, compliance, and security assessment programs.
- Proven experience leading large-scale cybersecurity advisory engagements and managing senior client stakeholders, executive sponsors, and steering committees.
- Strong knowledge of ISO/IEC 27001, NIST Cybersecurity Framework (CSF), cyber risk management principles, security controls, governance frameworks, and regulatory compliance requirements.
- Demonstrated experience leading cybersecurity maturity assessments, enterprise risk assessments, compliance reviews, audits, regulatory assessments, and third-party risk programs.
- Proven ability to manage multidisciplinary teams, complex engagements, project financials, stakeholder expectations, and delivery quality.
- Strong analytical, strategic thinking, problem-solving, stakeholder management, report writing, and executive presentation skills.
- Experience developing executive-level PowerPoint presentations, board reports, governance frameworks, operating models, risk dashboards, and cybersecurity transformation roadmaps.
- Professional certifications such as CISSP, CISM, CISA, CRISC, CGEIT, ISO/IEC 27001 Lead Implementer, or ISO/IEC 27001 Lead Auditor are preferred.
- AI Governance or AI Security certifications (e.g., ISO/IEC 42001, NIST AI RMF, or equivalent) will be an added advantage.
