Job Title: Assistant Manager | Security Frameworks and Standards | Hyderabad | Cyber Strategy & Transformation

Assistant Manager | Security Frameworks and Standards | Hyderabad | Cyber Strategy & Transformation
• Job requisition ID : 109083
• Location: Hyderabad
• Entity: Deloitte Touche Tohmatsu India LLP
|
The Team Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity
Your work profile |
We are seeking a Cyber Security Assurance & Transformation Consultant to support enterprise-wide cyber transformation initiatives by assessing security risks, validating security controls, and strengthening security governance across applications, cloud platforms, digital services, and technology environments.
The role focuses on driving security assurance programs, cyber risk assessments, security validation frameworks, and secure-by-design adoption across APAC markets. The successful candidate will work closely with security, technology, risk, and business stakeholders to identify control gaps, assess cyber risks, improve security maturity, and provide strategic recommendations that support regulatory compliance and organizational cyber resilience.
Key Skills Required:
Education - Any graduate from reputed college
Security Assurance & Cyber Risk Management
· Conduct cyber security assessments and security validation activities across applications, APIs, cloud platforms, infrastructure, and digital transformation initiatives.
· Evaluate the effectiveness of security controls through risk-based security reviews, technical assessments, and security validation exercises.
· Perform threat modeling, attack surface analysis, and cyber risk assessments to identify strategic security gaps, emerging threats, and business risks.
· Assess application, cloud, infrastructure, and platform security controls against organizational standards, regulatory requirements, and industry frameworks.
· Support the development, enhancement, and operationalization of enterprise security assurance frameworks, methodologies, standards, and governance processes.
· Validate security control effectiveness and identify opportunities to improve cyber resilience, security maturity, and risk reduction.
· Partner with architecture, engineering, cloud, and platform teams to embed security-by-design principles into technology transformation and modernization initiatives.
· Develop risk-informed recommendations and remediation roadmaps aligned with business priorities, regulatory obligations, and cyber strategy objectives.
· Support security governance activities through control assessments, compliance reviews, risk evaluations, and assurance reporting.
· Contribute to cyber maturity assessments, capability reviews, current-state assessments, and target-state transformation initiatives across APAC markets.
· Assist in defining security metrics, key risk indicators (KRIs), key performance indicators (KPIs), and executive dashboards that measure control effectiveness and transformation progress.
· Support audit readiness initiatives by ensuring security controls, assessment evidence, remediation activities, and governance processes are appropriately documented and maintained.
· Collaborate with Risk, Compliance, Architecture, Technology, and Business stakeholders to align security assurance activities with enterprise cyber strategy and transformation objectives.
· Facilitate workshops, stakeholder discussions, and governance forums to communicate cyber risks, transformation priorities, and strategic improvement opportunities.
Security Validation & Technical Assurance
· Support security validation initiatives including penetration testing, adversarial assessments, attack-path analysis, and control effectiveness reviews to evaluate organizational cyber resilience.
· Review and validate findings from internal security testing, third-party assessments, red team exercises, vulnerability assessments, and security reviews to identify systemic risks and improvement opportunities.
· Assess security controls across cloud environments (AWS/Azure), containerized platforms, Kubernetes environments, APIs, and modern application architectures.
· Evaluate application security controls including authentication, authorization, encryption, session management, secrets management, and API security practices.
· Perform secure architecture and design assessments to identify security gaps and provide strategic recommendations during technology implementation and transformation initiatives.
· Support the development of security assurance methodologies, assessment standards, operating procedures, and reporting frameworks aligned with industry best practices.
· Provide subject matter expertise during security incidents, investigations, and root-cause analysis activities by supporting attack-path validation and control effectiveness reviews.
Stakeholder Engagement & Transformation Support
· Partner with Cyber Security, Technology, Risk, Compliance, and Business leaders to support security transformation initiatives and strategic cyber programs.
· Develop executive-level reports, risk summaries, and assurance insights for senior leadership and governance committees.
· Support regulatory compliance initiatives by validating security controls against applicable regulatory requirements and industry standards.
· Drive continuous improvement initiatives focused on strengthening cyber resilience, governance effectiveness, and enterprise security posture.
· Promote a security-first culture through knowledge sharing, awareness initiatives, stakeholder engagement, and capability-building activities.
· Flexibility to collaborate with stakeholders across APAC and global regions to support security assurance and transformation initiatives.
· Ability to manage multiple concurrent assessments, transformation workstreams, and stakeholder engagements while maintaining quality and delivery timelines.
· Strong documentation, presentation, and communication skills, including the ability to articulate cyber risks and recommendations to both technical and executive audiences.
· Ability to balance strategic advisory responsibilities with hands-on security assessment and validation activities.
· Experience operating in complex, multi-country, and highly regulated environments.
· 5+ years of experience in Cyber Security, Security Assurance, Cyber Risk, Application Security, Security Architecture, Security Testing, or a closely related cybersecurity discipline.
· Experience conducting cyber risk assessments, security reviews, control assessments, and security assurance activities across enterprise technology environments.
· Strong understanding of cyber security frameworks and standards such as NIST CSF, ISO 27001, CIS Controls, OWASP, MITRE ATT&CK, and related industry practices.
· Experience assessing application, cloud, infrastructure, and platform security controls.
· Familiarity with cloud security concepts across AWS and Azure environments.
· Experience performing threat modeling, attack surface analysis, security architecture reviews, or cyber risk assessments.
· Strong understanding of secure-by-design principles and security control implementation across modern technology environments.
· Experience supporting governance, risk, compliance, audit, or regulatory-driven security initiatives.
· Strong analytical, problem-solving, stakeholder management, and communication skills.
· Experience producing executive-level reporting, risk assessments, and strategic recommendations for senior stakeholders.
Nice to Have
· Industry certifications such as CISSP, CISM, CRISC, CCSP, SABSA, TOGAF, CCSK, or equivalent.
· Experience supporting cyber transformation, cloud transformation, or enterprise security modernization initiatives.
· Knowledge of penetration testing, red teaming, purple teaming, adversary simulation, or security validation methodologies.
· Experience with security architecture reviews and secure solution design assessments.
· Familiarity with DevSecOps, Secure SDLC, cloud-native security, container security, and identity security concepts.
· Experience working within highly regulated industries such as Insurance, Banking, Financial Services, Healthcare, or Government.
· Experience supporting multi-country regulatory compliance programs and enterprise cyber maturity assessments.
Prior consulting or advisory experience supporting senior executives, CISOs, and transformation programs.
