Job Title:  T&T | Cyber- CST | Manager | Delhi | TPRM

T&T | Cyber- CST | Manager | Delhi | TPRM
Job requisition ID : 112817 
Location: Delhi
Entity: Deloitte Touche Tohmatsu India LLP 

The Team

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity

 

Your work profile

As a part of our Cyber Strategy & Transformation team, you'll build and nurture positive working relationships with teams and clients with the intention to exceed client expectations. You'll:

  • Lead end-to-end Cyber Security Advisory, Governance, Risk & Compliance (GRC), Cyber Risk Management, and cybersecurity transformation engagements across diverse client environments.
  • Lead and oversee Cyber Risk Management Framework (CRMF) programs, enterprise cyber risk assessments, cyber governance initiatives, and risk reporting programs across IT, OT, Cloud, IoT, AI, and emerging technology environments.
  • Manage complex cybersecurity maturity assessments, security control reviews, compliance assessments, regulatory assessments, audits, and third-party risk management engagements.
  • Lead ISO/IEC 27001 implementation, gap assessments, internal assessments, certification readiness, and continuous improvement initiatives for large and complex organizations.
  • Advise senior client stakeholders and executive leadership on cyber risk, governance models, security controls, regulatory compliance requirements, and cybersecurity transformation priorities.
  • Develop and enhance cybersecurity governance frameworks, risk management methodologies, operating models, policies, standards, procedures, and enterprise-wide risk treatment strategies.
  • Assess security controls against leading industry frameworks and standards, including ISO/IEC 27001, NIST Cybersecurity Framework (CSF), CIS Controls, and applicable regulatory requirements.
  • Identify strategic cybersecurity risks, governance gaps, compliance deficiencies, and operational improvement opportunities, and provide practical, risk-based remediation recommendations.
  • Lead executive workshops, steering committee discussions, stakeholder interviews, and board-level presentations to communicate cybersecurity risks, findings, strategic roadmaps, and transformation outcomes.
  • Oversee engagement delivery, ensuring quality, consistency, timeliness, and effective stakeholder management across multiple concurrent projects.
  • Manage, mentor, and develop consulting teams by providing coaching, technical guidance, performance feedback, and career development support.
  • Review and approve client deliverables, including assessment reports, governance frameworks, maturity assessments, risk registers, executive dashboards, transformation roadmaps, and management presentations.
  • Build and maintain strong client relationships while serving as a trusted advisor to senior business, risk, compliance, and technology stakeholders.
  • Support and lead business development activities, including proposal development, solution design, client presentations, RFP responses, thought leadership, and market development initiatives.
  • Collaborate with stakeholders across Information Security, Risk Management, Compliance, Internal Audit, Technology, and Business functions to deliver strategic cybersecurity outcomes.
  • Research emerging cybersecurity threats, industry trends, regulations, and leading practices to support innovative and forward-looking client solutions.
  • Leverage AI-enabled tools and automation to enhance engagement delivery while promoting awareness of AI governance, AI-related risks, and evolving cybersecurity regulations.

 

Key Skills Required

  • 8 to 12 years of relevant experience in Cyber Security Advisory, GRC, Cyber Risk Management, Technology Risk, Information Security, Cybersecurity Consulting, or Cybersecurity Transformation programs.
  • Strong preference for candidates with Big 4, management consulting, or cybersecurity consulting experience.
  • Deep expertise in Cyber Risk Management, GRC, ISO/IEC 27001, cybersecurity governance, compliance, and security assessment programs.
  • Proven experience leading large-scale cybersecurity advisory engagements and managing senior client stakeholders, executive sponsors, and steering committees.
  • Strong knowledge of ISO/IEC 27001, NIST Cybersecurity Framework (CSF), cyber risk management principles, security controls, governance frameworks, and regulatory compliance requirements.
  • Demonstrated experience leading cybersecurity maturity assessments, enterprise risk assessments, compliance reviews, audits, regulatory assessments, and third-party risk programs.
  • Proven ability to manage multidisciplinary teams, complex engagements, project financials, stakeholder expectations, and delivery quality.
  • Strong analytical, strategic thinking, problem-solving, stakeholder management, report writing, and executive presentation skills.
  • Experience developing executive-level PowerPoint presentations, board reports, governance frameworks, operating models, risk dashboards, and cybersecurity transformation roadmaps.
  • Professional certifications such as CISSP, CISM, CISA, CRISC, CGEIT, ISO/IEC 27001 Lead Implementer, or ISO/IEC 27001 Lead Auditor are preferred.
  • AI Governance or AI Security certifications (e.g., ISO/IEC 42001, NIST AI RMF, or equivalent) will be an added advantage.