Job Title:  T&T | Cyber - CST | Manager | Third Party Risk Management | Delhi

T&T | Cyber - CST | Manager | Third Party Risk Management | Delhi
Job requisition ID : 112817 
Location: Delhi
Entity: Deloitte Touche Tohmatsu India LLP 

The Team

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity 

 

Your work profile :

  • Lead end-to-end Cyber Security Advisory, Governance, Risk & Compliance (GRC), Cyber Risk Management, Cyber TPRM, and cybersecurity transformation engagements across diverse client environments.
  • Lead and oversee Cyber Risk Management Framework (CRMF) programs, enterprise cyber risk assessments, cyber governance initiatives, and third-party cyber risk management programs across IT, OT, Cloud, IoT, AI, and emerging technology environments.
  • Manage complex cybersecurity maturity assessments, security control reviews, compliance and regulatory assessments, IT audits, and third-party risk assessments, including risk-based security due diligence of critical vendors, technology providers, and outsourced service providers.
  • Lead end-to-end Cyber TPRM lifecycle activities, including third-party identification and scoping, inherent risk assessment, risk tiering, security due diligence, control assessments, findings management, remediation tracking, periodic monitoring, reassessment, and offboarding.
  • Develop and enhance TPRM frameworks, policies, procedures, SOPs, operating models, governance structures, assessment methodologies, and playbooks, covering vendor onboarding, due diligence, contracting, risk assessment, ongoing monitoring, renewal, and exit management.
  • Define and implement third-party cyber risk tiering and segmentation methodologies, assessment criteria, risk scoring, escalation mechanisms, exception management, risk acceptance, and executive-level reporting aligned with business criticality and regulatory expectations.
  • Lead third-party security assessments across areas including information security, data privacy, cloud security, application security, business continuity, incident response, vulnerability management, access management, encryption, and data protection.
  • Assess and challenge third-party and outsourced service provider controls against leading frameworks and standards, including ISO/IEC 27001, NIST CSF, CIS Controls, PCI DSS, SOC 2, CSA CCM, and applicable regulatory requirements.
  • Advise senior client stakeholders and executive leadership on cyber risk, third-party risk, governance models, security controls, regulatory compliance requirements, concentration risk, critical vendor risk, and cybersecurity transformation priorities.
  • Develop and enhance cybersecurity and TPRM governance frameworks, risk management methodologies, operating models, policies, standards, procedures, and enterprise-wide risk treatment strategies.
  • Interpret and translate regulatory requirements related to outsourcing, information security, data protection, technology risk, and operational resilience into practical TPRM and cybersecurity controls, processes, and governance mechanisms.
  • Identify strategic cybersecurity and third-party risks, governance gaps, compliance deficiencies, and operational improvement opportunities, and provide practical, risk-based remediation and risk treatment recommendations.
  • Lead executive workshops, steering committee discussions, stakeholder interviews, and board-level presentations to communicate cyber and third-party risks, assessment findings, remediation priorities, risk trends, and transformation outcomes.
  • Oversee engagement delivery, ensuring quality, consistency, timeliness, effective resource utilization, and stakeholder management across multiple concurrent projects and workstreams.
  • Manage, mentor, and develop consulting teams by providing coaching, technical guidance, performance feedback, and career development support, while building capabilities in Cyber GRC, TPRM, Technology Risk, and cybersecurity advisory.
  • Review and approve client deliverables, including cybersecurity and TPRM assessment reports, governance frameworks, maturity assessments, risk registers, vendor risk profiles, remediation trackers, executive dashboards, transformation roadmaps, and management presentations.
  • Build and maintain strong client relationships while serving as a trusted advisor to senior business, risk, compliance, procurement, information security, technology, and third-party management stakeholders.
  • Support and lead business development activities, including proposal development, TPRM and cybersecurity solution design, client presentations, RFP responses, thought leadership, account development, and market development initiatives.
  • Collaborate with stakeholders across Information Security, TPRM, Procurement, Risk Management, Compliance, Internal Audit, Technology, Legal, and Business functions to deliver strategic cybersecurity and third-party risk outcomes.
  • Research emerging cybersecurity threats, third-party risks, supply-chain risks, regulatory developments, industry trends, and leading practices to support innovative and forward-looking client solutions.
  • Leverage AI-enabled tools, automation, analytics, and continuous monitoring capabilities to enhance cybersecurity and TPRM assessment efficiency, risk identification, reporting, and ongoing monitoring, while promoting awareness of AI governance, AI-related risks, and evolving cybersecurity regulations.

 

Key Skills Required:

  • Education - Bachelor's or Master's
  • 8 to 12 years of relevant experience in Cyber Security Advisory, GRC, Cyber Risk Management, Technology Risk, Information Security, Cybersecurity Consulting, or Cybersecurity Transformation programs.
  • Strong preference for candidates with Big 4, management consulting, or cybersecurity consulting experience.
  • Deep expertise in Cyber Risk Management, GRC, ISO/IEC 27001, cybersecurity governance, compliance, and security assessment programs.
  • Proven experience leading large-scale cybersecurity advisory engagements and managing senior client stakeholders, executive sponsors, and steering committees.
  • Strong knowledge of ISO/IEC 27001, NIST Cybersecurity Framework (CSF), cyber risk management principles, security controls, governance frameworks, and regulatory compliance requirements.
  • Demonstrated experience leading cybersecurity maturity assessments, enterprise risk assessments, compliance reviews, audits, regulatory assessments, and third-party risk programs.
  • Proven ability to manage multidisciplinary teams, complex engagements, project financials, stakeholder expectations, and delivery quality.
  • Strong analytical, strategic thinking, problem-solving, stakeholder management, report writing, and executive presentation skills.
  • Experience developing executive-level PowerPoint presentations, board reports, governance frameworks, operating models, risk dashboards, and cybersecurity transformation roadmaps.
  • Professional certifications such as CISSP, CISM, CISA, CRISC, CGEIT, ISO/IEC 27001 Lead Implementer, or ISO/IEC 27001 Lead Auditor are preferred.
  • AI Governance or AI Security certifications (e.g., ISO/IEC 42001, NIST AI RMF, or equivalent) will be an added advantage.