Job Title: T&T | Cyber- CST | Deputy Manager | Risk Management | Pune |

T&T | Cyber- CST | Deputy Manager | Risk Management | Pune |
• Job requisition ID : 110232
• Location: Pune
• Entity: Deloitte Touche Tohmatsu India LLP
The Team
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity
Your Work Profile
We are looking for a dynamic Deputy Manager with 5–8 years of experience in Governance, Risk & Compliance (GRC), Cloud Security, Third-Party Risk Management (TPRM), and Data Privacy. The candidate will be responsible for leading client engagements, managing project delivery, mentoring team members, and supporting organizations in implementing security, privacy, and compliance programs aligned with regulatory and industry standards.
The ideal candidate should possess strong consulting skills, excellent stakeholder management capabilities, and hands-on experience in delivering compliance and cyber risk engagements across multiple domains.
Key Skills Required:
- Compliance & Governance
- Lead compliance assessments against frameworks and regulations such as ISO/IEC 27001, ISO/IEC 27701, RBI, SEBI, IRDAI, CERT-In, SOC 2, PCI DSS, and DPDPA.
- Develop and review governance frameworks, policies, standards, procedures, and control documents.
- Conduct enterprise risk assessments and compliance reviews.
- Support internal and external audits and regulatory assessments.
- Prepare executive dashboards, management reports, and Steering Committee presentations.
- Data Privacy
- Lead DPDPA and GDPR implementation and advisory engagements.
- Conduct Privacy Gap Assessments, Applicability Assessments, DPIAs, Business Impact Assessments (BIA), Data Discovery, RoPA, and Data Flow Mapping.
- Develop privacy governance frameworks, policies, notices, consent management processes, and data retention strategies.
- Support implementation of privacy controls and remediation initiatives
- Third-Party Risk Management (TPRM)
- Design and implement Third-Party Risk Management frameworks and operating models.
- Perform vendor due diligence, security assessments, and privacy assessments.
- Review vendor contracts from information security and privacy perspectives.
- Develop vendor onboarding, periodic review, and continuous monitoring processes.
- Track remediation of third-party risks.
- Cloud Security
- Conduct cloud security assessments for AWS, Microsoft Azure, and Google Cloud Platform (GCP).
- Review cloud architecture, IAM, encryption, logging, monitoring, backup, and security configurations.
- Assess cloud environments against CIS Benchmarks and security best practices.
- Recommend security improvements to enhance cloud resilience and compliance.
- Project & Team Management
- Lead multiple consulting engagements from initiation to closure.
- Develop project plans, effort estimates, and resource allocation plans.
- Manage project timelines, risks, issues, and client expectations.
- Conduct client workshops, interviews, and stakeholder meetings.
- Review team deliverables and ensure quality and timely delivery.
- Mentor and guide junior team members and support their professional development
- Business Development Support
- Support proposal development, RFP/RFI responses, and solution design.
- Contribute to thought leadership, accelerators, templates, and reusable assets.
- Participate in client presentations and business development discussions.
- Strong understanding of DPDPA, GDPR, and privacy principles.
- Experience in Governance, Risk & Compliance (GRC).
- Hands-on experience in Third-Party Risk Management (TPRM).
- Good understanding of Cloud Security concepts across AWS, Azure, and GCP.
- Experience in conducting security and privacy risk assessments.
- Strong knowledge of ISO/IEC 27001 and ISO/IEC 27701.
- Excellent documentation, presentation, and report-writing skills.
- Strong communication and stakeholder management skills.
- Ability to manage multiple client engagements simultaneously.
- Preferred Certifications (Good to have)
- ISO/IEC 27001 Lead Auditor/Lead Implementer
- ISO/IEC 27701 Lead Implementer
- CISA
- CRISC
- CISSP
- CCSP or CCSK
- CIPP/E, CIPM, or CIPT
- AWS Certified Security – Specialty
- Microsoft Certified: Azure Security Engineer Associate
- Educational Qualification
- Bachelor's degree in Computer Science, Information Technology, Cyber Security, Engineering, or a related field.
- Relevant postgraduate qualification or professional certifications will be an added advantage.
- Preferred Industry Experience
- Banking, Financial Services & Insurance (BFSI)
- FinTech
- Consulting
- IT/ITES
- Healthcare
- Manufacturing
- Leadership and team management
- Client relationship management
- Analytical and problem-solving skills
- Project management
- Presentation and communication skills
- Risk-based decision making
- Report writing and documentation
- Ability to work in a fast-paced consulting environment
