Job Title:  T&T | Cyber- CST | Assistant Manager | GRC | Hyderabad

T&T | Cyber- CST | Assistant Manager | GRC | Hyderabad
Job requisition ID : 109081 
Location: Hyderabad
Entity: Deloitte Touche Tohmatsu India LLP 

The team

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks: Learn more about Cyber | Deloitte

 

Your work profile

  • Drive cybersecurity initiatives as part of the Cyber Strategy team.
  • Build and maintain strong relationships with internal stakeholders and clients to ensure high-quality project delivery and client satisfaction.
  • Support security governance frameworks and oversee implementation of security controls across applications, systems, and network environments.
  • Lead and support security audits, compliance reviews, and risk assessment activities.

 

Key Skills Required:

  • Strong understanding of cybersecurity controls across domains including Cryptography, DLP, Endpoint Security, and Network Security.
  • Work closely with technology and security teams to manage and support implementation of cybersecurity controls.
  • Translate control requirements into:
  • Technical expectations for implementation teams
  • Control validation approaches to assess effectiveness
  • Assess control effectiveness and identify gaps in implementation
  • Manage and complete cybersecurity due diligence questionnaires from clients, partners, and vendors.
  • Coordinate with internal stakeholders to gather accurate responses and supporting evidence.
  • Ensure responses are technically accurate and aligned with organizational policies and controls.
  • Track questionnaire status, timelines, and outcomes.
  • Oversee the collection, validation, and documentation of evidence to support control compliance and audit requirements.
  • Analyze control validation results, identify control weaknesses, and escalate critical risks to senior management.
  • Support and manage regulatory and audit activities, including evidence collection, validation, and remediation tracking.
  • Recommend and implement improvements to control validation processes, documentation, and reporting mechanisms.
  • Foster strong understanding of cybersecurity controls, risk, and compliance requirements across teams.
  • Stay updated on evolving cybersecurity threats, regulatory requirements, and industry best practices to ensure ongoing compliance and effectiveness.
  • Bachelor’s degree in computer science, Information Technology, or a related field.
  • 5+ years of experience in Cybersecurity GRC, Cyber control reviews and assessment, Cyber control testing and or a similar role with a focus on security controls.
  • Strong understanding of:
  • Cryptography and PKI (TLS, certificates)
  • Data Loss Prevention (DLP)
  • Endpoint and Network security controls
  • Experience with security frameworks (NIST CSF, CIS, ISO 27001).
  • Strong analytical and problem-solving skills.
  • Excellent communication and documentation skills.
  • Ability to manage multiple priorities and work independently.
  • Experience with GRC tools such as:
  • ServiceNow GRC
  • IBM OpenPages
  • Exposure to automation or scripting for evidence collection.
  • Familiarity with cloud environments (AWS / Azure).
  • CISSP, CISA, CRISC, ISO 27001 Lead Auditor/Implementer is preferred