Job Title: Manager | CISSP | Mumbai | Cyber Strategy & Transformation

Manager | CISSP | Mumbai | Cyber Strategy & Transformation
• Job requisition ID : 113348
• Location: Mumbai
• Entity: Deloitte Touche Tohmatsu India LLP
The team
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks
Your work profile
As a part of our Cyber strategy team, you will build and nurture positive working relationships with teams and clients with the intention to exceed client expectations.
We are seeking an experienced cyber security specialist with deep expertise in securing critical infrastructure and operational technology (OT) environments within the energy sector. The candidate will support cybersecurity strategy, Application security, SDLC review, risk management, compliance, architecture reviews, and implementation of security controls across the ecosystems.
The ideal candidate should possess strong knowledge of industrial control systems (ICS), Mark-tech, cybersecurity frameworks, regulatory requirements, and emerging threats targeting critical infrastructure.
Key Responsibilities
- Develop and implement cybersecurity strategies aligned with business and operational objectives.
- Conduct cybersecurity maturity assessments and roadmap development.
- Define and review security policies, standards, procedures, and governance frameworks.
- Provide subject matter expertise for digital transformation and smart grid initiatives.
- Perform cybersecurity risk assessments for IT and OT environments.
- Work closely with Application Development teams to validate remediations for vulnerabilities, threats, and security gaps across critical infrastructure.
- Conduct cybersecurity architecture reviews for new projects and technology deployments.
- Support enterprise risk and compliance management activities.
- Support compliance initiatives related to:
- IEC 62443
- NIST Cybersecurity Framework
- ISO 27001
- NIST SP 800-82
- National Critical Infrastructure Protection guidelines
- Conduct cybersecurity audits and remediation tracking.
- Collaborate with plant operations teams, engineering teams, IT teams, and business leadership.
- Provide cybersecurity advisory services to project teams and business units.
- Present security risks and recommendations to senior management and client stakeholders.
- Bachelor's degree in Engineering, Computer Science, Information Security, or related field.
- 8–10 years of cybersecurity experience with at least 3–5 years in technical project management and vulnerability assessments
- Experience in securing critical infrastructure environments.
- Experience conducting cybersecurity assessments and architecture reviews.
- CISSP
- CISM
- ISO 27001 Lead Implementer or Lead Auditor
- Strong analytical and problem-solving skills.
- Excellent stakeholder management and communication skills.
- Ability to influence senior leadership and operational teams.
- Strong report writing and presentation skills.
- Capability to lead client engagements and cybersecurity workstreams.
