Job Title: Deputy Manager | Third Party Risk Management | Mumbai | Cyber Strategy & Transformation

Deputy Manager | Third Party Risk Management | Mumbai | Cyber Strategy & Transformation
• Job requisition ID : 112607
• Location: Mumbai
• Entity: Deloitte Touche Tohmatsu India LLP
The team
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity
Your work profile
- As Deputy Manager in our Cyber Team, you’ll build and nurture positive working relationships with teams and clients with the intention to exceed client expectations.
Key skills required:
- Lead compliance assessments against frameworks and regulations such as ISO/IEC 27001, ISO/IEC 27701, RBI, SEBI, IRDAI, CERT-In, SOC 2, PCI DSS, and DPDPA.
- Develop and review governance frameworks, policies, standards, procedures, and control documents.
- Conduct enterprise risk assessments and compliance reviews.
- Support internal and external audits and regulatory assessments.
- Prepare executive dashboards, management reports, and Steering Committee presentations.
- Data Privacy
- Lead DPDPA and GDPR implementation and advisory engagements.
- Conduct Privacy Gap Assessments, Applicability Assessments, DPIAs, Business Impact Assessments (BIA), Data Discovery, RoPA, and Data Flow Mapping.
- Develop privacy governance frameworks, policies, notices, consent management processes, and data retention strategies.
- Support implementation of privacy controls and remediation initiatives
- Third-Party Risk Management (TPRM)
- Design and implement Third-Party Risk Management frameworks and operating models.
- Perform vendor due diligence, security assessments, and privacy assessments.
- Review vendor contracts from information security and privacy perspectives.
- Develop vendor onboarding, periodic review, and continuous monitoring processes.
- Track remediation of third-party risks.
- Cloud Security
- Conduct cloud security assessments for AWS, Microsoft Azure, and Google Cloud Platform (GCP).
- Review cloud architecture, IAM, encryption, logging, monitoring, backup, and security configurations.
- Assess cloud environments against CIS Benchmarks and security best practices.
- Recommend security improvements to enhance cloud resilience and compliance.
- Project & Team Management
- Lead multiple consulting engagements from initiation to closure.
- Develop project plans, effort estimates, and resource allocation plans.
- Manage project timelines, risks, issues, and client expectations.
- Conduct client workshops, interviews, and stakeholder meetings.
- Review team deliverables and ensure quality and timely delivery.
- Mentor and guide junior team members and support their professional development
- Business Development Support
- Support proposal development, RFP/RFI responses, and solution design.
- Contribute to thought leadership, accelerators, templates, and reusable assets.
- Participate in client presentations and business development discussions.
- Strong understanding of DPDPA, GDPR, and privacy principles.
- Experience in Governance, Risk & Compliance (GRC).
- Hands-on experience in Third-Party Risk Management (TPRM).
- Good understanding of Cloud Security concepts across AWS, Azure, and GCP.
- Experience in conducting security and privacy risk assessments.
- Strong knowledge of ISO/IEC 27001 and ISO/IEC 27701.
- Excellent documentation, presentation, and report-writing skills.
- Strong communication and stakeholder management skills.
- Ability to manage multiple client engagements simultaneously.
- Preferred Certifications (Good to have)
- ISO/IEC 27001 Lead Auditor/Lead Implementer
- ISO/IEC 27701 Lead Implementer
- CISA
- CRISC
- CISSP
- CCSP or CCSK
- CIPP/E, CIPM, or CIPT
- AWS Certified Security – Specialty
- Microsoft Certified: Azure Security Engineer Associate
- Educational Qualification
- Bachelor's degree in Computer Science, Information Technology, Cyber Security, Engineering, or a related field.
- Banking, Financial Services & Insurance (BFSI)
- FinTech
- Consulting
- Analytical and problem-solving skills
- Project management
