Job Title: Deputy Manager | Risk Management | Pune | Cyber Strategy & Transformation

Deputy Manager | Risk Management | Pune | Cyber Strategy & Transformation
• Job requisition ID : 110731
• Location: Pune
• Entity: Deloitte Touche Tohmatsu India LLP
The team
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Lear more about Cybersecurity
Your work profile
- As Deputy manager in our Cyber Team, you’ll build and nurture positive working relationships with teams and clients with the intention to exceed client expectations.
- Conduct cybersecurity and technology assessments across data platforms, applications, cloud environments, and enterprise technology ecosystems.
- Assess data pipelines and data flows for security, privacy, integrity, resiliency, and control effectiveness.
- Review data ingestion, transformation, processing, storage, and consumption processes to identify security and data-related risks.
- Assess controls around data access, authentication, authorization, encryption, secrets management, logging, monitoring, and data protection.
- Perform assessment of ETL/ELT pipelines, data integration workflows, APIs, and data movement mechanisms from a cybersecurity perspective.
- Evaluate security controls implemented across Databricks, cloud data platforms, data lakes, warehouses, and analytics environments.
- Use Python and PySpark for data analysis, assessment automation, data validation, and identification of anomalies or control gaps.
- Work with Databricks to analyze large datasets and assess data processing and security configurations.
- Review DevSecOps pipelines and CI/CD processes to assess security integration across the software development lifecycle.
- Assess security controls across source code repositories, build pipelines, artifact repositories, deployment processes, and infrastructure-as-code.
- Evaluate implementation of security checks such as SAST, DAST, SCA, secrets scanning, vulnerability scanning, and container security within CI/CD pipelines.
- Review cloud security configurations and controls across environments such as AWS, Azure, or GCP, with focus on data and application security.
- Perform data profiling, data quality, data lineage, and data flow assessments to identify potential security and governance risks.
- Identify vulnerabilities, control deficiencies, misconfigurations, and potential data exposure risks and provide remediation recommendations.
- Support development of assessment methodologies, control checklists, risk matrices, and assessment reports.
- Work with engineering and cybersecurity teams to validate remediation actions and track findings through closure.
- Support automation of recurring assessment activities using Python, PySpark, SQL, and other scripting/analytics capabilities.
- Prepare dashboards, management reports, and assessment outputs highlighting risks, trends, control gaps, and remediation status.
- Strong understanding of Cybersecurity, Information Security, and Technology Risk concepts.
- Knowledge of security controls across application, infrastructure, cloud, network, and data environments.
- Understanding of IAM, encryption, vulnerability management, security monitoring, logging, endpoint security, and application security.
- Knowledge of secure SDLC and DevSecOps principles.
- Understanding of data security, data privacy, data governance, and data protection concepts.
- Experience with security and risk frameworks such as NIST, ISO 27001, CIS Controls, SOC 2, or similar frameworks.
- Ability to identify and assess cybersecurity risks, control gaps, vulnerabilities, and remediation requirements.
- Understanding of cloud security concepts and common cloud security controls.
- Python – scripting, data analysis, automation, and assessment tooling.
- PySpark – large-scale data processing, transformation, validation, and analysis.
- Databricks – data processing, notebooks, workflows, data analysis, and security assessment.
- Strong SQL skills for data extraction, validation, profiling, and analysis.
- Understanding of data lakes, data warehouses, ETL/ELT, APIs, and data pipelines.
- Ability to assess end-to-end data flows and data lineage.
- Experience with cloud data platforms and technologies across Azure, AWS, or GCP is preferred.
- Knowledge of Git/GitHub/GitLab/Bitbucket and source-code management practices.
- Experience assessing CI/CD pipelines from a cybersecurity and control perspective.
- Understanding of Jenkins, Azure DevOps, GitHub Actions, GitLab CI/CD, or similar tools.
- Knowledge of integrating security controls into pipelines, including:
- SAST – Static Application Security Testing
- DAST – Dynamic Application Security Testing
- SCA – Software Composition Analysis
- Secrets detection
- Container/image scanning
- Infrastructure-as-Code security scanning
- Vulnerability scanning
- Ability to assess pipeline configurations, security gates, approvals, segregation of duties, credentials/secrets management, and deployment controls.
- Understanding of DevSecOps lifecycle and secure deployment practices.
- Experience assessing Infrastructure-as-Code (IaC) using technologies such as Terraform is an advantage.
Key skills required:
- Bachelor's or Master's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related discipline.
- 7 years of experience in cybersecurity, technology risk, data security, data engineering, security assessment, or related areas.
- Experience working across Cybersecurity and Data/Technology Engineering teams.
- Relevant certifications such as CISSP, CISA, Security+, CCSP, CEH, or cloud/security certifications would be an advantage.
- Strong analytical and problem-solving skills.
- Ability to understand complex data architectures and technology environments.
- Ability to translate technical findings into business risks and actionable recommendations.
- Strong documentation and report-writing skills.
- Good stakeholder management and communication skills.
- Ability to work independently as well as collaboratively with Cyber, Data, Cloud, Engineering, and DevSecOps teams.
- Strong attention to detail and ability to work with large and complex datasets.
