Job Title:  T&T | Cyber: D&R | Assistant Manager | Compliance (ISO 27001, PCI DSS) | Mumbai

T&T | Cyber: D&R | Assistant Manager | Compliance (ISO 27001, PCI DSS) | Mumbai
• Job requisition ID : 113438 
• Location: Mumbai
• Entity: Deloitte Touche Tohmatsu India LLP 

The team  

 

Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity  

 

 

Your work profile

 

 

SOC Governance & Cybersecurity Compliance Lead

6+ years of overall cybersecurity experience, including hands-on experience in Security Operations Center (SOC) environments, cybersecurity governance, compliance, audits, and security operations.

Certifications

  • CEH (Certified Ethical Hacker) – Mandatory
  • Any additional relevant certification such as ISO 27001, Security+, or equivalent will be an added advantage.

 

We are looking for an experienced cybersecurity professional to drive SOC governance, cybersecurity compliance, regulatory reporting, documentation, and audit activities. The role requires a strong understanding of SOC operations along with the ability to translate operational activities into measurable security and compliance outcomes, particularly in line with CSCRF requirements.

 

  • Drive and provide accurate data for SOC Efficacy and Cyber Capability Index (CCI) in accordance with CSCRF requirements.
  • Work closely with SOC teams to assess and report SOC performance, effectiveness, detection capabilities, incident response, and operational maturity.
  • Develop, maintain, and govern SOPs, security solution procedures, reaction plans, incident response plans, and operational documentation.
  • Maintain audit trackers, compliance trackers, control evidence, risk registers, and action-item trackers.
  • Coordinate and support external audits, regulatory assessments, certifications, and customer audits.
  • Lead evidence collection, validation, submission, and closure of audit observations.
  • Identify gaps in SOC processes and controls and drive corrective and preventive actions with relevant stakeholders.
  • Ensure SOC processes and documentation remain aligned with regulatory requirements, cybersecurity frameworks, organizational policies, and industry best practices.
  • Work with SOC, IT, infrastructure, application, risk, compliance, and security teams to ensure end-to-end closure of governance and compliance requirements.
  • Prepare management reports, dashboards, metrics, and presentations highlighting SOC effectiveness, compliance posture, key gaps, and improvement areas.
  • Support continuous improvement initiatives to enhance SOC maturity, operational efficiency, incident response capability, and cyber resilience.

 

 

Key Skills Required:

 

 

  • 6+ years of experience in Cybersecurity/SOC, with strong exposure to SOC operations.
  • Good understanding of SIEM, EDR, security monitoring, incident response, threat detection, and SOC processes.
  • Strong understanding of SOC KPIs, metrics, effectiveness measurement, and security operations maturity.
  • Working knowledge of CSCRF and cybersecurity regulatory requirements.
  • Experience in security audits, compliance assessments, certification audits, and evidence management.
  • Strong documentation and governance skills, including SOPs, IR plans, reaction plans, control documentation, and audit artifacts.
  • Good understanding of cybersecurity frameworks such as ISO 27001, NIST, CIS Controls, etc.
  • Strong stakeholder-management and communication skills, with the ability to interact with senior management, auditors, customers, and technical teams.
  • Strong analytical, problem-solving, coordination, and reporting capabilities.

A candidate who combines hands-on SOC experience with governance and compliance expertise, and can independently manage CSCRF reporting, SOC efficacy assessment, audit readiness, documentation, and stakeholder coordination.

Preferred Certifications: CEH + one or more of CISM/ISO 27001/NIST-related certifications.